>>>>> "Lukas" == Lukas Grässlin <lukas.graess...@adfinis.com> writes:

    Lukas> We have a scenario where we need to disable reverse lookups for 
    Lukas> canonicalization in Kerberos as the customer's PTR records are not 
    Lukas> consistent and lead to wrongly requested SPNs otherwise (see 
    Lukas> 
https://web.mit.edu/kerberos/krb5-latest/doc/admin/princ_dns.html#reverse-dns-mismatches)

How are you actually triggering the GSS-API authentication?
ldapsearch in all cases?
And you are confident that libkrb5 is triggering the reverse lookup not
your application?
(I realize that you may be using the same application on Debian and RH,
but there could be differences in the application code).

Reply via email to