9 Configuration file for Kerberos 5
13 file specifies several configuration parameters for the Kerberos 5
14 library, as well as for some programs.
16 The file consists of one or more sections, containing a number of
17 bindings. The value of each binding can be either a string or a list
18 of other bindings. The grammar looks like:
19 .Bd -literal -offset indent
29 '[' section_name ']' bindings
40 name '=' '{' bindings '}'
47 consists of one or more non-white space characters.
48 Currently recognised sections and bindings are:
50 .Bl -tag -width "xxx" -offset indent
52 .Bl -tag -width "xxx" -offset indent
53 .It Li default_realm = Va REALM
54 Default realm to use, this is also known as your
56 The default is the result of
57 .Fn krb5_get_host_realm "local hostname" .
58 .It Li clockskew = Va time
59 Maximum time differential (in seconds) allowed when comparing
60 times. Default is 300 seconds (five minutes).
61 .It Li kdc_timeout = Va time
62 Maximum time to wait for a reply from the kdc, default is 3 seconds.
64 .It v4_instance_resolve
65 These are decribed in the
66 .Xr krb5_425_conv_principal
70 This is a list of mappings from DNS domain to Kerberos realm. Each
71 binding in this section looks like:
75 The domain can be either a full name of a host or a trailing
76 component, in the latter case the domain-string should start with a
79 .Bl -tag -width "xxx" -offset indent
81 .Bl -tag -width "xxx" -offset indent
82 .It Li kdc = Va host[:port]
83 Specifies a kdc for this realm. If the optional port is absent, the
87 .It Li v4_instance_convert
88 .It Li v4_name_convert
91 .Xr krb5_425_conv_principal 3 .
96 .Bl -tag -width "xxx" -offset indent
97 .It Va entity Li = Va destination
100 should use the specified
104 manual page for a list of defined destinations.
108 .Bd -literal -offset indent
110 default_domain = FOO.SE
116 kdc = kerberos.foo.se
120 v4_instance_convert = {
123 default_domain = foo.se
126 kdc = FILE:/var/heimdal/kdc.log
128 default = SYSLOG:INFO:USER