krb5 + nscd + SRV records

Jack Neely jjneely at ncsu.edu
Tue Jun 30 21:13:12 UTC 2009


Folks,

I'm trying to track down a kerberos weirdness and would appreciate some
help.

I'm using a krb5.conf from my production RHEL5 machines in f11 which is
set to lookup the KDC's using DNS for the EOS.NCSU.EDU realm.  A kinit
-5 <username> returns the following:

kinit(v5): Cannot resolve network address for KDS in realm EOS.NCSU.EDU
while getting initial credentials

If I turn on the nscd daemon the above kinit command works as expected
and I have tickets.  Turn nscd off, and the above error returns.

I've strace'd kinit and I see it pulling down the KDC DNS names but I
can't figure out what is happening to produce the error.  Thoughts?

Jack Neely

-- 
Jack Neely <jjneely at ncsu.edu>
Linux Czar, OIT Campus Linux Services
Office of Information Technology, NC State University
GPG Fingerprint: 1917 5AC1 E828 9337 7AA4  EA6B 213B 765F 3B6A 5B89




More information about the fedora-test-list mailing list