User Tools

Site Tools


hosts:virtual_machines:enclave:mit_kerberos_kdc

Differences

This shows you the differences between two versions of the page.

Link to this comparison view

Both sides previous revisionPrevious revision
Next revision
Previous revision
hosts:virtual_machines:enclave:mit_kerberos_kdc [2023/02/21 01:32] – created netboxhosts:virtual_machines:enclave:mit_kerberos_kdc [2023/08/30 17:53] (current) – [Configuration locations] tcmal
Line 1: Line 1:
 [[meta:autogen:start|​]] [[meta:autogen:start|​]]
 +===== MIT Kerberos KDC =====
 ^ Name | MIT Kerberos KDC | ^ Name | MIT Kerberos KDC |
 ^ Ports | 88, 749, 464 (tcp) | ^ Ports | 88, 749, 464 (tcp) |
Line 5: Line 6:
 [[meta:autogen:end|​]] [[meta:autogen:end|​]]
  
 +[[http://web.mit.edu/kerberos/|MIT Implementation]] of [[https://www.fortinet.com/resources/cyberglossary/kerberos-authentication|Kerberos]], a network authentication protocol. Because our network is largely trusted, this mostly just functions as a secure and authoritative way to validate passwords.
 +
 +===== Data directories =====
 +
 +  * ''/var/lib/krb5kdc/''
 +
 +===== Configuration locations =====
 +
 +Handled declaratively using [[https://git.tardisproject.uk/tardis/nix/-/blob/main/profiles/krb/server.nix|Nix]]. Unfortunately, upstream doesn't have a module for the kerberos KDC, so we use a [[https://git.tardisproject.uk/tardis/nix/-/blob/main/modules/services/kdc.nix|custom one]].
hosts/virtual_machines/enclave/mit_kerberos_kdc.1676943167.txt.gz · Last modified: 2023/02/21 01:32 by netbox