libdefaults
This stanza contains parameters relevant to the operation of the Kerberos library. The settings in this stanza apply globally to all of the Kerberos library functions for applications running on this host. Available settings in this stanza include:
- default_realm
This is the most important setting in the krb5.conf file. The default_realm key defines the default realm that Kerberos clients and services will use. This should be set to the realm that this machine is a member of.
- clockskew
The clockskew key defines the amount of time in seconds that the Kerberos library will allow two clocks to differ by and still consider the message valid. By default this setting is 300 seconds, or 5 minutes.
- default_tkt_enctypes
This key defines the list of session key encryption types that the KDC will return to clients. This list can be separated by whitespace or commas. For example:
default_tkt_enctypes = des3-hmac-sha1 des-cbc-crc
- default_tgs_enctypes
This key defines the list of session key encryption types requested by the Kerberos client libraries. This parameter takes the same type of options as the default_tkt_enctypes key above.
- noaddresses
Setting this key to “yes” will cause the Kerberos library to request addressless tickets from the KDC. This option can be helpful when using NAT. More information on the affect of NAT on Kerberos can be found in Section 6.5.2 in Chapter 6.
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access