
Step one in an AFS cell is getting kerberos working. This does not provide end-to-end KDC management - the realm still needs to be created by hand. Change-Id: I891d784d676ab79e7aca9c883dd9e705a30db6e5
17 lines
490 B
Plaintext
17 lines
490 B
Plaintext
[kdcdefaults]
|
|
kdc_ports = 750,88
|
|
|
|
[realms]
|
|
<%= @realm %> = {
|
|
database_name = /var/lib/krb5kdc/principal
|
|
admin_keytab = FILE:/etc/krb5kdc/kadm5.keytab
|
|
acl_file = /etc/krb5kdc/kadm5.acl
|
|
key_stash_file = /etc/krb5kdc/stash
|
|
kdc_ports = 750,88
|
|
max_life = 10h 0m 0s
|
|
max_renewable_life = 7d 0h 0m 0s
|
|
master_key_type = aes256-cts
|
|
supported_enctypes = aes256-cts:normal
|
|
default_principal_flags = +preauth
|
|
}
|