9baef8f
# To opt out of the system crypto-policies configuration of krb5, remove the
9baef8f
# symlink at /etc/krb5.conf.d/crypto-policies which will not be recreated.
6cb6b69
includedir /etc/krb5.conf.d/
6cb6b69
cvsdist af3b546
[logging]
6b1b652
    default = FILE:/var/log/krb5libs.log
6b1b652
    kdc = FILE:/var/log/krb5kdc.log
6b1b652
    admin_server = FILE:/var/log/kadmind.log
cvsdist af3b546
cvsdist af3b546
[libdefaults]
6b1b652
    dns_lookup_realm = false
6b1b652
    ticket_lifetime = 24h
6b1b652
    renew_lifetime = 7d
6b1b652
    forwardable = true
6b1b652
    rdns = false
6c692d1
    pkinit_anchors = FILE:/etc/pki/tls/certs/ca-bundle.crt
2c340ef
    spake_preauth_groups = edwards25519
331a9df
    dns_canonicalize_hostname = fallback
f15271f
    qualify_shortname = ""
6b1b652
#    default_realm = EXAMPLE.COM
cvsdist af3b546
cvsdist af3b546
[realms]
f2a7c1d
# EXAMPLE.COM = {
6b1b652
#     kdc = kerberos.example.com
6b1b652
#     admin_server = kerberos.example.com
f2a7c1d
# }
cvsdist af3b546
cvsdist af3b546
[domain_realm]
f2a7c1d
# .example.com = EXAMPLE.COM
f2a7c1d
# example.com = EXAMPLE.COM