krb5.conf

[libdefaults]
    default_realm  = MS.MFF.CUNI.CZ MFF.CUNI.CZ
    allow_weak_crypto = true
    clockskew  = 600
    #default_cc_type =
    #default_cc_name =
    #default_etypes =
    default_as_etypes = aes256-cts-hmac-sha1-96 aes128-cts-hmac-sha1-96 des3-cbc-sha1 arcfour-hmac-md5 des-cbc-crc
    default_tgs_etypes  = aes256-cts-hmac-sha1-96 aes128-cts-hmac-sha1-96 des3-cbc-sha1 arcfour-hmac-md5
    srv_lookup  = false
    dns_lookup_kdc = false
    dns_lookup_realm = false
    forwardable  = true
    forward   = true
    ticket_lifetime = 24h
    renew_lifetime = 7d
    encrypt   = true
    fcache_strict_checking = false

[realms]
    MS.MFF.CUNI.CZ = {
    kdc   = kerberos.ms.mff.cuni.cz
    kdc   = kerberos2.ms.mff.cuni.cz
    admin_server = kerberos.ms.mff.cuni.cz
    kpasswd_server = kerberos.ms.mff.cuni.cz
    }
    MFF.CUNI.CZ = {
    kdc   = mff-krb.ms.mff.cuni.cz
    }

[domain_realm]
    .ms.mff.cuni.cz = MS.MFF.CUNI.CZ
    ms.mff.cuni.cz = MS.MFF.CUNI.CZ
    .n.mff.cuni.cz = MS.MFF.CUNI.CZ
    n.mff.cuni.cz  = MS.MFF.CUNI.CZ
    .mff.cuni.cz = MFF.CUNI.CZ
    mff.cuni.cz  = MFF.CUNI.CZ