Service Principal Canonicalization
Service name canonicalization is a hard problem to solve on the client side. There are several solutions that are commonly used for service name canonicalization in current implementations. The first technique employed is to simply take the network name given by the user verbatim, and shift it to lowercase. The service name and the lowercased hostname are concatenated to form the service principal that the client requests from the KDC. This method has a major drawback: many users may use a short hostname or host alias when entering in host names, when the service principal is generated using the fully qualified domain name of the host name. When these names are used in the TGS request to the KDC, then the KDC may not be able to find the service principal, as the hostname given by the user may not be the same as the hostname component of the service principal in the Kerberos database.
The second canonicalization technique uses the DNS. The Kerberos libraries take the hostname given by the user, perform a DNS lookup to get the host’s IP address, and perform a reverse lookup on the IP address to get the host’s primary DNS fully-qualified domain name. This technique solves the problem of a host that has several DNS aliases, but does not solve the problem of a multihomed host that has several IP addresses, each with a different hostname. While this behavior of assigning multiple hostnames to the different interfaces of a multihomed machine is discouraged ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access