blob: 4b130fd9a39c1e6c02a4e2ff7a7d4ccba0497edc [file] [log] [blame]
# Lines starting with '#' and empty lines are ignored.
# Blocklisted directives
"module"
"include"
"includedir"
# Allowlisted keys in [libdefaults]
"canonicalize"
"clockskew"
"default_tgs_enctypes"
"default_tkt_enctypes"
"dns_canonicalize_hostname"
"dns_lookup_kdc"
"extra_addresses"
"forwardable"
"ignore_acceptor_hostname"
"kdc_default_options"
"kdc_timesync"
"noaddresses"
"permitted_enctypes"
"preferred_preauth_types"
"proxiable"
"rdns"
"renew_lifetime"
"ticket_lifetime"
"udp_preference_limit"
# Allowlisted keys in [realms]
"admin_server"
"auth_to_local"
"kdc"
"kpasswd_server"
"master_kdc" # nocheck
# Allowlisted sections
"libdefaults"
"realms"
"domain_realm"
"capaths"
# Other special characters
"["
"]"
"{"
"}"
"="
"\\n"
"*"
" "