Incidence Report: KDC Connection Timeout in Multi-Master IdM
- Date:
2026-04-19
- Status:
Resolved
- Node:
ipa02.raulvilchez.org (Replica)
- Standard:
IdM documentation standard strictly in English
Description
Users experienced a failure when requesting initial Kerberos credentials (kinit) from the workstation. The command returned the error: kinit: Cannot contact any KDC for realm 'RAULVILCHEZ.ORG'.
Infrastructure Context
The environment consists of two main nodes:
* Master Server: ipa.raulvilchez.org (192.168.17.39)
* Replica Server: ipa02.raulvilchez.org (192.168.17.40)
The issue occurred while the Master node was offline to optimize resource usage, leaving the Replica as the sole active KDC.
Root Cause Analysis
Diagnostic traces (KRB5_TRACE) revealed that the client was bypassing the local configuration and attempting to connect exclusively to the offline Master IP (.39). Two main misconfigurations were identified:
SSSD Service Discovery: The
/etc/sssd/sssd.conffile was configured withipa_server = _srv_, ipa.raulvilchez.org. The_srv_lookup was prioritizing the Master node, and the explicit fallback pointed only to the offline Master.DNS/Kerberos Interaction: With
dns_lookup_kdc = trueenabled inkrb5.conf, the Kerberos client ignored the manual priority list, favoring SRV records that included the unreachable Master node.
Resolution Actions
The following steps were implemented to restore service using the active Replica:
SSSD Configuration: Updated
ipa_serverinsssd.confto explicitly prioritize the Replica:ipa_server = ipa02.raulvilchez.org, ipa.raulvilchez.org- Kerberos Optimization: * Adjusted
udp_preference_limit = 1to force TCP and ensure faster failover. Verified that
/etc/krb5.conf.d/freeiparemains intact to preserve SPAKE pre-authentication (edwards25519).
- Kerberos Optimization: * Adjusted
Cache Purge: Executed
sss_cache -Eand restarted thesssdservice to clear the “dead” status of the KDC nodes.
Verification
Connectivity: Verified port 88 connectivity via
nc -zv 192.168.17.40 88.Authentication: Successful ticket granting confirmed via
kinit raul-ipa.DNS Resolution: Verified SRV records using
dig -t SRV _kerberos._udp.RAULVILCHEZ.ORG.
Notes
When the Master node (ipa.raulvilchez.org) is returned to service, the ipa_server parameter can be reverted to _srv_ to restore automated load balancing.