Rocksolid Light

Welcome to novaBBS (click a section below)

mail  files  register  newsreader  groups  login

Message-ID:  

"Your attitude determines your attitude." -- Zig Ziglar, self-improvement doofus


devel / comp.protocols.kerberos / domain_realm, hostname to realm mapping, what programs/services is this necessary for?

SubjectAuthor
* domain_realm, hostname to realm mapping, what programs/services isChristian, Mark
`- Re: domain_realm, hostname to realm mapping, what programs/servicesTodd Heron

1
domain_realm, hostname to realm mapping, what programs/services is this necessary for?

<mailman.0.1639032862.8148.kerberos@mit.edu>

  copy mid

https://www.novabbs.com/devel/article-flat.php?id=187&group=comp.protocols.kerberos#187

  copy link   Newsgroups: comp.protocols.kerberos
Path: i2pn2.org!i2pn.org!weretis.net!feeder6.news.weretis.net!tncsrv06.tnetconsulting.net!.POSTED.mailman.mit.edu!not-for-mail
From: mark.chr...@intel.com (Christian, Mark)
Newsgroups: comp.protocols.kerberos
Subject: domain_realm, hostname to realm mapping, what programs/services is
this necessary for?
Date: Thu, 9 Dec 2021 06:53:55 +0000
Organization: TNet Consulting
Lines: 4
Message-ID: <mailman.0.1639032862.8148.kerberos@mit.edu>
References: <BL1PR11MB5512F3419D36B877C93752DA85709@BL1PR11MB5512.namprd11.prod.outlook.com>
Mime-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 8bit
Injection-Info: tncsrv06.tnetconsulting.net; posting-host="mailman.mit.edu:18.7.21.50";
logging-data="30612"; mail-complaints-to="newsmaster@tnetconsulting.net"
To: "kerberos@mit.edu" <kerberos@mit.edu>
ARC-Seal: i=3; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=pass;
b=Xjh5QQJskBENj47V5dOuEgmVjdgzVFrITfuElcI/rfHwbhWZ5/+Hq6/Z3j3paliVDfempl2yUMHBzHwFH+3qvl7tE6oez0DF5HVwgfZYoNaIyIarwSwziLBWgIp63Hnn2MXQ+1WvvCpGYi0AHAG8wpWDdy4r4072kCrHMCvbBx46q9Iq60uGDuDt+ijFlmZivVf18fIbpoFFa5uwRRqPD0l03VqgFVrXAaFcE7RuQDUA569ySfJ4FElAAjOBcLVllKy7wxkLjgBebrQHMEPoa1pPLvc1obrJv3kcb7sltUF/n1UJJYvHsReUO9HeIgOo/HZuHoxQ5jX6GA3MKoHXBQ==
ARC-Message-Signature: i=3; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com;
s=arcselector9901;
h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1;
bh=u6gPR3//360Lsmz625VIY0tNNbYtZ9gD99QamOe51HE=;
b=EV2O3QxINc/rOjfvaW1AJYDQCLsfGbSZMt7m/AaOpB/zD8taBrJBg0GsX5boCbaOan141en768QErqIF51n94bEgxOAvR0f9W04k2vX7VInhSJBsAZp9SmxwguP6GKtiz8FT5mNVETVZhsecJyBh+GMj7g4kaHQhHI0zWEm8KXK3GeH5vEIJH5F6c5H2Cc0co0AUFF7c62Z8iwEa3hDjYNEu5/oTRhisu8Zj2d2y922sNVidB+ZWN/OY3QC9JmCrHfhDG5ge7TS3A7MtLEOdZCEtNKxHyMySVCBUCw7l6NA0o10BgryObxFkUdBzUASxIJUoPP33t2gMm35K5JddPg==
ARC-Authentication-Results: i=3; mx.microsoft.com 1; spf=pass (sender ip is
134.134.136.20) smtp.rcpttodomain=mit.edu smtp.mailfrom=intel.com; dmarc=pass
(p=none sp=none pct=100) action=none header.from=intel.com; dkim=pass
(signature was verified) header.d=intel.com; dkim=pass (signature was
verified) header.d=intel.onmicrosoft.com; arc=pass (0 oda=1 ltdi=1
spf=[1,1,smtp.mailfrom=intel.com] dkim=[1,1,header.d=intel.com]
dmarc=[1,1,header.from=intel.com])
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
d=mitprod.onmicrosoft.com; s=selector2-mitprod-onmicrosoft-com;
h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck;
bh=u6gPR3//360Lsmz625VIY0tNNbYtZ9gD99QamOe51HE=;
b=WDWqRI9q4AJ57yoIFaskloHkGCaKuTtI2LS9ofJVuU9dEAiWz1c6Sz7QlVtnPAbVPs6kuV+h7vsoXjvJR5JTmdN1UgRPGyjFFRns6cOKs3arFOdFKs5NSUWZtre0unqclXrdXJ/vozSdET220RU31JkQYD4YNeANcgvbEa1GFM0=
ARC-Seal: i=2; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=pass;
b=h02FVjknWrv/vuT8Eob9fVL2uYyiVywCktXnOcxbHIf0HI92zulemK+Et3vjqlUtVW4i4J/HXba67Hpncbs4ANfXLtwmMck3Qq47Fti8we9FqBm5qQ+NOJlPp+cuUGmlzZewezzQF8+XVujSWO/A6uyglD+MG55iAv8cXWxgYK0gwkIGVdU2QebC0AxzdJeELHDPBUrpnOIa3jLUIlNftPLOQ+kbIOaBeCzT5qoYzXHOBO0XCqbL3eWl3TshWGzfKOdwLbk7fAF33/G7d6XNEszWZDKQ9DEYSU5WqyENlItltn0TcBoXurJAqE7Qq+Zi3vN1pKTlx3G/7Cv7T6bSiA==
ARC-Message-Signature: i=2; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com;
s=arcselector9901;
h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1;
bh=u6gPR3//360Lsmz625VIY0tNNbYtZ9gD99QamOe51HE=;
b=O9YLe+kTJnwAKxeMMh+N4GDcbTm61iI2LxiHccy3EtzRFeNrkDBwXzTeN3PJDsPooTrfh7IsCQTalfs9Yjg12cMRx6BaMIdxQrDJE3hztzZkn2mDJ7q8C3Oo46iB/yF6ALNu5MXdZxuKyRZRQUyRC7W1erbYC1hp/R3Oy6zj6IV5Jnh62LkSGeWO23mkZ4/UAaSmpqkBILhv31xn3RF9MQAdg72Fh1VXT+LrchRGJG75iU9bVw811LERPs+oc6QgKIcMDCEadIYiVQFAdpCjqqQ+M6AQ6D/6AM+Mh9+P8VpSXOb5vtEwLGmXjeodxugwzWArmVU+0LQ4JpTU6r6P4w==
ARC-Authentication-Results: i=2; mx.microsoft.com 1; spf=pass (sender ip is
134.134.136.20) smtp.rcpttodomain=mit.edu smtp.mailfrom=intel.com; dmarc=pass
(p=none sp=none pct=100) action=none header.from=intel.com; dkim=pass
(signature was verified) header.d=intel.com; dkim=pass (signature was
verified) header.d=intel.onmicrosoft.com; arc=pass (0 oda=1 ltdi=1
spf=[1,1,smtp.mailfrom=intel.com] dkim=[1,1,header.d=intel.com]
dmarc=[1,1,header.from=intel.com])
Authentication-Results: spf=pass (sender IP is 134.134.136.20)
smtp.mailfrom=intel.com; dkim=pass (signature was verified)
header.d=intel.com;dmarc=pass action=none header.from=intel.com;
Received-SPF: Pass (protection.outlook.com: domain of intel.com designates
134.134.136.20 as permitted sender) receiver=protection.outlook.com;
client-ip=134.134.136.20; helo=mga02.intel.com;
DKIM-Signature: v=1; a=rsa-sha256; c=simple/simple;
d=intel.com; i=@intel.com; q=dns/txt; s=Intel;
t=1639032851; x=1670568851; h=from:to:subject:date:message-id:
content-transfer-encoding:mime-version;
bh=1d6xvLFiJ08Yrdf3sx4WcIM04LZXRCCoSZAPqP5W+Sw=;
b=hLZMno+Ybp0KMV1lrZME9IGgemh3f85+U/MXMUBrJW6aaMGIyKKGWthm
OFcFwZeKrqdcVibpqZnOMO9347g7SWndj/uod5c1bwy8gR5+VS4SURrVI
xJfyH+TTL/s2YutbNSY4TnXylPsirDsINAqVKVL/qkba3527EHMTlYVBb
LiPe1N5rAgC/Vi1qF8J5yxOuMkgaJr7gXwFO9NEZeKOO6Nr6ZTDPaMQDt
4rbBtLMNe4XAzXv0fQlpZbMnq/RlrW3z7TN0R4dDsrIBXqjh0HFJES6Gr
JNwih+WaFHmmWyoRaSPLIZ7qc8ClZjAnhZXx8kMuh2KU/alF4vcvD09a3 g==;
X-IronPort-AV: E=McAfee;i="6200,9189,10192"; a="225294436"
X-IronPort-AV: E=Sophos;i="5.88,191,1635231600"; d="scan'208";a="225294436"
X-ExtLoop1: 1
X-IronPort-AV: E=Sophos;i="5.88,191,1635231600"; d="scan'208";a="750251947"
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none;
b=CWypmoirQheDoYPw7Dp+fPkwqG4ti5E5Fx7yMW1t8A9SO5DvdvUZqtoYzO1N5FrL7v5pfje4W/tgvoY/5XUHM2DEtXOpP2L9olL9lYuiLeF+J977pljj8wJSB0gppczQ5P7ZhxWRCOgBBOkG3ohFdGQ4UH5TnN+Nd4NgLy3s/Ig2Db1ATI9OcyVkfnmRLVIQ1F5trqFX8cRuoyKScb1jO7BNNfGxQe869uMaC/nXPl/i8ctqaopLDoWY76uOEPWWwu8qrYhk2oZh5vLhZmTDc7PvWlcKb+P3ZC9GLSmXphdZ1f+p29a/Q05nFGSSIFOC9krasfzazeBFTodnqcBe3Q==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com;
s=arcselector9901;
h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1;
bh=u6gPR3//360Lsmz625VIY0tNNbYtZ9gD99QamOe51HE=;
b=jpo1P+QFdiz9/Gwr6/S62Wg1rcniF0vGBJ+XAVN5Eha9nQOvdhRPi9JV6aFHRDFLorwznwyrPZGnHMMt03mnVKeUmrZM0dkLwO34x3nudPzK7veZP6Vl5T94WludJ+GqyLTByHcKqZQtnqU/osKXlcg1bS+JYVhULcmoHni/aPR4kV81pcheQj8k7fFzuGU2VWEsBAB3SpctT+/u66cdjvilkzq856pFTUejxWclV2HE/PXEg5eY7e/isqlXf1i43bkofFtDwlJ2vEqHaKpePsEAPN8bqVE+CIN/FcvVdDZdVsrl0jK4/mYUA8moBbdGUH/AAkXzcR5abJuO1ceczg==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass
smtp.mailfrom=intel.com; dmarc=pass action=none header.from=intel.com;
dkim=pass header.d=intel.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=intel.onmicrosoft.com;
s=selector2-intel-onmicrosoft-com;
h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck;
bh=u6gPR3//360Lsmz625VIY0tNNbYtZ9gD99QamOe51HE=;
b=SMKOn/1pKxP13zwG83UpDcbjPicYMWEtvSuhlTh48cgThr4m5fXNSYfXXoz7u8DCK8k1paLi3DYl8iXR3mZKcVtKnCmDWfh1DHIB1d8BWvg0W7jdYT807dJazxCnbDwxUJzLfOeYmmNpTxlxA3hZm8wIMAk+K1mXNl72m5vTQVE=
Thread-Topic: domain_realm, hostname to realm mapping, what programs/services
is this necessary for?
Thread-Index: AdfsxXn3raWbK6YEQqCzQFJh/P0S7w==
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
dlp-product: dlpe-windows
dlp-reaction: no-action
dlp-version: 11.6.200.16
Authentication-Results-Original: dkim=none (message not signed)
header.d=none;dmarc=none action=none header.from=intel.com;
X-MS-Office365-Filtering-Correlation-Id: 873406b9-cc2b-4b5f-12e4-08d9bae0b4da
x-ms-traffictypediagnostic: MN2PR11MB4517:EE_|BN8NAM11FT058:EE_|CO1PR01MB6757:EE_
X-Microsoft-Antispam-PRVS: <CO1PR01MB6757157B1BB0CE3A9472349F85709@CO1PR01MB6757.prod.exchangelabs.com>
x-ms-oob-tlc-oobclassifiers: OLM:6790;OLM:6790;
X-MS-Exchange-SenderADCheck: 0
X-MS-Exchange-AntiSpam-Relay: 0
X-Microsoft-Antispam-Untrusted: BCL:0;
X-Microsoft-Antispam-Message-Info-Original: RhW6TE8G6YTK9dcV7WLBK2IsOtgIK1T3Ywfht8kCQ+dlhP8Ffyp9z5EJBi7sNPpNGdmeEqJd6YQOZHlap/IuwMacfTsyZor7tGd+nybKq16QJrJCfynwBCXVYtlWrBKQ1BCHVD0Vx+e0to6/JvEYqfgkF8TyOhuRbHxhhbQpmHtyAeMxc7CaEdJ59UZLR5wrOP3WVOWc+P3a1H5QY3BcrTnL+cQMdsFp51UvFyNLjnfIiVcZ3RP15KEZtSnxeiKE3/8WAzMqvFxV8r/P5TpKIKe22EOtBT+m8kpD4yByDfUBRP02w+IrYV391x+mnr6Aa1sl4KWD8C3b5NTaXzGwXoZmLjQll4/ED49g1N5YloIcZCrSb08N4Agq3xsGTgz0JElh8BMKcMJeRm7ZhtcwdoGUiRFz3ilEygBBSgXdy/vl1mO/nPjxbu3t0PiSsqjhbHEohYjQorsQfRhQS+SSub34nT1MLs1IHsbuP2EGq19lcdIYii40P4B45xOR/B8okZrzal0kIVDS1xGaEv4O57cEd90MKCJB0kANTDk72Mg8uTMWMkndxQ7iF61MJg/YcV/beqDthorbgcvkFe4tCRK35cciIVy1RYQHxZsUIworfWD1yoPEKz80ig6oQI2M5W2IKH07vxvCS2qDqPiih0jKb0vYORDgK8EJL+je5vskm3mtYhGUl58vyD5UUg/ahsNnJaKkn1iMmOfndEPAnQ==
X-Forefront-Antispam-Report-Untrusted: CIP:255.255.255.255; CTRY:; LANG:en;
SCL:1; SRV:; IPV:NLI; SFV:NSPM; H:BL1PR11MB5512.namprd11.prod.outlook.com;
PTR:; CAT:NONE;
SFS:(366004)(9686003)(38100700002)(26005)(122000001)(316002)(82960400001)(186003)(2906002)(6506007)(52536014)(38070700005)(71200400001)(76116006)(33656002)(8936002)(6916009)(7696005)(86362001)(8676002)(66946007)(64756008)(66476007)(55016003)(66556008)(66446008)(5660300002)(508600001)(4744005);
DIR:OUT; SFP:1102;
X-MS-Exchange-AntiSpam-MessageData-Original-ChunkCount: 1
X-MS-Exchange-AntiSpam-MessageData-Original-0: cLlIf97Rzy9S2C7b6aHaUiyTHuJ5iJrAbWB7EE1ppjriPSEDMlcK/f+g/+fK
k00tIPpIEe248dzESi6WIt3nHAY98QHkI2YiCkTc0ksJhJOzWVvZWMOvSKTA
h0otJ7DWtWtTHqFEQweUdSWqflRRT/gOzgn5QS0h0xppMAaRWse3sulGdv4e
rOCxAPQD5z5053SofIl9Clq5EOdo3R1RV/2hnjNC/dXlqxxp7TaxxJmmLgIB
cSQzUwokHUaays6XmwQJW6pPab+1BSFwxzrhayr/SI4hfKyTxRR4Mr84kZCS
WBCnA4IRwuCOpAGG6tmgKfWtHUCR8sdMj/gf/4kSph3LO/TYxe9KIrplWzdR
g1Z4zHtlHvErmieo6cnMD+trj1qYt58HOltSxJuhaOlgoz4pHpjOBT44HkVk
Hq4w4VO8OcBml/cLqxHQVMEGSe+yBxai0BLZLgLYXDJ3yMi41LFuI8GiVlh7
ic2acM1JVQKj0tcsyvVi/cen4W9C4++43KlEK1tO8tTyA1yMwxV1Y9cFylKF
QBXigFfY64Crfrht8ht/R3mDrypUxSqE58m8vPNJsYb5IlywwVoXZXOx0J9c
xd3beH0HPX/VAY2y+oK3kJ5a7coAqdIwgu2qOK3rmM4jIpoAXImjx+VyoS+Y
5UhO33IDZyPo/S4ye3qctO8HYZupqr4yqmsOUUivOZmhHSE7mtsKK0kK6X9i
erXpyzRC+1JtvXPcFXYA+983hrmwfR86z4+CKn+Eh2fLHD0aqWtdF8otmrWM
DOETauG611rlZ3JTRLqKy5v/x/1+OZZO5CNpj8wimTLLl+slYAZpWUFGcw81
Som9EkgYi2guKyZTmdESix+SL1lfvzktZjgTeCboY6NKkAhmdhbnIbHAv8dX
hFU24/g2X1yFGRL9c0r+r9wtoxLtzcZah4ybtIioOEkoW2Ltoe8kPIoXUeWB
clwxUZgiqn9kZSiMKtlvtzAK+ac3Tn6PEXqp13DttIQRIdsUbKCAb7ho3sTZ
vGfhLHR5j96B1XysShBwMy2eKilyKMMYlIuV8p2Hg5w+ImeIJVpKQ2uHE0Qu
Xon9reXImx5A30jeUeomWh0Wk/2+WiozKSyYId7raa/4TGFuU+R6wM3cCasv
FQmRb9lLSwH5ADFix/5WGMd5eJe6vx8qmCn2iUg6iQTKbE6W+cmOzeQ8q1GW
HqdydfCYoPQ8JysTSx+JZ4R3fymkCPXbbucwL7p1tig0f56ZhuWk6hPsQux7
DVhdJiETQJCC3IISffMwaDMsDtuQ+XV501Zp6heV0G+hh8HclZjDQs2nscx9
WurdcDL3QoBwGJo8qxnTEDK7IigXwqjF4eu/EHfmshz/BtkeGimA/zIMKGgF
OyZ9iGHozOitE3wI4H2EvuRAtrLf7VbxhpiO8yFwsiper/+SSAwVgxW6KVHs
lxmfuHC8ZBXrjMqPPBQbCoAYhE1N47AdCcqzMWSfytpG1fcy72uAmx/bM03c
5tmRQ3MWfSUJzCrm1vvoCY6cwc48wPCodaR0/+pJWHEDvXvSqbjRxufkbC08
OpbFFFnaM6+1GbQ/Xm6HvcRpeCDQXnWtonpb4aMm2exTw2Y4eRnGmooEU/QH
bKbgnr1+RORRtHJDEJmDq4BYWTY/Lqs794ZiLz1mspSszLZkcMCkgYQtxFtI
NeWb4w==
X-MS-Exchange-Transport-CrossTenantHeadersStamped: MN2PR11MB4517
X-EOPAttributedMessage: 0
X-EOPTenantAttributedMessage: 64afd9ba-0ecf-4acf-bc36-935f6235ba8b:0
X-MS-Exchange-Transport-CrossTenantHeadersStripped: BN8NAM11FT058.eop-nam11.prod.protection.outlook.com
X-MS-PublicTrafficType: Email
X-MS-Office365-Filtering-Correlation-Id-Prvs: eb0270d2-fefb-4e9f-d7c8-08d9bae0ab19
X-LD-Processed: 64afd9ba-0ecf-4acf-bc36-935f6235ba8b,ExtAddr
X-MS-Exchange-AtpMessageProperties: SA
X-Microsoft-Antispam: BCL:0;
X-Microsoft-Antispam-Message-Info: Ay6iGkiPkuc5iSi82vSSJf9+UOhchj/u+B5AYHIS68+7omjZCmUjJSlEmMnxAT9IkuCsg8MfRa77FN2uCV9LL3RpeXX18+7d46kWlzne3Zp/2k+DYoocC8KwQ9ioBQlBz5eP3B1uaK2Dc+E3i16wTVt9UnUvxhVtvfmohlHhYSTXauNQWAVMeIZSGonaSNTJpwSCMkrHHlmbX+ptvnhOiM+DsdroOxr4S09uwGSy+cUtbxxPaKzIzJunGLpMDbP809UFN8btjaOSfI9KUVhuB2jbCEk+1EGL2q+zFdJCT5gWKTElBKWLUaLXkFEe0tNq3UnkIylyBamNIobug6RNCGy2VlIwzw0R6MJApBR+XlfZKUOEn0kSxLlj7wVZtoy0F7KGsr6qRgN6IcqJZDbbXW9RK+SBzi1/X8PcAe4m26Xpjwx0+IcUKSzZIdVkxvDi4pLFsuOgGOdIsLF9zrkhgl3iBgFDhHv51N71/x7dzXQbwLBmiX/yYApZ6QSuvC1vlWGsunvFEuF63wya1lo/p0Dxv3Dcw4y9OqRNvhxTIwpjWzlXvM3cO04G0tP+TlDCL1C1ots38jqKwCauA/iCKLx6g3IYibJa/hPvMfZMSMlImK91FwuLMhQOoJbKHOIQ
X-Forefront-Antispam-Report: CIP:134.134.136.20; CTRY:US; LANG:en; SCL:1; SRV:;
IPV:NLI; SFV:NSPM; H:mga02.intel.com; PTR:mga02.intel.com; CAT:NONE;
SFS:(4636009)(8676002)(786003)(52536014)(70586007)(68406010)(316002)(26005)(7596003)(55016003)(7696005)(83310400002)(7636003)(83300400002)(83320400002)(83280400002)(83290400002)(356005)(6506007)(2906002)(86362001)(5660300002)(4744005)(9686003)(508600001)(6862004)(336012)(33656002);
DIR:OUT; SFP:1102;
X-Auto-Response-Suppress: DR, OOF, AutoReply
X-MS-Exchange-CrossTenant-OriginalArrivalTime: 09 Dec 2021 06:54:11.5986 (UTC)
X-MS-Exchange-CrossTenant-Network-Message-Id: 873406b9-cc2b-4b5f-12e4-08d9bae0b4da
X-MS-Exchange-CrossTenant-Id: 64afd9ba-0ecf-4acf-bc36-935f6235ba8b
X-MS-Exchange-CrossTenant-AuthSource: BN8NAM11FT058.eop-nam11.prod.protection.outlook.com
X-MS-Exchange-CrossTenant-AuthAs: Anonymous
X-MS-Exchange-CrossTenant-FromEntityHeader: Internet
X-MS-Exchange-Transport-CrossTenantHeadersStamped: CO1PR01MB6757
X-OriginatorOrg: mitprod.onmicrosoft.com
X-MIME-Autoconverted: from quoted-printable to 8bit by mailman.mit.edu id
1B96sL1l383362
X-BeenThere: kerberos@mit.edu
X-Mailman-Version: 2.1.34
Precedence: list
List-Id: The Kerberos Authentication System Mailing List <kerberos.mit.edu>
List-Unsubscribe: <https://mailman.mit.edu/mailman/options/kerberos>,
<mailto:kerberos-request@mit.edu?subject=unsubscribe>
List-Archive: <http://mailman.mit.edu/pipermail/kerberos/>
List-Post: <mailto:kerberos@mit.edu>
List-Help: <mailto:kerberos-request@mit.edu?subject=help>
List-Subscribe: <https://mailman.mit.edu/mailman/listinfo/kerberos>,
<mailto:kerberos-request@mit.edu?subject=subscribe>
X-Mailman-Original-Message-ID: <BL1PR11MB5512F3419D36B877C93752DA85709@BL1PR11MB5512.namprd11.prod.outlook.com>
 by: Christian, Mark - Thu, 9 Dec 2021 06:53 UTC

I primarily use Kerberos with ssh gssapi-with-mic authentications, samba, and apache. I don't believe I need to populate the [domain_realm] section with hostname/domainname mappings to realms, even though the domainname for the hosts differs from the Kerberos realm; these Kerberized services still work. Or am I mistaken? default_realm is defined under [libdefaults], and dns_lookup_realm and dns_lookup_kdc are set to false. The krb5.conf man page mentions that this mapping is necessary for some programs or services. I'm wondering which services require this mapping?

Mark

Re: domain_realm, hostname to realm mapping, what programs/services is this necessary for?

<ad98d3fe-e9c5-49ba-b23d-c1222e634ed9n@googlegroups.com>

  copy mid

https://www.novabbs.com/devel/article-flat.php?id=188&group=comp.protocols.kerberos#188

  copy link   Newsgroups: comp.protocols.kerberos
X-Received: by 2002:a05:620a:2996:: with SMTP id r22mr12909466qkp.485.1639059054308;
Thu, 09 Dec 2021 06:10:54 -0800 (PST)
X-Received: by 2002:a05:6830:1107:: with SMTP id w7mr5412454otq.20.1639059053830;
Thu, 09 Dec 2021 06:10:53 -0800 (PST)
Path: i2pn2.org!i2pn.org!weretis.net!feeder6.news.weretis.net!news.misty.com!border2.nntp.dca1.giganews.com!border1.nntp.dca1.giganews.com!nntp.giganews.com!news-out.google.com!nntp.google.com!postnews.google.com!google-groups.googlegroups.com!not-for-mail
Newsgroups: comp.protocols.kerberos
Date: Thu, 9 Dec 2021 06:10:53 -0800 (PST)
In-Reply-To: <mailman.0.1639032862.8148.kerberos@mit.edu>
Injection-Info: google-groups.googlegroups.com; posting-host=2600:4040:4012:c900:913:d951:1cc:d1cd;
posting-account=x_5fPwoAAAC5bAU5tjeqVfhlbG9E6nU3
NNTP-Posting-Host: 2600:4040:4012:c900:913:d951:1cc:d1cd
References: <AdfsxXn3raWbK6YEQqCzQFJh/P0S7w==> <BL1PR11MB5512F3419D36B877C93752DA85709@BL1PR11MB5512.namprd11.prod.outlook.com>
<mailman.0.1639032862.8148.kerberos@mit.edu>
User-Agent: G2/1.0
MIME-Version: 1.0
Message-ID: <ad98d3fe-e9c5-49ba-b23d-c1222e634ed9n@googlegroups.com>
Subject: Re: domain_realm, hostname to realm mapping, what programs/services
is this necessary for?
From: todd.he...@gmail.com (Todd Heron)
Injection-Date: Thu, 09 Dec 2021 14:10:54 +0000
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable
Lines: 22
 by: Todd Heron - Thu, 9 Dec 2021 14:10 UTC

On Thursday, December 9, 2021 at 1:54:26 AM UTC-5, Christian, Mark wrote:
> I primarily use Kerberos with ssh gssapi-with-mic authentications, samba, and apache. I don't believe I need to populate the [domain_realm] section with hostname/domainname mappings to realms, even though the domainname for the hosts differs from the Kerberos realm; these Kerberized services still work. Or am I mistaken? default_realm is defined under [libdefaults], and dns_lookup_realm and dns_lookup_kdc are set to false. The krb5.conf man page mentions that this mapping is necessary for some programs or services. I'm wondering which services require this mapping?
>
> Mark

There are many reasons [domain_realm] section exists. One overlooked reason is Kerberos understands lower-case only. Some environments might have the realm in upper case (some Microsoft Active Directory environments, for instance). Thus this section allows your local Kerberos client to find those upper-case realms. Kerberos requires DNS, so even though your dns_lookup_realm and dns_lookup_kdc are set to false, and [domain_realms} might be blank, DNS will still be used, it just means your local Kerberos client is not going to rely on what is defined in krb5.conf, rather it will use on the operating system's configured DNS servers. As far as the language on the krb5.conf man page mentioning that the mapping is necessary for some programs or services - don't know.

1
server_pubkey.txt

rocksolid light 0.9.8
clearnet tor