Groups | Search | Server Info | Login | Register


Groups > comp.protocols.kerberos > #5384

Re: define own SRV-record

From Simo Sorce <simo@redhat.com>
Newsgroups comp.protocols.kerberos
Subject Re: define own SRV-record
Date 2025-02-26 14:11 -0500
Organization Red Hat
Message-ID <mailman.159.1740597093.2322.kerberos@mit.edu> (permalink)
References <4c320b53-995e-4d44-983e-361380bdc234@kania-online.de> <27e41f65d41278742d12c88a4ccb3cb96bcc6e05.camel@redhat.com>

Show all headers | View raw


You are barking up the wrong tree because your request also means you
intend to use the same kerberos realm for two distinct realms, and this
will not work and end up in pain.
Get your own subdomain (or a completely different second level domain),
and then you will be able to create your own records there.

On Wed, 2025-02-26 at 19:39 +0100, Stefan Kania wrote:
> Hi to all,
> 
> I'm having the following problem:
> 
> I set up an openldap with kerberos, now I want to add the srv-records 
> for Kerberos, but as DNS-Server we MUST use a DNS-Server from Active 
> Directory. So I can't add a srv-record _kerberos._tcp, because the 
> domain controller of the AD are keeping these records. So I would like 
> to add my own srv-record like _olkerberos._tcp so that I can use these 
> srv-records for krb5.conf. I'm already doing this for sssd, because 
> there I can configure the name of the srv-record. Can I do the same in 
> krb5.conf? If yes what do I have to do?
> 
> Thanks
> 
> Stefan
> 

-- 
Simo Sorce
Distinguished Engineer
RHEL Crypto Team
Red Hat, Inc

Back to comp.protocols.kerberos | Previous | Next | Find similar


Thread

Re: define own SRV-record Simo Sorce <simo@redhat.com> - 2025-02-26 14:11 -0500

csiph-web