Propagating the Kerberos Server

The kpropd.ini File

[default_values] interval=15s key_exp=6h max_cache=1024K max_retry_delay=1h net_timeout=30s port=kerberos-adm primary_realm=REALM1 realms=all service_name=host [sersrv1]

child = secsrv2 [secsrv2] child1 = secsrv3 child = secsrv4 parent = secsrv1 [secsrv3]

parent = secsrv2, realms = REALM1 [secsrv4]

parent = secsrv2, realms = REALM2

The [default_values] section lists the default values that mkpropcf may create using the krb.conf file on a primary security server, which supports REALM1 as its default realm. The propagation hierarchy that kpropd creates is derived from the security servers that support the default realm.

Because the krb.conf file cannot describe a propagation hierarchy, where secondary security servers themselves have secondary security servers, edit the kpropd.ini file to support such relationships.

256

Chapter 9