[libdefaults] default_realm = CLASSE.CORNELL.EDU ticket_lifetime = 24h default_tgs_enctypes = aes256-cts-hmac-sha1-96 aes128-cts-hmac-sha1-96 des3-hmac-sha1 default_tkt_enctypes = aes256-cts-hmac-sha1-96 aes128-cts-hmac-sha1-96 des3-hmac-sha1 permitted_enctypes = aes256-cts-hmac-sha1-96 aes128-cts-hmac-sha1-96 des3-hmac-sha1 default_etypes = aes256-cts-hmac-sha1-96 aes128-cts-hmac-sha1-96 des3-hmac-sha1 [realms] CLASSE.CORNELL.EDU = { kdc = dc1.classe.cornell.edu kdc = dc2.classe.cornell.edu kdc = dc4.classe.cornell.edu admin_server = dc1.classe.cornell.edu default_domain = classe.cornell.edu } LNS.CORNELL.EDU = { kdc = kerberos.lns.cornell.edu kdc = kerberos-1.lns.cornell.edu admin_server = kerberos.lns.cornell.edu default_domain = lns.cornell.edu } FNAL.GOV = { kdc = krb-fnal-1.fnal.gov:88 kdc = krb-fnal-2.fnal.gov:88 kdc = krb-fnal-3.fnal.gov:88 kdc = krb-fnal-4.fnal.gov:88 kdc = krb-fnal-5.fnal.gov:88 admin_server = krb-fnal-admin.fnal.gov default_domain=fnal.gov } CERN.CH = { default_domain = cern.ch kdc = cerndc.cern.ch } CIT.CORNELL.EDU = { kdc = kerberos.login.cornell.edu:88 kdc = kerberos2.login.cornell.edu:88 admin_server = kerberos.login.cornell.edu:749 default_domain = cit.cornell.edu } [domain_realm] .classe.cornell.edu = CLASSE.CORNELL.EDU classe.cornell.edu = CLASSE.CORNELL.EDU .lepp.cornell.edu = CLASSE.CORNELL.EDU lepp.cornell.edu = CLASSE.CORNELL.EDU .lns.cornell.edu = LNS.CORNELL.EDU lns.cornell.edu = LNS.CORNELL.EDU .fnal.gov = FNAL.GOV fnal.gov = FNAL.GOV .cern.ch = CERN.CH cornell.edu = CIT.CORNELL.EDU .cornell.edu = CIT.CORNELL.EDU .mail.cornell.edu = CIT.CORNELL.EDU [pam] debug = false ticket_lifetime = 36000 renew_lifetime = 36000 forwardable = true krb4_convert = false renewable = true [appdefaults] kinit = { renewable = true forwardable = true }