Sure, I am really missing this information written on the wiki page. The secret is, they are in the DNS record. If you try $ host -t URI _kerberos.fedoraproject.org
you might get it. But some DNS servers seem to have trouble with this record. As Red Hat defaults have dns_lookup_realm = false, we need manual configuration. I think there are more people like us. I think this should be mentioned on https://fedoraproject.org/wiki/Infrastructure/Kerberos: [realms] FEDORAPROJECT.ORG = { kdc = https://id.fedoraproject.org/KdcProxy } [domain_realm] fedoraproject.org = FEDORAPROJECT.ORG .fedoraproject.org = FEDORAPROJECT.ORG -- Petr Menšík Software Engineer Red Hat, http://www.redhat.com/ email: [email protected] PGP: 65C6C973 ----- Original Message ----- From: "Dave Love" <[email protected]> To: [email protected] Sent: Monday, December 12, 2016 5:36:24 PM Subject: Re: Packagers - Flag day 2016 Important changes Dennis Gilmore <[email protected]> writes: > See the general kerberos information at: > https://fedoraproject.org/wiki/Infrastructure_kerberos_authentication > for more details. I was going to try to authenticate, even if the tools won't work, but that's missing the fundamental information about how to configure the realm for clients. What are the kdc(s) and admin_server (if admin_server is relevant)? _______________________________________________ devel mailing list -- [email protected] To unsubscribe send an email to [email protected] _______________________________________________ devel mailing list -- [email protected] To unsubscribe send an email to [email protected]
