Re: Packing Kerberos Tickets into X.509 certificates

2015-11-01 Thread Rick van Rein
Hi Bryce, > I may be asking a question which exposes either my ignorance or lack > of imagination, but is there a reason a kx509 (RFC6717/RFC4556) > certificate wouldn't work? Wouldn't it be easier to add support for > these previously defined extensions? > I'm happy to answer that of course; but

Re: daily latency spike

2015-11-01 Thread Russ Allbery
"Paul B. Henson" writes: > We currently have two kerberos realms, each consisting of three systems > (1 physical box and 2 virtual machines). For a while now we've been > having an issue where once a day, almost exactly every 24 hours, the two > physical boxes have a latency spike and don't respo

daily latency spike

2015-11-01 Thread Paul B. Henson
We currently have two kerberos realms, each consisting of three systems (1 physical box and 2 virtual machines). For a while now we've been having an issue where once a day, almost exactly every 24 hours, the two physical boxes have a latency spike and don't respond to authentication requests, to t