Docs

Browse releases →

krb5

MIT Kerberos and GSSAPI implementation

krb5

MIT Kerberos and GSSAPI implementation

1.22.2 · aarch64-darwin

Master credential

The KDC master password is an opaque credential reference used only during controlled initialization and service operation.

Realm lifecycle

Choose the realm and KDC endpoints before initialization. The package retains the principal database and applies ticket lifetime and ACL policy declaratively.

OptionTypeDescription
acllist of string matching [^ ]+kadmind ACL entries.
adminServerstring matching [A-Za-z0-9][A-Za-z0-9.-]*Host name of the Kerberos administration server.
enablebooleanEnable the package-owned Kerberos KDC.
enableAdminServerbooleanEnable the kadmind remote administration service.
kdcServerslist of string matching [A-Za-z0-9][A-Za-z0-9.-]*Ordered KDC host names published to clients.
masterPasswordsubmoduleOpaque initial KDC database master password.
maxLifestring matching [1-9][0-9]*[smhd]Maximum ticket lifetime.
maxRenewableLifestring matching [1-9][0-9]*[smhd]Maximum renewable ticket lifetime.
realmstring matching [A-Z0-9][A-Z0-9.-]*Kerberos realm served by this KDC.