DNS Domain Name-to-Realm Mapping
Kerberos can also use DNS for domain name-to-realm mapping. This mapping, provided by the domain_realm stanza in MIT-style krb5.conf files, can also be provided through TXT records in DNS. The TXT record format for specifying domain name-to-realm mappings is similar to the SRV record format for locating Kerberos KDCs within a given Kerberos realm. It contains three major fields:
- Service
This field is always
_kerberos.- Domain/host name
This field is the DNS domain name or hostname.
- Realm name
This field is the Kerberos realm associated with the domain name in the previous field.
An example, mapping all hosts within the domain wedgie.org to the Kerberos realm WEDGIE.ORG is shown below:
_kerberos.wedgie.org. IN TXT "WEDGIE.ORG"
Note that the latest Kerberos Clarifications call for less dependence on the insecure DNS service to perform domain name-to-realm mapping for future implementations of Kerberos. This DNS-to-realm mapping is used by Windows’ Active Directory services to locate realm information, and was documented as part of an Internet Draft. However, the most recent Kerberos Clarifications drafts obsoletes the older Internet Draft and strongly recommends against using unsecured DNS services to provide this mapping.
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access