You are viewing an old version of this page. View the current version.

Compare with Current View Page History

« Previous Version 5 Next »

NetID Kerberos KDC

  • KDC stands for Key Distribution Center
  • Provides central AuthN for Cornell NetIDs
  • Hands out Kerberos 4 and Kerberos 5 tickets for NetIDs
  • Provides cross-realm authentication for some groups on campus
  • Uses MIT Kerberos 1.3.6 (patched with a local mod)
  • Fail over provided by Kerberos software on clients
    • Clients try to contact primary Kerberos server
    • If they can not, they contact the secondary Kerberos server
  • No dynamic load balancing
  • OS: Red Hat Enterprise Linux 4
  • Production: 2 machines (primary and secondary)
  • Machines are in server farm (Dell x86)
    • Two factor AuthN required for SSH login
    • Machines are split between Rhodes and CCC
  • Test: 2 machines
  • Dev: 1 machine
  • No labels