Hello,

I have the following configuration:

I have two realms, A.ABC.COM and B.ABC.COM and one openldap dit (dc=abc,dc=com). I have the master openldap server in location A with the following entry in A.ABC.COM realm database: ldap/[EMAIL PROTECTED] and the respective keytab on the master ldap server. I have the slave openldap server in location B with a krb5.keytab with an entry for ldap/[EMAIL PROTECTED]

I am setting replication between the two sites with a Kerberos principal called replicator. My question is: can I use the same keytab to hold the keys to the same service but for different realms?

I will install a realm ABC.COM to have hierarchical relation ships but for now I wanted to have the above configuration.

Best regards,

M

_________________________________________________________________
Don’t just search. Find. Check out the new MSN Search! http://search.msn.click-url.com/go/onm00200636ave/direct/01/

________________________________________________
Kerberos mailing list           Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos

Reply via email to