[Authentication] When does 'realm discover' return two sections for the one realm, with one not configured?

Richard Sharpe realrichardsharpe at gmail.com
Tue Oct 15 16:26:38 UTC 2019


Hi folks,

Today I saw the following when running 'realm discover -v <some-realm>'
 * Resoving: _ldap._tcp.<some-realm>
 * Performing LDAP DSE LOOKUP on: 10.x.y.z
 * Performing LDAP DSE LOOKUP on: 10.x.a.z
 * Successfully discovered: <some-realm>
SOME-REALM
  type: kerberos
  realm-name: SOME-REALM
  domain-name: some-realm
  configured: kerberos-member
  ...
some-realm
  type: kerberos
  realm-name: SOME-REALM
  domain-name: some-realm
  configured: no

Why would a domain/realm have this second section?

-- 
Regards,
Richard Sharpe
(何以解憂?唯有杜康。--曹操)(传说杜康是酒的发明者)


More information about the Authentication mailing list