Skip to content

Instantly share code, notes, and snippets.

@lilongen
Last active April 26, 2016 07:04
Show Gist options
  • Save lilongen/0e436f1308a5c149acba3621b1793702 to your computer and use it in GitHub Desktop.
Save lilongen/0e436f1308a5c149acba3621b1793702 to your computer and use it in GitHub Desktop.
KDC configure files example
# /etc/krb5.conf
[logging]
default = FILE:/var/log/krb5libs.log
kdc = FILE:/var/log/krb5kdc.log
admin_server = FILE:/var/log/kadmind.log
[libdefaults]
dns_lookup_realm = false
ticket_lifetime = 24h
renew_lifetime = 7d
forwardable = true
rdns = false
default_realm = YHDC.COM
default_ccache_name = KEYRING:persistent:%{uid}
[realms]
YHDC.COM = {
kdc = 172.17.128.60
admin_server = 172.17.128.60
}
[domain_realm]
.yhdc.com = YHDC.COM
yhdc.com = YHDC.COM
# /var/kerberos/krb5kdc/kdc.conf
default_realm = YHDC.COM
[kdcdefaults]
kdc_ports = 88
kdc_tcp_ports = 88
[realms]
YHDC.COM = {
#master_key_type = aes256-cts
database_name = /var/kerberos/krb5kdc/principal
acl_file = /var/kerberos/krb5kdc/kadm5.acl
dict_file = /usr/share/dict/words
admin_keytab = /var/kerberos/krb5kdc/kadm5.keytab
supported_enctypes = aes256-cts:normal aes128-cts:normal des3-hmac-sha1:normal arcfour-hmac:normal camellia256-cts:normal camellia128-cts:normal des-hmac-sha1:normal des-cbc-md5:normal des-cbc-crc:normal
max_renewable_life = 7d 0h 0m 0s
default_principal_flags = +renewable, +forwardable
}
# /var/kerberos/krb5kdc/kadm5.acl
*/admin@YHDC.COM *
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment