• Load Balancing KCDs

    From Jonathan Towles@21:1/5 to Robbie Harwood on Thu Feb 18 21:53:19 2021
    To: kerberos@mit.edu (kerberos@mit.edu)

    Yeah I saw this also.

    From what I've read holistically, Putting your DCs behind a VIP tends to be problematic because the member server name doesn't match the name of the SPN thus it becomes vehemently unhappy.

    I suppose you could possibly build an ASA similar to how you do Kerberos with Exchange and try to leverage that but I've read/heard there's a ton of reliability issues and you should just rely on the krb5.conf like:

    [realms]
    ATHENA.MIT.EDU = {
    kdc = kerberos.mit.edu
    kdc = kerberos-1.mit.edu
    kdc = kerberos-2.mit.edu:750
    admin_server = kerberos.mit.edu
    master_kdc = kerberos.mit.edu
    default_domain = mit.edu

    Jon Towles
    CTO, Synterex
    (m) 978-609-5545



    -----Original Message-----
    From: Robbie Harwood <rharwood@redhat.com>
    Sent: Thursday, February 18, 2021 4:48 PM
    To: Jonathan Towles <jjtowles@synterex.com>; kerberos@mit.edu
    Subject: Re: Load Balancing KCDs

    Jonathan Towles <jjtowles@synterex.com> writes:

    Does anyone have experience putting DCs behind a network load balancer
    for Kerberos Authentication?

    Depending on who you ask, it doesn't really work. I wanted to ask the
    group to see if anyone has strong experience in doing it and if it's feasible?

    I usually refer to Simo's post on this:
    https://ssimo.org/blog/id_019.html

    Thanks,
    --Robbie

    --- SoupGate-Win32 v1.05
    * Origin: fsxNet Usenet Gateway (21:1/5)
  • From Robbie Harwood@21:1/5 to Jonathan Towles on Thu Feb 18 16:48:11 2021
    To: kerberos@mit.edu (kerberos@mit.edu)

    Jonathan Towles <jjtowles@synterex.com> writes:

    Does anyone have experience putting DCs behind a network load balancer
    for Kerberos Authentication?

    Depending on who you ask, it doesn't really work. I wanted to ask the
    group to see if anyone has strong experience in doing it and if it's feasible?

    I usually refer to Simo's post on this:
    https://ssimo.org/blog/id_019.html

    Thanks,
    --Robbie

    -----BEGIN PGP SIGNATURE-----

    iQJIBAEBCgAyFiEEA5qc6hnelQjDaHWqJTL5F2qVpEIFAmAu4JsUHHJoYXJ3b29k QHJlZGhhdC5jb20ACgkQJTL5F2qVpELLWg//dtAEOJHU4MnUKa23vV+7ly7ShILL y0/Ow1u3iACCVtlUthIfHdMvFbklEfaRQN9N/XfHWIAXxX5rX5lCSrAj8vRAX+iq OseXL5hs7Sm3l42eH3VUpUsmpgGaicq2A9rei8BHr4Dk1fcGkQo4rVJ9eG8n1DZh fMGQkmw1mZ/5h1lwfLaLfIkTX48ofyV5I9lv+0lzzqbAiiCf5GK6XaHjxMs2irvx 6Ca/b1HoInBN1osXOGle+Z+fyywxHVHTZTxQb3wPmG2E6ZLfPXjbSES2uqcVe70T EvriHUAXhyknB5LxI/sPwyHSkUqqTWNtzBSQkR2l/n/75j3oiKPpJI8CMQY/48yu +uqsQvec6eTUyx2TcYhz77x/QtvDdXKhTb1cvHr8M3+7y/kYp0U7dtrHhusyrGpU nCd2tFaHT/JsNRutswmwPhyKRR/q9lxBJEh3PwBKQE+lyR6/bbaqXM/Sk1M6gixH mtWRFVs3od+QUaZs0wIAMEXI3CZ+yngr+lUvptuHG0NvlkJ02fcN+ijZVwKWxsFs eCcXl5li6zxivlqXCLUqwfS5QfaohxAvGeZISwxlB5L+VF/ZM6OP5T6BnZm867Qk ZSRzS3f5Kyb+dvx9m25BSbr0k3riNCt9XPHqcuThrYZaBONaplUUWqLxMkftVEfX YKY2LXVpOWu1mz8=
    =RkmE
    -----END PGP SIGNATURE-----

    --- SoupGate-Win32 v1.05
    * Origin: fsxNet Usenet Gateway (21:1/5)