HKLM\SYSTEM\CurrentControlSet\Control\Lsa\Kerberos\Domains\<Realm-name>
Data type | Range | Default value |
---|---|---|
REG_MULTI_SZ | Space-separated list of the DNS names of KDC servers | (There is no default value for this entry. You must specify at least one KDC server when you create a realm.) |
Stores the DNS names of computers running the Key Distribution Center (KDC) service for an Kerberos realm.
This entry stores the values you enter when you use the
Computers running Windows 2000 can use a non-Windows Kerberos server to administer authentication, instead of using a Windows 2000 domain for Kerberos authentication. These systems participate in an Kerberos realm instead of a Windows domain, and the DNS names for the KDC servers are stored in this entry in the registry, instead of on a domain controller.
To change the value of this entry, use Kerberos Setup (Ksetup.exe), a tool included in Windows 2000 Support Tools. Do not edit the registry.
Note
This entry is required for a Kerberos realm. The realm will not operate properly unless this entry appears in the registry.
Tip
For more information about KSetup.exe, see Tools Help in the Windows 2000 Support Tools. For more information about Kerberos interoperability features, see MIT Kerberos 5 (krb5 1.0) Interoperability on the Windows 2000 Server Security Services Web site.