kerberos/kdc: Rename to just kdc

This commit is contained in:
Timo Makinen 2021-09-01 15:35:25 +00:00
parent 5cc9012783
commit 29c6fd3205
7 changed files with 1 additions and 1 deletions

View file

@ -0,0 +1,33 @@
[libdefaults]
default_realm = {{ kerberos_realm }}
[logging]
kdc = SYSLOG
admin_server = SYSLOG
[kdcdefaults]
# listen on localhost only
kdc_listen = 127.0.0.1:88
kdc_tcp_listen = 127.0.0.1:88
[realms]
{{ kerberos_realm }} = {
database_module = ldap.{{ kerberos_realm|lower() }}
key_stash_file = "/var/kerberos/krb5kdc/.k5.{{ kerberos_realm }}"
max_lifetime = 24h 0m 0s
max_renewable_life = 7d 0h 0m 0s
master_key_type = aes256-cts-hmac-sha1-96
supported_enctypes = aes256-cts-hmac-sha1-96:normal
}
[dbmodules]
ldap.{{ kerberos_realm|lower() }} = {
db_library = kldap
disable_last_success = true
disable_lockout = true
ldap_kerberos_container_dn = "ou=System,{{ ldap_basedn }}"
ldap_kdc_dn = "uid=krb5kdc,cn={{ kerberos_realm }},ou=System,{{ ldap_basedn }}"
ldap_kadmind_dn = "uid=krb5kadmin,cn={{ kerberos_realm }},ou=System,{{ ldap_basedn }}"
ldap_service_password_file = "/var/kerberos/krb5kdc/.k5.ldap.{{ kerberos_realm|lower() }}"
ldap_servers = "{% for item in ldap_server %}ldaps://{{ item }} {% endfor %}"
}

View file

@ -0,0 +1,4 @@
[global]
[{{ kerberos_realm }}]
kerberos = kerberos+tcp://localhost

View file

@ -0,0 +1,3 @@
location /KdcProxy {
proxy_pass http://unix:/run/gunicorn/gunicorn-kdcproxy.sock:/KdcProxy;
}