# ============================================================================= # settings.conf - every tunable value for the Kerberos kit, in one place # ============================================================================= # Both start-kerberos.sh and test-kerberos.sh read this file. # Edit a value here, then re-run ./start-kerberos.sh so the KDC picks it up. # (If you change a value in section 3 that changes the database, such as the # number of principals, start-kerberos.sh rebuilds the test database.) # # Any value can also be overridden for a single run from the command line: # DURATION=30 ./test-kerberos.sh as # ============================================================================= # ----------------------------------------------------------------------------- # 1. The test realm, and where its servers are reached # ----------------------------------------------------------------------------- # A separate realm used only for testing. The ".TEST" ending is reserved for # testing (RFC 6761), so it can never clash with a real realm. REALM="PERF.TEST" # All test traffic stays on this machine (loopback). No traffic leaves the host. KDC_ADDRESS="127.0.0.1" KDC_PORT="${KDC_PORT:-88}" # KDC: tickets (AS and TGS requests), UDP + TCP KADMIN_PORT="${KADMIN_PORT:-749}" # kadmind: remote administration KPASSWD_PORT="${KPASSWD_PORT:-464}" # kadmind: password changes # These are the standard Kerberos ports. SELinux on RHEL already allows the # Kerberos daemons to use them. If you change them, SELinux (enforcing) also # needs: semanage port -a -t kerberos_port_t -p udp (and -p tcp) # ----------------------------------------------------------------------------- # 2. Files and services used on the server # ----------------------------------------------------------------------------- # The kit never edits /etc/krb5.conf, /var/kerberos/krb5kdc/kdc.conf or the # normal krb5kdc / kadmin services. It writes its own files and runs its own # two services. "./start-kerberos.sh cleanup" removes all of these again. # # The file names are chosen so that SELinux gives them the right labels # automatically (for example, the database name must start with "principal"). KDC_DIR="/var/kerberos/krb5kdc" KDC_CONF="$KDC_DIR/perf-test-kdc.conf" # KDC + kadmind configuration CLIENT_CONF="$KDC_DIR/perf-test-krb5.conf" # client configuration (realm, KDC address) TCP_CLIENT_CONF="$KDC_DIR/perf-test-krb5-tcp.conf" # small add-on: "always use TCP" ACL_FILE="$KDC_DIR/perf-test-kadm5.acl" # who may administer the realm DATABASE="$KDC_DIR/principal-perf-test" # the principal database STASH_FILE="$KDC_DIR/.k5.$REALM" # master key, so the KDC starts unattended USER_KEYTAB="$KDC_DIR/perf-test-users.keytab" # keys of the test users ADMIN_KEYTAB="$KDC_DIR/perf-test-admin.keytab" # key of the test administrator DB_INFO_FILE="$KDC_DIR/perf-test-db.info" # what the database was built with KDC_LOG="/var/log/krb5kdc.log.perf-test" KADMIN_LOG="/var/log/kadmind.log.perf-test" KDC_SERVICE="krb5kdc-perf-test" # systemd service names KADMIN_SERVICE="kadmind-perf-test" # ----------------------------------------------------------------------------- # 3. KDC and database settings # ----------------------------------------------------------------------------- # Database back end: "db2" (the classic default) or "lmdb" (newer, often # faster under many parallel logins). Both are part of RHEL's krb5-server. DB_BACKEND="${DB_BACKEND:-db2}" # Worker processes of the KDC. 0 = one single process (the RHEL default). # A number N starts N worker processes (krb5kdc -w N) that share the work. KDC_WORKERS="${KDC_WORKERS:-0}" # Principals (accounts) created in the test database: TEST_USERS="${TEST_USERS:-1000}" # perfuser00001 ... : log in during the tests TEST_SERVICES="${TEST_SERVICES:-100}" # HTTP/web0001.perf.test ... : services users ask tickets for FILLER_PRINCIPALS="${FILLER_PRINCIPALS:-10000}" # never used; they make the database realistically big # Encryption types the KDC creates keys for (the RHEL 9 defaults, without the # old camellia and RC4 types). The first one is used when both sides support it. SUPPORTED_ENCTYPES="aes256-cts-hmac-sha384-192:normal aes128-cts-hmac-sha256-128:normal aes256-cts-hmac-sha1-96:normal aes128-cts-hmac-sha1-96:normal" MASTER_KEY_TYPE="aes256-cts-hmac-sha384-192" # Pre-authentication method. RHEL 9 enables SPAKE by default, on both the KDC # and the clients ("yes"). "no" = the older encrypted-timestamp method, which # needs one network round trip less per login. SPAKE_PREAUTH="${SPAKE_PREAUTH:-yes}" # After every successful login the KDC writes the login time into the database # ("last successful login"). That is a disk write per login. "false" is the # MIT and RHEL default; "true" switches the write off (faster logins). DISABLE_LAST_SUCCESS="${DISABLE_LAST_SUCCESS:-false}" # ----------------------------------------------------------------------------- # 4. How hard and how long each test runs # ----------------------------------------------------------------------------- DURATION="${DURATION:-10}" # seconds of load for each test run # "Clients" = client processes of the load generator (lib/krb5-load.py). Each # one sends a request, waits for the answer, and sends the next one at once. CLIENTS="${CLIENTS:-8}" # "as", "tgs", "tcp" tests CLIENT_LEVELS="${CLIENT_LEVELS:-1 2 4 8 16 32 64}" # "concurrency" test steps # The steady, "normal day" load used by the latency, cpu and memory tests: # LOGIN_RATE users log in per second (AS request), and each of them then asks # for TGS_PER_LOGIN service tickets (TGS requests), like a user who opens a # few intranet sites or file shares after logging in. LOGIN_RATE="${LOGIN_RATE:-100}" TGS_PER_LOGIN="${TGS_PER_LOGIN:-4}" STARTUP_ROUNDS="${STARTUP_ROUNDS:-3}" # KDC restarts measured by the "startup" test KADMIN_OPERATIONS="${KADMIN_OPERATIONS:-1000}" # principals added/read/changed/deleted by "kadmin" DUMP_ROUNDS="${DUMP_ROUNDS:-3}" # database dumps timed by the "dump" test # The KDC writes one log line per request (about 470 bytes), so a full test # run adds about 100 to 150 MB to its log. "yes" empties the test KDC log at the # start of every test run; "no" keeps it growing. RESET_KDC_LOG_BEFORE_TEST="${RESET_KDC_LOG_BEFORE_TEST:-yes}" # ----------------------------------------------------------------------------- # 5. Pass / fail targets # ----------------------------------------------------------------------------- # Sensible starting points for a small RHEL 9 KDC tested over localhost. # Adjust them to your own hardware and service requirements. A result that # misses its target is reported as FAIL; see PERFORMANCE-METRICS.md for what # each number means. TARGET_STARTUP_MAX_MS="${TARGET_STARTUP_MAX_MS:-5000}" # start until first ticket TARGET_AS_MIN_RPS="${TARGET_AS_MIN_RPS:-500}" # logins (TGTs) per second, at least TARGET_TGS_MIN_RPS="${TARGET_TGS_MIN_RPS:-1000}" # service tickets per second, at least TARGET_AS_P95_MAX_MS="${TARGET_AS_P95_MAX_MS:-20}" # 95% of logins faster than TARGET_AS_P99_MAX_MS="${TARGET_AS_P99_MAX_MS:-50}" # 99% of logins faster than TARGET_TGS_P95_MAX_MS="${TARGET_TGS_P95_MAX_MS:-10}" # 95% of service tickets faster than TARGET_TGS_P99_MAX_MS="${TARGET_TGS_P99_MAX_MS:-25}" # 99% of service tickets faster than TARGET_ERRORS_MAX_PCT="${TARGET_ERRORS_MAX_PCT:-0.1}" # failed requests at the steady load TARGET_SCALING_MIN_PCT="${TARGET_SCALING_MIN_PCT:-70}" # throughput kept at top level vs peak TARGET_TCP_MIN_RPS="${TARGET_TCP_MIN_RPS:-300}" # logins per second over TCP TARGET_KADMIN_MIN_OPS="${TARGET_KADMIN_MIN_OPS:-100}" # admin operations per second (slowest kind) TARGET_DUMP_MAX_S="${TARGET_DUMP_MAX_S:-30}" # full database dump, at most TARGET_CPU_MAX_PCT="${TARGET_CPU_MAX_PCT:-50}" # KDC CPU at the steady load, % of one core TARGET_MEMORY_MAX_MB="${TARGET_MEMORY_MAX_MB:-256}" # peak KDC memory, at most