Can multiple KDCs be setup within an Active Directory ( AD ) integration?
In general you can setup multiple KDCs within your KRB5.conf file. The format, in general, would be:
[realms]
MY.REALM.COM = {
kdc = KDC1.MY.REALM.COM
kdc = KDC2.MY.REALM.COM
}
As another example of multiple KDCs setup you can see as reference http://www.domainexample.gov/docs/strongauth/krb5conf.html
16.4 krb5.conf.template
[....]
FNAL.GOV = {
kdc = krb-fnal-1.domainexample.gov:88
kdc = krb-fnal-2.domainexample.gov:88
kdc = krb-fnal-3.domainexample.gov:88
kdc = krb-fnal-4.domainexample.gov:88
kdc = krb-fnal-5.domainexample.gov:88
kdc = krb-fnal-6.domainexample.gov:88
admin_server = krb-domain-admin.fnal.gov
master_kdc = krb-domain-admin.domainexample.gov:88
default_domain = domainexample.gov
WIN.FNAL.GOV = {
kdc = domain.win.domainexample.gov:88
kdc = domain.win.domainexample.gov:88
default_domain = domainexample.gov
}
See also TECH220384 - Does Enforce support multiple Active Directory realms?