Score:0

Kerberos: ticket with no REALM after principal name (i.e. `principal@`)

cn flag

When I run a klist after ssh-ing into a Kerberized instance, I obtain the TGS for the principal host/vmtest001, however, why do I get two of them including one with no REALM after the @ separator?

Here is the output of klist:

Ticket cache: FILE:/tmp/krb5cc_1000
Default principal: [email protected]

Valid starting     Expires            Service principal
06/13/21 21:05:00  06/14/21 07:05:00  krbtgt/[email protected]
        renew until 06/14/21 21:04:59
06/13/21 21:05:03  06/14/21 07:05:00  host/vmtest001@
        renew until 06/14/21 21:04:59
06/13/21 21:05:03  06/14/21 07:05:00  host/[email protected]
        renew until 06/14/21 21:04:59
Score:0
cn flag

Add this to your /etc/krb5.conf to explicity define the realm's domain:

[domain_realm]
    .example.com = EXAMPLE.COM
    example.com = EXAMPLE.COM
mangohost

Post an answer

Most people don’t grasp that asking a lot of questions unlocks learning and improves interpersonal bonding. In Alison’s studies, for example, though people could accurately recall how many questions had been asked in their conversations, they didn’t intuit the link between questions and liking. Across four studies, in which participants were engaged in conversations themselves or read transcripts of others’ conversations, people tended not to realize that question asking would influence—or had influenced—the level of amity between the conversationalists.