mit-kdc: Use more strict KDC default settings
[bbaumbach/samba-autobuild/.git] / selftest / target / Samba.pm
index c4f8eb5d4f9ebcd14c3a9022e9bab7457546f8ec..ab6d8edc2cce7c6be0d4c7cfe447fb0a41f602f8 100644 (file)
@@ -457,15 +457,22 @@ sub mk_mitkdc_conf($$)
 [kdcdefaults]
        kdc_ports = 88
        kdc_tcp_ports = 88
+       restrict_anonymous_to_tgt = true
 
 [realms]
        $ctx->{realm} = {
+               master_key_type = aes256-cts
+               default_principal_flags = +preauth
        }
 
        $ctx->{dnsname} = {
+               master_key_type = aes256-cts
+               default_principal_flags = +preauth
        }
 
        $ctx->{domain} = {
+               master_key_type = aes256-cts
+               default_principal_flags = +preauth
        }
 
 [dbmodules]