realms
The realms stanza contains parameters that are configurable on a per-realm basis. The most important configuration information contained in this stanza is the list of authoritative KDCs for each realm that this client will communicate with. Also, if settings in the global appdefaults stanza (described above) must be overridden for some Kerberos realms, key/value pairs that are valid for appdefaults may be placed in an appropriate realm entry in the realms stanza.
Each realm entry is comprised of a key whose name is a Kerberos realm. The value is a set of key/value pairs, which define the properties of that realm. The following settings can be found inside of a realm section:
- kdc
Each kdc key defines one KDC in the realm. Multiple kdc directives can be listed when multiple KDCs are present in a realm. An optional port number can follow the domain name of the kdc in this directive, but as all Kerberos 5 implementations listen on the standardized Kerberos port, 88, this port number is not required.
- admin_server
The admin_server key defines the Kerberos administrative server for this realm. This would typically be the master KDC for the realm, and is the server that clients will contact for services such as the kadmin service or password changing requests.
Note that the KDC configuration information may also be stored in DNS SRV records, as covered in Chapter 4.
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access