Kerberos DNS discovery can simplify the client hosts setup. The following need to be added to zone file.
$ORIGIN dev.local.
_kerberos-adm._tcp SRV 0 0 749 kdc1
$ORIGIN _udp.dev.local.
_kerberos SRV 10 0 88 kdc1.dev.local.
_kerberos SRV 20 0 88 kdc2.dev.local.
_kerberos-master SRV 0 0 88 kdc1.dev.local.
_kpasswd SRV 0 0 464 kdc1.dev.local.
The client configuration can now look like this (file
/etc/krb5.conf):
[libdefaults]
default_realm = DEV.LOCAL
# ...
[realms]
DEV.LOCAL = {
}
[domain_realm]
Let test this:
deby01:~$ host -t SRV _kerberos._udp
_kerberos._udp.dev.local has SRV record 10 0 88 kdc1.dev.local.
No comments :
Post a Comment