[krbdev.mit.edu #6782] Master KDC lookup can use SRV lookups despite profile KDC configuration

Greg Hudson via RT rt-comment at krbdev.mit.edu
Tue Apr 8 14:19:53 EDT 2014


The change I suggested above could alter the behavior of existing 
environments.  Where there are widely distributed krb5.conf files 
specifying kdc but not master_kdc entries, and a SRV record for kerberos-
master, we would be effectively disabling fallback to master.  This is the 
case for ATHENA.MIT.EDU.

A more conservative change would be to support "master_kdc = ." or 
something to explicitly suppress the master_kdc setting in the profile, 
preventing a lookup in DNS.  I am not sure if we will go this route or 
make the previously suggested change.


More information about the krb5-bugs mailing list