[krbdev.mit.edu #6031] krb needs better realm lookup logic

Mark.Phalan@Sun.Com via RT rt-comment at krbdev.mit.edu
Wed Jul 16 07:24:13 EDT 2008


[raeburn - Tue Jul 15 14:27:02 2008]:

> Thanks.  The heuristic looks good.  Is there some specific reason you
> went with direct resolver
> calls, bypassing /etc/hosts and whatever else might be configured?

The direct resolver calls will still use /etc/hosts (at least on Solaris).
On Solaris we only support Kerberos if DNS is used. I believe there may
have been issues with host resolution to get fully qualified domain
names when using NIS or NIS+ as a name service backend. I don't know if
the original reasons for only supporting DNS are still valid.




More information about the krb5-bugs mailing list