domain_realm
This stanza defines the DNS domain name to Kerberos realm mappings used by the Kerberos libraries when performing service name canonicalization. When an application wishes to connect to a Kerberized server, it has to acquire a service ticket from the KDC. However, the client requires some method to determine what Kerberos realm, and consequently, what service principal, that it needs to request, and also what KDC to contact. Currently, the MIT and Heimdal distributions use the DNS domain name of the server, coupled with the domain_realm mapping, to determine what Kerberos realm that the server belongs to.
By default, if there is no domain_realm entry for a given hostname, a machine is assumed to be in the realm formed by the domain portion of the hostname, converted to all uppercase. For example, the server bigserver.sample.com would be assumed to be in the realm SAMPLE.COM. Note that this policy would place the server sample.com inside of a realm named COM, which probably isn’t what you want.
The domain_realm stanza contains a list of key/value pairs, where the key is a DNS hostname or domain name, and the value is the associated Kerberos realm for that key. Domain-to-realm mappings for an entire DNS subdomain begin with a single dot (.) to signify that the realm mapping applies to any hosts inside of the given subdomain. Note that more specific entries override less specific ones. For example, given the domain_realm stanza given at the beginning of this section:
[domain_realm] ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access