Tuesday, December 21, 2010

How to setup Kerberos DNS discovery

Kerberos DNS discovery can simplify the client hosts setup. The following need to be added to zone file.
$ORIGIN dev.local.
_kerberos-adm._tcp      SRV     0 0 749 kdc1
$ORIGIN _udp.dev.local.
_kerberos               SRV     10 0 88 kdc1.dev.local.
_kerberos               SRV     20 0 88 kdc2.dev.local.
_kerberos-master        SRV     0 0 88 kdc1.dev.local.
_kpasswd                SRV     0 0 464 kdc1.dev.local.
The client configuration can now look like this (file /etc/krb5.conf):
[libdefaults]
        default_realm = DEV.LOCAL
# ...
[realms]
        DEV.LOCAL = {
        }

[domain_realm]
Let test this:
deby01:~$ host -t SRV _kerberos._udp
_kerberos._udp.dev.local has SRV record 10 0 88 kdc1.dev.local.

No comments :

Post a Comment