Skip to content

docs: note dns_canonicalize_hostname=false may be needed - #3

Merged
kratsg merged 1 commit into
mainfrom
krb5-dns-canonicalize-doc
Sep 4, 2026
Merged

kratsg merged 1 commit into
mainfrom
krb5-dns-canonicalize-doc

Conversation

@kratsg

@kratsg kratsg commented Sep 4, 2026

Copy link
Copy Markdown
Collaborator

Confirmed necessary at UChicago's AF while investigating why cern-get-keytab (used by /v1/keytab) hangs/times out from that cluster — unrelated to the DNS setting itself, but found in the same pass, so documenting it here as a standalone fix. Companion PR: maniaclab/af-mcp-platform#278.

Documentation only — no code or default config changed.

kratsg added a commit to maniaclab/atlas-search-mcp-bridge that referenced this pull request Sep 4, 2026
The redeem->negotiate pipeline now completes end to end but the target
rejects the ticket with 401: GSSAPI canonicalizes the connected host via
a reverse DNS lookup before building the AP-REQ's service principal name,
and os-search-atlas-physics-dev.cern.ch's own TLS certificate shows a
different canonical name (CN=oscqa301.cern.ch) for the same host -- the
SPN curl builds from that canonical name doesn't match what the server's
keytab was issued for, so Apache's mod_auth_gssapi rejects an otherwise-
valid ticket. Same class of DNS-canonicalization issue as
maniaclab/krb5-token-service#3, applied here to curl's GSSAPI layer
rather than kinit's KDC contact. Both rdns and dns_canonicalize_hostname
are set for compatibility across krb5 library versions.

Assisted-by: Claude (Anthropic)
@kratsg
kratsg merged commit a8b258e into main Sep 4, 2026
5 checks passed
@kratsg
kratsg deleted the krb5-dns-canonicalize-doc branch September 4, 2026 07:00
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant