[cups.development] [RFE] STR #3634: virtual host support for kerberos authentication

Mark Dieterich mkd at cs.brown.edu
Wed Aug 11 08:38:01 PDT 2010


DO NOT REPLY TO THIS MESSAGE.  INSTEAD, POST ANY RESPONSES TO THE LINK BELOW.

[STR New]

We are actually running version 1.3.7 under Centos, but this version wasn't
available from the drop down menu.  I'm also not sure whether this is a bug
report or a feature request, so please feel free to adjust the priority as
you see fit.

Our setup includes two servers configured via heartbeat for high
availability printing.  They share a virtual hostname of "printhost" and
this is the machine all print jobs/commands are sent to.  As such, we
define the ServerName to be printhost in the configuration.  The problem
comes in when we try to use kerberos authentication for job control.  The
cups daemon doesn't seem to honor/use the service principle ipp/printhost,
instead it appears to look for its own hostname.  This means a client can't
rely on kerberized communication to the virtual hostname and must use the
real hostname instead.

Looking at the network traffic between the server and the client, it
appears to have correctly bound to the virtual IP and all communications
are done via this ip.  I suspect this will just require having the server
look for a ServerName setting in the configuration and, if found, have it
search for and use the appropriate kerberos host and service principles.

Thanks!

Mark

Link: http://www.cups.org/str.php?L3634
Version:  -feature





More information about the cups mailing list