You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.
ansible-msvsphere.ci/roles/kerberos_kdc/templates/etc/krb5.conf.j2

32 lines
917 B

# To opt out of the system crypto-policies configuration of krb5, remove the
# symlink at /etc/krb5.conf.d/crypto-policies which will not be recreated.
includedir /etc/krb5.conf.d/
[logging]
default = FILE:/var/log/krb5libs.log
kdc = FILE:/var/log/krb5kdc.log
admin_server = FILE:/var/log/kadmind.log
[libdefaults]
dns_lookup_realm = false
ticket_lifetime = 24h
renew_lifetime = 7d
forwardable = true
rdns = false
pkinit_anchors = FILE:/etc/pki/tls/certs/ca-bundle.crt
spake_preauth_groups = edwards25519
dns_canonicalize_hostname = fallback
qualify_shortname = ""
default_realm = {{ kerberos_kdc_realm }}
default_ccache_name = KEYRING:persistent:%{uid}
[realms]
{{ kerberos_kdc_realm }} = {
kdc = {{ kerberos_kdc_domain_name }}
admin_server = {{ kerberos_kdc_domain_name }}
}
[domain_realm]
# .example.com = EXAMPLE.COM
# example.com = EXAMPLE.COM