You may need a third entry in the keytab for the VIP. IE will look for a HTTP/<vip> ticket.

Regards
Markus


"brendan" <bpk...@gmail.com> wrote in message news:1346159765625-4656345.p...@n4.nabble.com...
i have two squid instances on two separate servers. each is configured with kerberos auth, and when i point at one or the other, the kerberos auth works fine. when i point to a load balanced VIP, the auth does not work. i found the below and tried the method using the one keytab file for both instances
and the -s GSS_C_NO_NAME option in the conf file.  this did not work as
expected.

the load balancing process i am using is the "balance" package for fedora
16. it does a SNAT on all requests it handles. could this be part of why i am having issues? i found a couple of packages that i might be able to use for load balancing in the repos, balance, ipvsadm and haproxy. does anyone
have experience/success with any of these or might one be recommended over
the others?



--
View this message in context: http://squid-web-proxy-cache.1019090.n4.nabble.com/Help-with-Kerberos-Configuration-tp4076779p4656345.html
Sent from the Squid - Users mailing list archive at Nabble.com.



Reply via email to