Sure, I am really missing this information written on the wiki page. The secret is, they are in the DNS record. If you try $ host -t URI _kerberos.fedoraproject.org
you might get it. But some DNS servers seem to have trouble with this record. As Red Hat defaults have dns_lookup_realm = false, we need manual configuration. I think there are more people like us. I think this should be mentioned on https://fedoraproject.org/wiki/Infrastructure/Kerberos: [realms] FEDORAPROJECT.ORG = { kdc = https://id.fedoraproject.org/KdcProxy } [domain_realm] fedoraproject.org = FEDORAPROJECT.ORG .fedoraproject.org = FEDORAPROJECT.ORG -- Petr Menšík Software Engineer Red Hat, http://www.redhat.com/ email: pemen...@redhat.com PGP: 65C6C973 ----- Original Message ----- From: "Dave Love" <d.l...@liverpool.ac.uk> To: devel@lists.fedoraproject.org Sent: Monday, December 12, 2016 5:36:24 PM Subject: Re: Packagers - Flag day 2016 Important changes Dennis Gilmore <den...@ausil.us> writes: > See the general kerberos information at: > https://fedoraproject.org/wiki/Infrastructure_kerberos_authentication > for more details. I was going to try to authenticate, even if the tools won't work, but that's missing the fundamental information about how to configure the realm for clients. What are the kdc(s) and admin_server (if admin_server is relevant)? _______________________________________________ devel mailing list -- devel@lists.fedoraproject.org To unsubscribe send an email to devel-le...@lists.fedoraproject.org _______________________________________________ devel mailing list -- devel@lists.fedoraproject.org To unsubscribe send an email to devel-le...@lists.fedoraproject.org