141
IGEL
Technology GmbH
IGEL Zero HDX
5.09.100
10.3.
AD/Kerberos Configuration
Menu path:
Setup > Devices > Security > Active Directory / Kerberos
Enable and configure Kerberos on these setup pages in order to use this service for login and single
sign-on purposes.
Standard realm
Specifies the standard Kerberos realm for the client. Set this value so that it
corresponds to your Kerberos realm (Windows domain).
DNS look-up KDC
Specifies whether DNS SRV records should be used to find key distribution
centers (KDCs, domain controllers) and other servers for a realm if they are
not indicated.
DNS look-up realm
Specifies whether DNS TXT records should be used to determine the
Kerberos realm of a host.
No addresses
If this option is set, the first Kerberos ticket is addressless. This may be
necessary if the client is located behind an NAT device (
Network Address
Translation
).
10.3.1.
Realm 1-4
Menu path:
Setup > Devices > Security > Active Directory / Kerberos > Realm [1-4]
Up to 4 realms where a login is possible can be configured here.
Realm
The name of the realm/the domains where you would like to authenticate yourself.
KDC list
IP or FQDN list of the
key distribution centers
(domain controllers) for this realm. An
optional port number preceded by a colon can be attached to the host name.
10.3.2.
Domain-Realm Mapping
Menu path:
Setup > Devices > Security > Active Directory / Kerberos > Domain Realm Mapping
Domain Realm Mapping
offers translation of a host name into the Kerberos realm name for the services
provided by this host.
Standard domain-realm mapping
This should be enabled if the DNS and realm names match.
Otherwise, you will need to create user-specific entries in the list.
DNS host or domain name
The entry can be a host name or a domain name. Domain names
are indicated by a preceding dot. Host names and domain names
should be entered in lower-case letters.
Realm
Kerberos realm name for this host or this domain