Guest User

Untitled

a guest
Jun 18th, 2018
209
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 1.30 KB | None | 0 0
  1. # kinit adtest@AD.EXAMPLE.COM
  2. Password for adtest@AD.EXAMPLE.COM:
  3. root@clienttest2:~# kvno ltest@EXAMPLE.COM
  4. ltest@EXAMPLE.COM: kvno = 1
  5.  
  6. # kinit ltest@EXAMPLE.COM
  7. Password for ltest@EXAMPLE.COM:
  8. root@clienttest2:~# kvno adtest@AD.EXAMPLE.COM
  9. kvno: KDC has no support for encryption type while getting credentials for adtest@AD.EXAMPLE.COM
  10.  
  11. [libdefaults]
  12. default_realm = EXAMPLE.COM
  13. allow_weak_crypto = true
  14. verify_ap_req_nofail = false
  15. default_tkt_enctypes = rc4-hmac
  16. default_tgs_enctypes = rc4-hmac
  17.  
  18. [realms]
  19. EXAMPLE.COM = {
  20. kdc = unix-server.example.com
  21. admin_server = unix-server.example.com
  22. }
  23. AD.EXAMPLE.COM = {
  24. kdc = ad-server.ad.example.com
  25. admin_server = ad-server.ad.example.com
  26. }
  27.  
  28. [domain_realm]
  29. .example.com = EXAMPLE.COM
  30. .ad.example.com = AD.EXAMPLE.COM
  31.  
  32. [capaths]
  33. EXAMPLE.COM = {
  34. AD.EXAMPLE.COM = .
  35. }
  36. AD.EXAMPLE.COM = {
  37. EXAMPLE.COM = .
  38. }
  39.  
  40. [logging]
  41. default = FILE:/var/krb5/kdc.log
  42. kdc = FILE:/var/krb5/kdc.log
  43. kdc_rotate = {
  44. period = 1d
  45. versions = 10
  46. }
  47.  
  48. [appdefaults]
  49. kinit = {
  50. renewable = true
  51. forwardable = true
  52. }
  53.  
  54. addprinc -e rc4-hmac krbtgt/AD.EXAMPLE.COM@EXAMPLE.COM
  55. addprinc -e rc4-hmac krbtgt/EXAMPLE.COM@AD.EXAMPLE.COM
Add Comment
Please, Sign In to add comment