Sei sulla pagina 1di 1

Installing KDCs

When setting up Kerberos in a production environment, it is best to have multiple


slave KDCs alongside with a master KDC to ensure the continued availability of the
Kerberized services. Each KDC contains a copy of the Kerberos database. The master
KDC contains the writable copy of the realm database, which it replicates to the
slave KDCs at regular intervals. All database changes (such as password changes)
are made on the master KDC. Slave KDCs provide Kerberos ticket-granting services,
but not database administration, when the master KDC is unavailable. MIT recommends
that you install all of your KDCs to be able to function as either the master or
one of the slaves. This will enable you to easily switch your master KDC with one
of the slaves if necessary (see Switching master and slave KDCs). This installation
procedure is based on that recommendation.

Potrebbero piacerti anche