Go to main content

Oracle® ZFS Storage Appliance Administration Guide, Release OS8.7.x

Exit Print View

Updated: November 2018
 
 

Kerberos Service Properties

The following properties are available for the Kerberos service:

  • Realm - A string, the name of the realm.

  • KDC(s) - A list of zero or more host names, the Key Distribution Center(s) for the realm. The first Key Distribution Center (KDC) listed is assumed to be the Admin Server, which is relevant if creating principals on the KDC from the appliance, but not when importing keys. The list may be empty if at least one KDC is published for the realm in DNS.

  • Allow weak encryption types - A Boolean value. This enables/disables support for deprecated weak encryption types (des-cbc-crc, des-cbc-md5, and arcfour-hmac-exp). This property is disabled by default.

  • Admin - A string, the name of the Kerberos admin principal (administrator). By convention, a principal name is divided into three components: the primary, the instance, and the realm. You can specify a principal as joe, joe/admin, or joe/admin@ENG.EXAMPLE.COM. This property is used only if creating service principals, and is not retained.

  • Password - Kerberos admin password - A string, the password for the administrator. This property is used only if creating service principals, and is not retained.

Changing services properties is documented in Setting Service Properties (BUI) and Setting Service Properties (CLI).