You can list as many as you like. You can also use DNS srv records which AD usually defines automatically ( if you run DNS on it too)

Also squid does not require any kdc. The client does all the communication to AD (That is why Kerberos should perform better then NTLM)

Regards
Markus

"Mrvka Andreas" <m...@tuv.at> wrote in message news:200910021209.19296....@tuv.at...
Hi list,

does anybody know if there is any change to define a backup kerberos
authentication server?

Do I have to set anything in krb5.conf to support more than one AD server?

If I want to reboot the kerberos server squid should still be able to
authenticate.

Are there any hints?

Regards
Andrew



Reply via email to