4 ms·
"You should set your hostname to be your FQDN, uppercased." Never had an issue with this. "name: initialize Kerberos ticket" What's the use case for this Ans
by bblb 11mo ago
"You should set your hostname to be your FQDN, uppercased."
Never had an issue with this.
"name: initialize Kerberos ticket"
What's the use case for this Ansible task. Never had a need to manually generate tickets.
edit: didn't read it through; this is part of their automation pipeline
--
We manage 1000+ Windows Servers with Ansible and it's been as simple as Linux SSH. Multiple SOCKS5 proxies to different AD forests, WinRM double hop works great when become:true, GPO works just fine on Linux, initial setup is very simple with realmd. Biggest manual task is setting up the service accounts for Ansible.
- mmh0000 11mo agoIt’s not required, but it is a long standing convention with the justification that it makes for easier troubleshooting. https://web.mit.edu/kerberos/www/krb5-latest/doc/admin/realm_config.html https://web.mit.edu/kerberos/www/krb5-latest/doc/admin/realm...
- jborean93 11mo agoThat's the realm side which should be upper case. The comment reference was for hostname themselves which I've always just done as lower case and have never seen a reason to make it upper case. The krb5.conf has a [domain_realm] section which can map a DNS name/suffix to the actual realm [domain_realm] .domain.com = DOMAIN.COM domain.com = DOMAIN.COM
- woleium 11mo agoiirc, on the windows side, workgroups had to be upper case, so initially the krb realm was set to the workgroup name. dns came later