Can multiple KDCs be set up within a realm in an Active Directory integration
search cancel

Can multiple KDCs be set up within a realm in an Active Directory integration

book

Article ID: 160549

calendar_today

Updated On:

Products

Data Loss Prevention Enforce

Issue/Introduction

Can multiple KDCs be setup within an Active Directory ( AD ) integration?

Resolution

In general you can setup multiple KDCs within your KRB5.conf file.  The format, in general, would be:

[realms]

MY.REALM.COM = {
kdc = KDC1.MY.REALM.COM
kdc = KDC2.MY.REALM.COM
}


As another example of multiple KDCs setup you can see as reference 
http://www.domainexample.gov/docs/strongauth/krb5conf.html

16.4 krb5.conf.template
[....]

FNAL.GOV = {
kdc = krb-fnal-1.domainexample.gov:88
kdc = krb-fnal-2.domainexample.gov:88
kdc = krb-fnal-3.domainexample.gov:88
kdc = krb-fnal-4.domainexample.gov:88
kdc = krb-fnal-5.domainexample.gov:88
kdc = krb-fnal-6.domainexample.gov:88
admin_server = krb-domain-admin.fnal.gov
master_kdc = krb-domain-admin.domainexample.gov:88
default_domain = domainexample.gov
WIN.FNAL.GOV = {
kdc = domain.win.domainexample.gov:88
kdc = domain.win.domainexample.gov:88
default_domain = domainexample.gov
}

 

See also TECH220384 - Does Enforce support multiple Active Directory realms?