Migrating Krb5 realm

Andreas Ladanyi andreas.ladanyi at kit.edu
Thu May 21 09:40:02 EDT 2015


i want to migrate my old Krb5 Realm. I have a Krb5 own DB and want to
use LDAP to hold the principals in the future. Also i want to change the
realm name.

I read a lot about dumping the Krb5 DB with kdb5_util and restore them.
I also read something about replacing the master key or to reencrypt the
Krb5 DB with a new master key when dumping the DB with kdb5_util.

I dont read something about changing the realm name in the dumping
process. So iam asking myself the question if it is possible to dump,
reencrypt and change the realm name without changing the principals
password hashes ?


-------------- next part --------------
A non-text attachment was scrubbed...
Name: smime.p7s
Type: application/pkcs7-signature
Size: 5306 bytes
Desc: S/MIME Cryptographic Signature
Url : http://mailman.mit.edu/pipermail/kerberos/attachments/20150521/25b8183a/attachment.bin

More information about the Kerberos mailing list