Re: Running KDC as non-root and dockerize KDC

2019-01-05 Thread Russ Allbery
Grant Taylor writes: > Aside: How well would Kerberos work if these services ran on a high > port and IPTables magic was used to redirect requests to the low ports > up to high ports? It should be fine as long as the magic handles both UDP and TCP. Another option would be to run the services o

Re: Running KDC as non-root and dockerize KDC

2019-01-05 Thread Grant Taylor
On 1/4/19 9:14 AM, Robbie Harwood wrote: The KDC and kadmin want several low-number ports, including 88, 749, and possibly 754. It's possible (on Linux) to give utilities access to bind to ports below 1024 as non-root user by adding the cap_net_bind_service capability via the setcap command.