BlackBerry Dynamics properties

Kerberos Constrained Delegation

Property

Description

Default

Restart

Location of krb5.conf file on GC server (gc.krb5.config.file)

The location of the krb5.conf file that is required to configure KCD and to enable cross-realm authentication when there is a CAPATH trust relationship with multiple Kerberos domains.

Not set

Yes

Enable KCD debugging mode (gc.krb5.debug)

Whether UEM logs debug level data.

Off

Yes

Fully qualified name for the KDC (gc.krb5.kdc)

The FQDN of the server that hosts the Kerberos Key Distribution Center (KDC) service.

Not set

Yes

Location of keytab file (gc.krb5.keytab.file)

The location of the Kerberos keytab file on the computer that hosts BlackBerry UEM.

Not set

Yes

Service account name under which KCD service is running (gc.krb5.principal.name)

The username of the Kerberos account. Do not include the domain or realm.

Not set

Yes

Realm - Active Directory (gc.krb5.realm)

The realm of the Kerberos account.

Not set

Yes