Uploaded image for project: 'Ambari'
  1. Ambari
  2. AMBARI-20586

Add (optional) master_kdcs to kerberos-env and generated krb5.conf file

    XMLWordPrintableJSON

Details

    • Bug
    • Status: Resolved
    • Major
    • Resolution: Fixed
    • None
    • 3.0.0, 2.5.1
    • None
    • None

    Description

      Add (optional) master_kdcs to kerberos-env and generated krb5.conf file. If kerberos-env/master_kdcs is not empty, it should contain a list of IP addresses or FQDNs for one or more KDCs. Multiple entries should be comma-delimited.

      According to https://web.mit.edu/kerberos/krb5-1.12/doc/admin/conf_files/krb5_conf.html:

      master_kdc

      Identifies the master KDC(s). Currently, this tag is used in only one case: If an attempt to get credentials fails because of an invalid password, the client software will attempt to contact the master KDC, in case the user’s password has just been changed, and the updated database has not been propagated to the slave servers yet.

      This should help with scenarios where multiple KDCs are in a master/slave (or replicated) configuration.

      Attachments

        1. AMBARI-20586-Master-kdc_trunk_v4.patch
          17 kB
          Balázs Bence Sári

        Issue Links

          Activity

            People

              bsari Balázs Bence Sári
              bsari Balázs Bence Sári
              Votes:
              0 Vote for this issue
              Watchers:
              4 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved: