Go to main content

Oracle® ZFS Storage Appliance Administration Guide, Release OS8.7.x

Exit Print View

Updated: September 2017
 
 

Creating a Kerberos Realm (BUI)

Use the following procedure to create a Kerberos realm, set the KDC(s), and select strong or weak encryption types. Descriptions of each property are located in Kerberos Service Properties.

Before You Begin

Ensure that you have configured the NTP service.

  1. Go to Configuration > Services.
  2. To enable the Kerberos service, click the enable icon image:Graphic showing enable icon. for Kerberos.
  3. Click Kerberos.
  4. In the Realm field, type the Kerberos realm.

    For familiarity, the realm name can be the same as your DNS domain name, except that the realm name is in uppercase.


    image:image of BUI screen with Kerberos properties
  5. In the KDC(s) field, type the host name of the KDC administrative server.

    If your Kerberos configuration includes DNS support for KDC lookup, leave this field blank.

  6. If you have another KDC, click the add icon image:Graphic showing add icon. next to KDC(s) and type its host name. Repeat for each additional KDC.

    If your configuration includes DNS support, do not complete this step.

  7. To allow support for weak encryption types, such as DES and Exportable ArcFour with HMAC/md5, select Allow weak encryption types.

    The default does not support weak encryption types.

  8. Click APPLY.

    To reset the properties to their original values, click REVERT instead.

Next Steps