Dear Mit:
I found that in Kebreros core code.if first request reach kadmin process,but 
return to kdc after 1 second, kdc will send the same request to the other 
kadmind process.(in my environment, two Kerberos servers work as double active 
mode)
But actually, first request was processed Successfully, then the other kadmind 
will reject the the same request. These caused error in Kerberos client when I 
run "kinit user".

I wonder why timeout between kdc and kadmind can not config in somewhere else?? 
Or the duration(first request 1 second ,second request 2 seconds) can not be 
changed for some special reasons??
________________________________________________
Kerberos mailing list           Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos

Reply via email to