Re: [Freeipa-devel] KDC proxy URI records

2017-04-28 Thread Christian Heimes
On 2017-04-27 14:00, Martin Bašti wrote: > > > On 26.04.2017 20:41, Simo Sorce wrote: >> On Wed, 2017-04-26 at 12:57 +0200, Martin Bašti wrote: >>> On 25.04.2017 16:57, Martin Bašti wrote: Hello all, I'm going to implement automatic URI records for kdc proxy and I'd like to

Re: [Freeipa-devel] KDC proxy URI records

2017-04-28 Thread Martin Bašti
On 28.04.2017 09:32, Martin Kosek wrote: On 04/27/2017 04:16 PM, Simo Sorce wrote: On Thu, 2017-04-27 at 15:56 +0200, Petr Vobornik wrote: On 04/27/2017 02:19 PM, Christian Heimes wrote: On 2017-04-27 14:00, Martin Bašti wrote: I would like to discuss consequences of adding kdc URI

Re: [Freeipa-devel] KDC proxy URI records

2017-04-28 Thread Martin Kosek
On 04/27/2017 04:16 PM, Simo Sorce wrote: > On Thu, 2017-04-27 at 15:56 +0200, Petr Vobornik wrote: >> On 04/27/2017 02:19 PM, Christian Heimes wrote: >>> On 2017-04-27 14:00, Martin Bašti wrote: I would like to discuss consequences of adding kdc URI records: 1. basically all ipa

Re: [Freeipa-devel] KDC proxy URI records

2017-04-27 Thread Christian Heimes
On 2017-04-27 16:16, Martin Bašti wrote: > > > On 27.04.2017 14:19, Christian Heimes wrote: >> On 2017-04-27 14:00, Martin Bašti wrote: >>> I would like to discuss consequences of adding kdc URI records: >>> >>> 1. basically all ipa clients enrolled using autodiscovery will use >>> kdcproxy

Re: [Freeipa-devel] KDC proxy URI records

2017-04-27 Thread Simo Sorce
On Thu, 2017-04-27 at 15:56 +0200, Petr Vobornik wrote: > On 04/27/2017 02:19 PM, Christian Heimes wrote: > > On 2017-04-27 14:00, Martin Bašti wrote: > > > I would like to discuss consequences of adding kdc URI records: > > > > > > 1. basically all ipa clients enrolled using autodiscovery will >

Re: [Freeipa-devel] KDC proxy URI records

2017-04-27 Thread Martin Bašti
On 27.04.2017 14:19, Christian Heimes wrote: On 2017-04-27 14:00, Martin Bašti wrote: I would like to discuss consequences of adding kdc URI records: 1. basically all ipa clients enrolled using autodiscovery will use kdcproxy instead of KDC on port 88, because URI takes precedence over SRV

Re: [Freeipa-devel] KDC proxy URI records

2017-04-27 Thread Petr Vobornik
On 04/27/2017 02:19 PM, Christian Heimes wrote: On 2017-04-27 14:00, Martin Bašti wrote: I would like to discuss consequences of adding kdc URI records: 1. basically all ipa clients enrolled using autodiscovery will use kdcproxy instead of KDC on port 88, because URI takes precedence over SRV

Re: [Freeipa-devel] KDC proxy URI records

2017-04-27 Thread Christian Heimes
On 2017-04-27 14:00, Martin Bašti wrote: > I would like to discuss consequences of adding kdc URI records: > > 1. basically all ipa clients enrolled using autodiscovery will use > kdcproxy instead of KDC on port 88, because URI takes precedence over > SRV in KRB5 client implementation. Are we ok

Re: [Freeipa-devel] KDC proxy URI records

2017-04-27 Thread Martin Bašti
On 26.04.2017 20:41, Simo Sorce wrote: On Wed, 2017-04-26 at 12:57 +0200, Martin Bašti wrote: On 25.04.2017 16:57, Martin Bašti wrote: Hello all, I'm going to implement automatic URI records for kdc proxy and I'd like to clarify if following URI records are the right one.

Re: [Freeipa-devel] KDC proxy URI records

2017-04-26 Thread Simo Sorce
On Wed, 2017-04-26 at 12:57 +0200, Martin Bašti wrote: > > On 25.04.2017 16:57, Martin Bašti wrote: > > Hello all, > > > > I'm going to implement automatic URI records for kdc proxy and I'd > > like to clarify if following URI records are the right one. > > > > > > _kerberos-adm.example.com. IN

Re: [Freeipa-devel] KDC proxy URI records

2017-04-26 Thread Martin Bašti
On 25.04.2017 16:57, Martin Bašti wrote: Hello all, I'm going to implement automatic URI records for kdc proxy and I'd like to clarify if following URI records are the right one. _kerberos-adm.example.com. IN URI 0 "krb5srv:M:kkdcp:https://ipaserver.example.com/KdcProxy;

[Freeipa-devel] KDC proxy URI records

2017-04-25 Thread Martin Bašti
Hello all, I'm going to implement automatic URI records for kdc proxy and I'd like to clarify if following URI records are the right one. _kerberos-adm.example.com. IN URI 0 "krb5srv:M:kkdcp:https://ipaserver.example.com/KdcProxy; _krb5kdc.example.com. IN URI 0