Active Directory on Ubuntu kerberos

Christopher Chan christopher.chan at bradbury.edu.hk
Tue Nov 16 23:30:18 UTC 2010


Chris,

You should be modifying krb5.conf, not kdc.conf.


           default_realm = local.bfs.uk.com
[realms]
           bradbury.lan = {
                  kdc = ???.local.bfs.uk.com
                  admin_server = ???.local.bfs.uk.com
           }

[domain_realm]

           local.bfs.uk.com = LOCAL.BFS.UK.COM


Get rid of the kdc.conf file.

cheers,

Christopher


On Tuesday, November 16, 2010 10:53 PM, Chris Robinson wrote:
> Hi
>
> I can not get k functions to work.
>
> [kdcdefaults]
> kdc_ports =
> 750,88
> default_realm =
> local.bfs.uk.com
> [realms]
> local.bfs.uk.com =
> {
> database_name =
> /var/lib/krb5kdc/principal
> admin_keytab =
> FILE:/etc/krb5kdc/kadm5.keytab
> acl_file =
> /etc/krb5kdc/kadm5.acl
> key_stash_file =
> /etc/krb5kdc/stash                                             kdc_ports
> = 750,88
> max_life = 10h 0m
> 0s
> max_renewable_life = 7d 0h 0m
> 0s                                                master_key_type =
> des3-hmac-sha1
> supported_enctypes = aes256-cts:normal arcfour-hmac:normal
> des3-hmac-sha1:normal des-cbc-crc:normal des:normal des:v4 des:norealm
> des:onlyrealm des:afs3        default_principal_flags =
> +preauth
> }
> ~
> ~
> ~
>
>
> config file
> [kdcdefaults]
> kdc_ports =
> 750,88
> default_realm =
> local.bfs.uk.com
> [realms]
> local.bfs.uk.com =
> {
> database_name =
> /var/lib/krb5kdc/principal
> admin_keytab =
> FILE:/etc/krb5kdc/kadm5.keytab                                  acl_file
> = /etc/krb5kdc/kadm5.acl
> key_stash_file =
> /etc/krb5kdc/stash                                            kdc_ports
> = 750,88
> max_life = 10h 0m
> 0s
> max_renewable_life = 7d 0h 0m
> 0s                                               master_key_type =
> des3-hmac-sha1
> supported_enctypes = aes256-cts:normal arcfour-hmac:normal
> des3-hmac-sh1:normal des-cbc-crc:normal des:normal des:v4 des:norealm
> des:onlyrealm des:afs        default_principal_flags =
> +preauth
> }
> ~
>
>
> Chris
>
>





More information about the ubuntu-users mailing list