Rev 10 | Blame | Compare with Previous | Last modification | View Log | RSS feed
[logging]
default = FILE:/var/log/krb5libs.log
kdc = FILE:/var/log/krb5kdc.log
admin_server = FILE:/var/log/kadmind.log
[libdefaults]
dns_lookup_realm = false
dns_lookup_kdc = true
ticket_lifetime = 24h
renew_lifetime = 7d
forwardable = true
default_keytab_name = /etc/krb5.keytab
default_tgs_enctypes = AES256-CTS AES128-CTS RC4-HMAC DES-CBC-MD5 DES-CBC-CRC
default_tkt_enctypes = AES256-CTS AES128-CTS RC4-HMAC DES-CBC-MD5 DES-CBC-CRC
preferred_enctypes = AES256-CTS AES128-CTS RC4-HMAC DES-CBC-MD5 DES-CBC-CRC
pkinit_kdc_hostname = <DNS>
pkinit_anchors = DIR:/var/lib/pbis/trusted_certs
pkinit_cert_match = &&<EKU>msScLogin<PRINCIPAL>
pkinit_eku_checking = kpServerAuth
pkinit_win2k_require_binding = false
pkinit_identities = PKCS11:/opt/pbis/lib64/libpkcs11.so
[realms]
UJSOFTWARE.COM = {
auth_to_local = RULE:[1:$0\$1](^UJSOFTWARE\.COM\\.*)s/^UJSOFTWARE\.COM/UJSOFTWARE/
auth_to_local = DEFAULT
}
[domain_realm]
.ujsoftware.com = UJSOFTWARE.COM
ujsoftware.com = UJSOFTWARE.COM
[appdefaults]
pam = {
mappings = UJSOFTWARE\\(.*) $1@UJSOFTWARE.COM
forwardable = true
validate = true
}
httpd = {
mappings = UJSOFTWARE\\(.*) $1@UJSOFTWARE.COM
reverse_mappings = (.*)@UJSOFTWARE\.COM UJSOFTWARE\$1
}
[capaths]