multiple kdc masters with resilient LDAP backend

2010-02-02 Thread rhod davies
Hi, I've been reading through the mail archives, and doing the obligatory google search, but seem to be hitting a brick wall on trying to get a better understanding of something that should be trivial to get a handle on (I think). MIT Kerberos 1.7 configured with a KLDAP backend to a

Re: multiple kdc masters with resilient LDAP backend

2010-02-02 Thread Ken Raeburn
On Feb 2, 2010, at 07:35, rhod davies wrote: I understand that we can run multiple KDCs in an autonomous way, but sharing the same data store (in LDAP), this is good, and what I want to have - i.e. a resilient KDC service. We can misplace a data centre, but still offer a KDC service as LDAP

Re: multiple kdc masters with resilient LDAP backend

2010-02-02 Thread Simo Sorce
On Tue, 2 Feb 2010 12:35:53 + rhod davies nomr...@googlemail.com wrote: Hi, I've been reading through the mail archives, and doing the obligatory google search, but seem to be hitting a brick wall on trying to get a better understanding of something that should be trivial to get a

Re: multiple kdc masters with resilient LDAP backend

2010-02-02 Thread rhod davies
On Tuesday, February 2, 2010, Ken Raeburn raeb...@mit.edu wrote: You can also run multiple KDCs with replicated data without LDAP; the data just needs to be replicated from one master KDC to the others, and MIT ships code to do that, all at once or incrementally.  If the master KDC should go