2007-06-28 18:09:54 -05:00
|
|
|
[kdcdefaults]
|
2008-07-02 09:05:55 -05:00
|
|
|
kdc_ports = 88
|
2008-12-12 19:10:04 -06:00
|
|
|
kdc_tcp_ports = 88
|
2011-01-12 15:43:00 -06:00
|
|
|
restrict_anonymous_to_tgt = true
|
2018-04-09 13:33:56 -05:00
|
|
|
spake_preauth_kdc_challenge = edwards25519
|
2007-06-28 18:09:54 -05:00
|
|
|
|
|
|
|
[realms]
|
|
|
|
$REALM = {
|
2010-11-01 08:33:14 -05:00
|
|
|
master_key_type = aes256-cts
|
2007-06-28 18:09:54 -05:00
|
|
|
max_life = 7d
|
|
|
|
max_renewable_life = 14d
|
2016-03-22 17:32:52 -05:00
|
|
|
acl_file = $KRB5KDC_KADM5_ACL
|
|
|
|
dict_file = $DICT_WORDS
|
2007-06-28 18:09:54 -05:00
|
|
|
default_principal_flags = +preauth
|
2016-03-22 17:32:52 -05:00
|
|
|
; admin_keytab = $KRB5KDC_KADM5_KEYTAB
|
2016-07-26 10:19:01 -05:00
|
|
|
pkinit_identity = FILE:$KDC_CERT,$KDC_KEY
|
2017-05-03 01:09:03 -05:00
|
|
|
pkinit_anchors = FILE:$KDC_CERT
|
2016-03-22 17:32:52 -05:00
|
|
|
pkinit_anchors = FILE:$CACERT_PEM
|
2017-05-03 01:09:03 -05:00
|
|
|
pkinit_pool = FILE:$CA_BUNDLE_PEM
|
2019-07-29 10:17:08 -05:00
|
|
|
pkinit_indicator = pkinit
|
|
|
|
spake_preauth_indicator = hardened
|
|
|
|
encrypted_challenge_indicator = hardened
|
2007-06-28 18:09:54 -05:00
|
|
|
}
|