7 realm
: CASE_INSENSITIVE
8 flatname
: CASE_INSENSITIVE
9 sAMAccountName
: CASE_INSENSITIVE
11 #Add modules to the list to activate them by default
12 #beware often order is important
18 objectClass: container
21 dn: CN=Primary Domains
23 objectClass: container
26 dn: flatname
=$
{DOMAIN
},CN=Primary Domains
28 objectClass: primaryDomain
29 objectClass: kerberosSecret
32 secret
: $
{MACHINEPASS
}
34 sAMAccountName
: $
{NETBIOSNAME
}$
35 whenCreated
: $
{LDAPTIME
}
36 whenChanged
: $
{LDAPTIME
}
37 msDS
-KeyVersionNumber
: 1
38 objectSid
: $
{DOMAINSID
}
39 privateKeytab
: secrets.keytab
41 dn: samAccountName
=krbtgt
,flatname
=$
{DOMAIN
},CN=Principals
44 objectClass: kerberosSecret
48 sAMAccountName
: krbtgt
49 whenCreated
: $
{LDAPTIME
}
50 whenChanged
: $
{LDAPTIME
}
51 msDS
-KeyVersionNumber
: 1
52 objectSid
: $
{DOMAINSID
}
53 servicePrincipalName
: kadmin
/changepw
54 saltPrincipal
: krbtgt@$
{REALM
}
55 privateKeytab
: secrets.keytab