krb5.conf

[libdefaults]
    default_realm       = MS.MFF.CUNI.CZ
    allow_weak_crypto   = true
    srv_lookup          = false
    dns_lookup_kdc      = false
    dns_lookup_realm    = false
    forwardable         = true
    forward             = true
    ticket_lifetime     = 24h
    renew_lifetime      = 7d
    encrypt             = true

[realms]
    MS.MFF.CUNI.CZ = {
        kdc             = kerberos.ms.mff.cuni.cz
        kdc             = kerberos2.ms.mff.cuni.cz
        admin_server    = kerberos.ms.mff.cuni.cz
        kpasswd_server  = kerberos.ms.mff.cuni.cz
    }

[domain_realm]
    .ms.mff.cuni.cz     = MS.MFF.CUNI.CZ
    ms.mff.cuni.cz      = MS.MFF.CUNI.CZ