KDC.CONF(5) MIT Kerberos KDC.CONF(5) (NAME) kdc.conf - (KDC) kdc.conf krb5.conf KDC krb5kdc kadmind kdb5_util. krb5.conf KDC krb5.conf kdc.conf . kdc.conf KDC /var/lib/krb5kdc . KRB5_KDC_PROFILE . KDC . (STRUCTURE) kdc.conf krb5.conf . (SECTIONS) kdc.conf : +--------------+-----------------------------------+ |[kdcdefaults] | | | | | | | KDC | +--------------+-----------------------------------+ |[realms] | | | | | | | | | | | | | | +--------------+-----------------------------------+ |[dbdefaults] | | | | | | | | +--------------+-----------------------------------+ |[dbmodules] | | | | | | | | +--------------+-----------------------------------+ |[logging] | | | | | | | | | | () | | | | | | | +--------------+-----------------------------------+ [kdcdefaults] [kdcdefaults] [realms] . [realms] . o host_based_services o kdc_listen o kdc_ports o kdc_tcp_listen o kdc_tcp_ports o no_host_referral o restrict_anonymous_to_tgt [kdcdefaults] : kdc_max_dgram_reply_size UDP . . kdc_tcp_listen_backlog ( .) KDC . . . spake_preauth_kdc_challenge (.) SPAKE . spake_preauth_groups [libdefaults] . . ( 1.17.) [realms] [realms] . KDC . ATHENA.MIT.EDU : [realms] ATHENA.MIT.EDU = { max_renewable_life = 7d 0h 0m 0s } [realms] : acl_file (.) (ACL) kadmind . ACL acl_file = "" . /var/lib/krb5kdc/kadm5.acl . ACL kadm5.acl . database_module (.) [dbmodules] . . . database_name ( .) DB2 [dbmodules] . /var/lib/krb5kdc/principal . default_principal_expiration ( .) . 0 . default_principal_flags ( .) . '+' '-' . postdateable forwardable tgt-based renewable proxiable dup-skey allow-tickets service . : allow-tickets KDC . . dup-skey KDC -- (user-to-user) . forwardable (forwardable) . hwauth . no-auth-data-required PAC AD-SIGNEDPATH . ok-as-delegate . ok-to-auth-as-delegate S4USelf . postdateable (postdateable) . preauth KDC . (TGT) (preauthenticated) . proxiable . pwchange . pwservice . . renewable (renewable) . service KDC . . dup-skey -- . tgt-based (TGT) (TGT) . dict_file (.) . (whitespace) . . disable_pac ( .) true KDC PAC S4U2Self S4U2Proxy . false KDC PAC . 1.20. encrypted_challenge_indicator (.) (authentication indicator) KDC FAST . 1.16. host_based_services ( .) (host-based referral) . iprop_enable ( .) (iprop) . false . iprop_ulogsize ( .) (log entries) (iprop) . 1000 . 1.11 2500 . 1.19. iprop_master_ulogsize iprop_ulogsize 1.19. iprop_ulogsize (fallback) . iprop_replica_poll ( [Delta time].) KDC (Replica) (Primary) (poll) . 2m ( ) . 1.17. iprop_slave_poll ( [Delta time].) iprop_replica_poll 1.17. iprop_replica_poll (fallback) . iprop_listen ( .) / RPC iprop kadmind . (interface) (:) . ([]) . (wildcard) . kadmind (bind) . ( iprop_enable true ) iprop_port . 1.15. iprop_port ( .) (iprop) . iprop_enable true KDC (Replica) iprop_listen (Primary) . iprop_listen kadmind (override). iprop_resync_timeout ( [Delta time].) . KDC (Replica) . (5m) . 1.11. iprop_logfile ( .) (update log) . database_name realms krb5 .ulog . (: database_name realms LDAP [dbmodules] (hard-coded) database_name . iprop_logfile [dbmodules] .) kadmind_listen ( .) / RPC kadmin kadmind . (interface) (:) (UNIX domain socket) . ([]) . (wildcard) . kadmin RPC kadmind_listen = "" . kadmind (bind) . kadmind_port kadmin (749) . 1.15. kadmind_port ( .) kadmind . kadmind_listen (override). kadmind 749 . key_stash_file (.) ( kdb5_util stash). /var/lib/krb5kdc/.k5.REALM REALM . kdc_listen ( .) / krb5kdc . (interface) (:) . ([]) . (wildcard) . (88) . UDP kdc_listen = "" . KDC (bind) . . 1.15. kdc_ports ( .) 1.15 krb5kdc UDP . 1.15 kdc_listen . kdc_tcp_listen ( .) / TCP krb5kdc . (syntax) kdc_listen . TCP kdc_tcp_listen = "" . UDP . 1.15. kdc_tcp_ports ( .) 1.15 krb5kdc UDP . 1.15 kdc_tcp_listen . kpasswd_listen ( .) / kpasswd kadmind . (interface) (:) . ([]) . (wildcard) . kpasswd kpasswd_listen = "" . kadmind (bind) . kpasswd_port kpasswd (464) . 1.15. kpasswd_port ( .) kadmind . kpasswd_listen (override). 464 . master_key_name (.) (master key) . K/M . master_key_type ( .) . aes256-cts-hmac-sha1-96 . Encryption types . max_life ( Time duration.) . . max_renewable_life ( Time duration.) . 0 . no_host_referral ( .) host_based_services . no_host_referral = * . reject_bad_transit ( .) true KDC (transited realms) (cross-realm) capaths krb5.conf . false . disable-transited-check . reject_bad_transit . TGS . true . restrict_anonymous_to_tgt ( .) true KDC (anonymous) (ticket-granting service) . PKINIT FAST (FAST armor tickets) . false . 1.9. spake_preauth_indicator (.) (authentication indicator) KDC SPAKE . . . 1.17. supported_enctypes ( key:salt.) / (key/salt) . kadmin . aes256-cts-hmac-sha1-96:normal aes128-cts-hmac-sha1-96:normal . Keysalt lists . [dbdefaults] [dbdefaults] [dbmodules] . [dbmodules] . o ldap_kerberos_container_dn o ldap_kdc_dn o ldap_kdc_sasl_authcid o ldap_kdc_sasl_authzid o ldap_kdc_sasl_mech o ldap_kdc_sasl_realm o ldap_kadmind_dn o ldap_kadmind_sasl_authcid o ldap_kadmind_sasl_authzid o ldap_kadmind_sasl_mech o ldap_kadmind_sasl_realm o ldap_service_password_file o ldap_conns_per_server [dbmodules] [dbmodules] KDC . [dbmodules] (realm) database_module . ATHENA.MIT.EDU : [dbmodules] ATHENA.MIT.EDU = { disable_last_success = true } [dbmodules] : database_name DB2 . /var/lib/krb5kdc/principal . db_library . DB2 db2 LMDB klmdb LDAP kldap . disable_last_success true KDC "Last successful authentication" ( ) (principal) . . ( "Last successful authentication" .). . . disable_lockout true KDC "Last failed authentication" ( ) "Failed password attempts" ( ) . . . . ldap_conns_per_server LDAP LDAP . ldap_kdc_dn ldap_kadmind_dn LDAP DN (bind) LDAP . krb5kdc ldap_kdc_dn kadmind ldap_kadmind_dn . kadmind DN LDAP . KDC DN disable_lockout disable_last_success true . SASL ldap_kdc_sasl_mech ldap_kadmind_sasl_mech . ldap_kdc_sasl_mech ldap_kadmind_sasl_mech LDAP SASL ( EXTERNAL) LDAP . .. ldap_kdc_sasl_authcid ldap_kadmind_sasl_authcid LDAP SASL LDAP . SASL . SASL ( DIGEST-MD5) ldap_service_password_file . .. ldap_kdc_sasl_authzid ldap_kadmind_sasl_authzid LDAP (authorization identity) SASL LDAP . . .. ldap_kdc_sasl_realm ldap_kadmind_sasl_realm LDAP SASL LDAP . . .. ldap_kerberos_container_dn LDAP DN (container object) . ldap_servers LDAP LDAP . LDAP (whitespace) . LDAP (URI) . (URL) ldapi: ldaps: LDAP . ldap_service_password_file LDAP ( kdb5_ldap_util stashsrvpw) ldap_kdc_dn ldap_kadmind_dn ldap_kdc_sasl_authcid ldap_kadmind_sasl_authcid SASL . . mapsize LMDB . . "Environment mapsize limit reached" . .. max_readers LMDB . . .. nosync LMDB (throughput) kadmind ( ). KDC . false . .. unlockiter true DB2 (iteration) . true KDC kadmin (dump) . . . [dbmodules] : db_module_dir . . [logging] [logging] krb5kdc kadmind . : admin_server kadmind . kdc krb5kdc . default . debug ( .) SYSLOG . syslog . false . 1.15. : FILE=filename FILE:filename filename . = . : . STDERR . CONSOLE . DEVICE= . SYSLOG[:severity[:facility]] . (severity) (facility) . . (facility) . syslog(3) LOG_ : KERN USER MAIL DAEMON AUTH LPR NEWS UUCP CRON LOCAL0 LOCAL7. AUTH . KDC LOG_DAEMON /var/adm/kadmin.log /dev/tty04 . [logging] kdc = CONSOLE kdc = SYSLOG:INFO:DAEMON admin_server = FILE:/var/adm/kadmin.log admin_server = DEVICE=/dev/tty04 syslog . default = DEVICE=/dev/null . [otp] [otp] OTP . (OTP) RADIUS . : server RADIUS . IP (Unix domain socket) . /var/lib/krb5kdc/.socket . secret ( /var/lib/krb5kdc ) (secret) RADIUS. . server . . timeout KDC RADIUS . OTP . . retries RADIUS . ( ) . strip_realm true principal realm RADIUS . realm . true . indicator (ticket) . . ( 1.14.) UDP : [otp] MyRemoteTokenType = { server = radius.mydomain.com:1812 secret = SEmfiajf42$ timeout = 15 retries = 5 strip_realm = true } DEFAULT principal . . (override) : [otp] DEFAULT = { strip_realm = false } PKINIT (PKINIT OPTIONS) : pkinit . [kdcdefaults] [realms] . [kdcdefaults] . : 1. [realms]: [realms] EXAMPLE.COM = { pkinit_anchors = FILE:/usr/local/example.com.crt } 2. [kdcdefaults]: [kdcdefaults] pkinit_anchors = DIR:/usr/local/generic_trusted_cas/ Specifying PKINIT identity information krb5.conf . pkinit_anchors () KDC . pkinit KDC . . pkinit_dh_min_bits - (Diffie-Hellman) KDC . 1024 2048 P-256 4096 P-384 P-521. 2048 . (P-256 P-384 P-521 1.22 .) pkinit_allow_upn KDC (SAN) UserPrincipalName (UPN) . KDC UPN (principal name) . false . KDC id-pkinit-san RFC 4556 . SAN KDC . pkinit_eku_checking KDC (EKU) . kdc.conf : kpClientAuth EKU id-pkinit-KPClientAuth RFC 4556 . scLogin scLogin EKU (id-ms-kp-sc-logon) . none none EKU . . pkinit_identity X.509 KDC . pkinit KDC . pkinit_indicator pkinit . . ( 1.14 .) pkinit_pool KDC . . pkinit_revoke (CRL) KDC . . pkinit_require_crl_checking . CRL . CRL CRL CA pkinit_require_crl_checking false . pkinit_require_crl_checking true CRL CA . CRL CA pkinit_require_crl_checking true . pkinit_require_freshness PKINIT . false . ( 1.17 .) (ENCRYPTION TYPES) . " (weak)" " (deprecated)" . +---------------------------+-------------------------------+ |des3-cbc-raw | cbc | | | Triple DES () | +---------------------------+-------------------------------+ |des3-cbc-sha1 | Triple DES cbc | |des3-hmac-sha1 | HMAC/sha1 | |des3-cbc-sha1-kd | () | +---------------------------+-------------------------------+ |aes256-cts-hmac-sha1-96 | AES-256 CTS | |aes256-cts aes256-sha1 | HMAC | | | SHA-1 | +---------------------------+-------------------------------+ |aes128-cts-hmac-sha1-96 | AES-128 CTS | |aes128-cts aes128-sha1 | HMAC | | | SHA-1 | +---------------------------+-------------------------------+ |aes256-cts-hmac-sha384-192 | AES-256 CTS | |aes256-sha2 | HMAC | | | | | | SHA-384 | +---------------------------+-------------------------------+ |aes128-cts-hmac-sha256-128 | AES-128 CTS | |aes128-sha2 | HMAC | | | | | | SHA-256 | +---------------------------+-------------------------------+ |arcfour-hmac rc4-hmac | RC4 | |arcfour-hmac-md5 | HMAC/MD5 | | | () | +---------------------------+-------------------------------+ |arcfour-hmac-exp | RC4 | |rc4-hmac-exp | | |arcfour-hmac-md5-exp | | | | HMAC/MD5 () | +---------------------------+-------------------------------+ |camellia256-cts-cmac | Camellia-256 CTS | |camellia256-cts | CMAC | +---------------------------+-------------------------------+ |camellia128-cts-cmac | Camellia-128 CTS | |camellia128-cts | CMAC | +---------------------------+-------------------------------+ |des3 | triple | | | DES: des3-cbc-sha1 | +---------------------------+-------------------------------+ |aes | AES: | | | aes256-cts-hmac-sha1-96 | | | aes128-cts-hmac-sha1-96 | | | aes256-cts-hmac-sha384-192 | | | | | | aes128-cts-hmac-sha256-128 | +---------------------------+-------------------------------+ |rc4 | RC4: | | | arcfour-hmac | +---------------------------+-------------------------------+ |camellia | | | | Camellia: | | | camellia256-cts-cmac | | | camellia128-cts-cmac | +---------------------------+-------------------------------+ DEFAULT . ("-") . ("+") . "DEFAULT -rc4" RC4 "des3 DEFAULT" triple DES . aes128-cts aes256-cts GSSAPI (krb5-1.3.1 ) . krb5 AES KDC . aes128-sha2 aes256-sha2 . . krb5 KDC . - (KEYSALT LISTS) . - (enctype-salttype "keysalt") - (keysalt lists) . - (enctype) (salttype) enc:salt . - (",") . : kadmin -e aes256-cts:normal,aes128-cts:normal kadmin aes256-cts aes128-cts normal . (salt) . : +----------+---------------------------+ |normal | | | | | | | | | | | +----------+---------------------------+ |norealm | | | | | | | | | | | | | | | | | | | | +----------+---------------------------+ |onlyrealm | | | | | | | | | | | | | | | | | +----------+---------------------------+ |special | | | | | | | | +----------+---------------------------+ KDC.CONF (SAMPLE KDC.CONF FILE) kdc.conf : [kdcdefaults] kdc_listen = 88 kdc_tcp_listen = 88 [realms] ATHENA.MIT.EDU = { kadmind_port = 749 max_life = 12h 0m 0s max_renewable_life = 7d 0h 0m 0s master_key_type = aes256-cts-hmac-sha1-96 supported_enctypes = aes256-cts-hmac-sha1-96:normal aes128-cts-hmac-sha1-96:normal database_module = openldap_ldapconf } [logging] kdc = FILE:/usr/local/var/krb5kdc/kdc.log admin_server = FILE:/usr/local/var/krb5kdc/kadmin.log [dbdefaults] ldap_kerberos_container_dn = cn=krbcontainer,dc=mit,dc=edu [dbmodules] openldap_ldapconf = { db_library = kldap disable_last_success = true ldap_kdc_dn = "cn=krbadmin,dc=mit,dc=edu" # ldap_kadmind_dn = "cn=krbadmin,dc=mit,dc=edu" # ldap_service_password_file = /etc/kerberos/service.keyfile ldap_servers = ldaps://kerberos.mit.edu ldap_conns_per_server = 5 } (FILES) /var/lib/krb5kdc/kdc.conf (SEE ALSO) krb5.conf, krb5kdc, kadm5.acl (AUTHORS) (MIT) (COPYRIGHT) 1985-2026, MIT 1.22.2 KDC.CONF(5)