Immediate password propagation

Rahul.Jain@wellsfargo.com Rahul.Jain at wellsfargo.com
Tue Apr 12 20:26:47 EDT 2005


Is there a way or a plan to implement immediate propagation of password
changes?

 

If a client GSS implementation does not support the DNS
_kerberos-master._udp SRV record and it gets load-balanced to a slave
KDC, it will fail authentication if replication hasn't yet completed,
right? Or is that implemented in the MIT KDC code itself when it
recognizes that it is configured as a slave? Is there a way to use the
standard kpasswd and have the master KDC push the new password to the
slaves itself if the GSS implementation needs to be aware of this setup?

 

TIA,

Rahul Jain



More information about the Kerberos mailing list