On Mon, 12 Dec 2016 11:49:47 -0500 (EST)
Petr Mensik <pemen...@redhat.com> wrote:

> Sure, I am really missing this information written on the wiki page.
> The secret is, they are in the DNS record. If you try $ host -t URI
> _kerberos.fedoraproject.org
> 
> you might get it. But some DNS servers seem to have trouble with this
> record. As Red Hat defaults have dns_lookup_realm = false, we need
> manual configuration. I think there are more people like us. I think
> this should be mentioned on
> https://fedoraproject.org/wiki/Infrastructure/Kerberos:
> 
> [realms]
>      FEDORAPROJECT.ORG = {
>        kdc = https://id.fedoraproject.org/KdcProxy
>      }
> [domain_realm]
>      fedoraproject.org = FEDORAPROJECT.ORG
>      .fedoraproject.org = FEDORAPROJECT.ORG

This is included in the fedora-packager-0.6.0 update. 

Make sure your /etc/krb5.conf has the include to include them
from /etc/krb5.conf.d/ though

kevin

Attachment: pgp8EZ1OPP30P.pgp
Description: OpenPGP digital signature

_______________________________________________
devel mailing list -- devel@lists.fedoraproject.org
To unsubscribe send an email to devel-le...@lists.fedoraproject.org

Reply via email to