Re: newsletter: Slow page loads when in failover with mod_auth_kerb
2012-03-07 22:30:44 GMT
Found a smoking gun when creating a parallel lab environment. This is a forehead slapping ommission from my original problem description so apologies in advance!
I did not mention that I contact my web server via a CNAME alias of "www". i.e. http://www gets you to our intranet that is mod_auth_kerb protected. The servername is of the form server1.ny1.example.com. In the normal case, this doesnt make any appreciable difference to the client connections. The client is able to authenticate to the http://www server instantaneously and no problem. In a failure scenario, every page takes 30 seconds. However, pointing the browser directly at http://server1 instead of the CNAME is instantaneous even in the failure scenario.
If you are using another kerberized application like ssh, running an ssh login to the cname "www" is fine - i.e. passwordless kerberos works fine and the timeout is a couple of seconds as expected. It is only apache/mod_auth_kerb that has this very specific issue with using a CNAME when one of the kerberos servers is down.
Not sure if this clarifies anything or muddies the waters further though!
------------------------------------------------------------------------------ Virtualization & Cloud Management Using Capacity Planning Cloud computing makes use of virtualization - but cloud computing also focuses on allowing computing to be delivered as a service. http://www.accelacomm.com/jaw/sfnl/114/51521223/
_______________________________________________ modauthkerb-help mailing list modauthkerb-help <at> lists.sourceforge.net https://lists.sourceforge.net/lists/listinfo/modauthkerb-help

RSS Feed