>>> Is there a way to make MIT's kadmin authenticate its user against the master kdc (in environments where there is only one) when the user's principal is not yet propagated (either due to latency or misadventure)?
>> Like kinit, kadmin will fall back to the master KDC on most AS request
>> errors if a master KDC is defined.  You need to set the master_kdc
>> relation in the realm section or create a _kerberos-master SRV record.
> With which version of Kerberos was master_kdc in the krb5.conf introduced?
> I saw it referenced in a mailing list post from a few years back, but my feeble searches on it turned up nothing useful.
Ah! I just checked and the message in question called it kdc_master, which is why I couldn't find it.


