Windows Kerberos Configuration Parameters

Document created by RSA Information Design and Development on Nov 22, 2016Last modified by RSA Information Design and Development on May 4, 2017
Version 10Show Document
  • View in full screen mode
  

This topic covers the Kerberos Realm configuration parameters for Windows Kerberos Authentication.

  1. In the Security Analytics menu, select Administration > Services.
  2. In the Services grid, select a Log Collector service.
  3. In the toolbar, select View > Config > Event Sources.
  4. In the Event Sources tab, select Windows/Kerberos Realm Configuration from the drop-down menu.

Features

The Windows/Kerberos Realm Configuration view in the Event Sources tab has one panel: Kerberos Realm Configuration.

Kerberos Realm Configuration Panel

In the Kerberos Realm Configuration panel, you can add, delete, or edit Kerberos realms.

Note: Security Analytics pre-fills the Mappings parameter based on the the Kerberos Realm Name parameter values that you enter.

                   
FeatureDescription
Icon-Add.pngDisplays the Add Kerberos Realm dialog in which you define Kerberos realm parameters.
Icon_Delete_sm.pngDeletes the selected Kerberos realms.
icon-edit.pngDisplays the Edit Kerberos Domain dialog in which you edit Kerberos realm parameters.
Checkbox.pngSelects Kerberos realms.
Kerberos realm parametersDisplays the realms that you have added with its parameters.

Add or Edit Kerberos Domain Dialog

In this dialog, you add or modify Kerberos realm parameters.

                      
Feature

Description

Kerberos Realm Name *Kerberos realm name. Valid value is a name that is in all upper case letters and is in Fully-Qualified Domain Name (FQDN) format.
KDC Host Name *A Key Distribution Center name. Valid value is a name that is in .domain-name format. If multiple KDCs are available, you can enter them using comma as a separator.
Admin Server(Optional) The name of the Kerberos Administration Server in FQDN format.
MappingsMappings from hosts to Kerberos realms. .domain,domain is the default value where domain is the Windows domain. If your deployment requires additional mappings, you can enter them using comma as a separator.

Note: Security Analytics pre-fills the Mappings parameter based on the the Kerberos Realm Name parameter values that you entered.

CloseCloses the dialog without adding the realm or saving modifications to the parameters.
SaveAdds the Kerberos realm parameters or saves modifications to the parameters.
You are here
Table of Contents > Windows Collection Configuration Guide > References - Windows Collection Configuration Parameters > Windows Kerberos Configuration Parameters

Attachments

    Outcomes