Re: Running KDC as non-root and dockerize KDC

2019-01-06 Thread Russ Allbery
Grant Taylor writes: > Do you happen to know off hand if DNS lookups for SRV records happen > before or after initial connection attempts to the standard ports? > If SRV records are looked up /before/ attempting to connect to standard > ports, I could see adding SRV records as a simple optimizat

Re: Running KDC as non-root and dockerize KDC

2019-01-06 Thread Grant Taylor
On 1/5/19 12:24 PM, Russ Allbery wrote: It should be fine as long as the magic handles both UDP and TCP. ACK It's trivial to add IPTables rules (the magic I was thinking of) to handle both UDP and TCP. Another option would be to run the services on non-standard ports and configure the clie