Creating a Kerberos Realm (BUI)

Use the following procedure to create a Kerberos realm, set the KDC(s), and select strong or weak encryption types. Descriptions of each property are located in Kerberos Service Properties.

Before You Begin

Ensure that you have configured the NTP service.

  1. From the Configuration menu, select Services.
  2. To enable the Kerberos service, click the enable icon image showing the enable icon for Kerberos.
  3. Click Kerberos.
  4. In the Realm field, type the Kerberos realm.

    For familiarity, the realm name can be the same as your DNS domain name, except that the realm name is in uppercase.


    image of BUI screen with Kerberos properties
  5. In the KDC(s) field, type the host name of the KDC administrative server.

    If your Kerberos configuration includes DNS support for KDC lookup, leave this field blank.

  6. If you have another KDC, click the add icon image showing the add icon next to KDC(s) and type its host name. Repeat for each additional KDC.

    If your configuration includes DNS support, do not complete this step.

  7. To allow support for weak encryption types, such as DES and Exportable ArcFour with HMAC/md5, select Allow weak encryption types.

    The default does not support weak encryption types.

  8. Click APPLY.

    To reset the properties to their original values, click REVERT instead.

Next Steps

Choose one of the following options: