Get a Quote   (408) 943-4100               TrueNAS Discord      VendOp_Icon_15x15px   Commercial Support Toggle between Light and Dark mode

Kerberos Screens

  2 minute read.

Last Modified 2022-05-07 16:35 EDT

Use the Directory Services > Kerberos screens to configure Kerberos realms and keytabs on your TrueNAs. Kerberos uses realms and keytabs to authenticate clients and servers.

KerberosRealmsScreen

Both the Kerberos Realsms and the Kerberos Keytabs screens display a table of what is added to the system.

Use the blue Columns button to display a list of options to customize the table displays for both the realms and keytabs screens.

Use ADD to display the settings screens for either realms or keytabs.

Selecting Kerberos Settings opens the settings screen but no table.

Kerberos Realms

Your network must contain a Key Distribution Center (KDC) to add a realm. A Kerberos realm is an authorized domain that a Kerberos server can use to authenticate a client. By default, TrueNAS creates a Kerberos realm for the local system.

Use ADD to create a realm on the TrueNAS. Use SUBMIT to save changes.

KerberosRealmAdvancedOptions

Basic Options

SettingDescription
Realmenter a name for the realm.

Advanced Options

SettingDescription
KDCEnter the name of the Key Distribution Center. Separate multiple values by pressing Enter.
Admin ServerDefine the server where all changes to the database are performed. Separate multiple values by pressing Enter.
Password ServerDefine the server where all password changes are performed. Separate multiple values by pressing Enter.

Kerberos Keytabs

A keytab (key table) is a file that stores encryption keys for various authentication scenarios. Kerberos keytabs allow systems and clients to join an Active Directory or LDAP without a password.

After generating the keytab, use the Add Kerberos Keytab screen to add it to your TrueNAS.

KerberosKeytabAddScreen

Kerberos Keytab

SettingDescription
NameEnter a name for the keytab.
Choose FileOpens a file explorer window where you can locate and select the keytab file.

Use SUBMIT to save settings or CANCEL to exit without saving.

Kerberos Settings

Use the Directory Services > Kerberos Settings screen to enter an additional settings.

KerberosSettingsScreen

SettingDescription
Appdefaults Auxiliary ParametersDefine any additional settings for use by some Kerberos applications. The available settings and syntax are listed in the [appdefaults] section of krb.conf(5).
Libdefaults Auxiliary ParametersDefine any settings used by the Kerberos library. The available settings and their syntax are listed in the [libdefaults] section of krb.conf(5).

Additional Information

Setting Up Kerberos