summaryrefslogtreecommitdiffstats
path: root/install/share/kdc.conf.template
blob: 232fedc445f660c30a88d8844d9f1b6042db41a7 (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
[kdcdefaults]
 kdc_ports = 88
 kdc_tcp_ports = 88
 restrict_anonymous_to_tgt = true
 spake_preauth_kdc_challenge = edwards25519

[realms]
 $REALM = {
  master_key_type = aes256-cts
  max_life = 7d
  max_renewable_life = 14d
  acl_file = $KRB5KDC_KADM5_ACL
  dict_file = $DICT_WORDS
  default_principal_flags = +preauth
;  admin_keytab = $KRB5KDC_KADM5_KEYTAB
  pkinit_identity = FILE:$KDC_CERT,$KDC_KEY
  pkinit_anchors = FILE:$KDC_CERT
  pkinit_anchors = FILE:$CACERT_PEM
  pkinit_pool = FILE:$CA_BUNDLE_PEM
  pkinit_indicator = pkinit
  spake_preauth_indicator = hardened
  encrypted_challenge_indicator = hardened
 }