Existing Network Layout
With the conceptual model in mind, let’s go a little deeper and examine the hosts that are members of each Kerberos realm. Since this is an example, we’ll keep it simple and limit the number of machines to make things easy to follow. Figure 9-2 shows the hosts involved in our sample network, their IP addresses, and what Kerberos realm each host belongs to.
Our existing network has been assigned the 192.168.0.0/16 network block, and is divided into several subnets to separate out the production network, customer hosting network, and lab networks. In the production network, 192.168.1.0/24, there is a Microsoft Active Directory server for the SAMPLE.COM domain that also serves as the Exchange server, known as exchange.sample.com. A Windows desktop machine is a member of the SAMPLE.COM domain, with a DNS name of desktop.sample.com. At the conclusion of this example, it should be possible for technical support personnel to login to the Windows desktop machine and transparently access their accounts on the Unix servers in the hosting.sample.com domain.
Also notable in the production network are several Unix hosts that will be part of the UNIX.SAMPLE.COM realm. The host dns.sample.com handles DNS for the Sample ISP, as well as providing a stratum-2 NTP service for the rest of the Sample ISP network. We’ll use it as our time-synchronization source for Kerberos.
Next, the customer web-hosting subnet at 192.168.2.0/24 contains several Unix-based web servers that will ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access