NetID Kerberos KDC
- KDC stands for Key Distribution Center
- Provides central AuthN for Cornell NetIDs
- Hands out Kerberos 4 and Kerberos 5 tickets for NetIDs
- Provides cross-realm authentication for some groups on campus
- Uses MIT Kerberos 1.3.6 (with a small local mod)
- Fail over provided by Kerberos software on clients
- Clients try to contact primary Kerberos server
- If they can not, they contact the secondary Kerberos server
- No dynamic load balancing
- OS: Red Hat Enterprise Linux 4
- Production: 2 machines (primary and secondary)
- Machines are in server farm (Dell x86)
- Two factor AuthN required for SSH login
- Machines are split between Rhodes and CCC
- Test: 2 machines
- Dev: 1 machine