DNS SRV RRs and priority

Greg Hudson ghudson at MIT.EDU
Fri Jun 1 00:45:14 EDT 2012

On 05/31/2012 09:33 PM, Jaap Winius wrote:
> One of the sites I maintain uses DNS SRV resource records to allow  
> Debian squeeze workstations to discover three MIT Kerberos key  
> servers. Like with all SRV records, it's possible to alter the  
> priority value, but my question is, does this ever make a difference?

We do sort SRV responses by priority (but we ignore weights).

> So I tried an experiment: use three SRV records, but give the one for  
> the local KDC the highest priority. Unfortunately, this way the system  
> behaves just like in the first situation. So, now I'm back to using  
> one SRV RR per location.

My only guess is that you have the sense of SRV priorities backwards?
Per RFC 2782, we prefer records with lower-numbered priority fields over
records with higher-number priority fields.

More information about the Kerberos mailing list