# krb5 を Homebrew, apk, Nix, pacman, zypper, apt, dnf でインストール

krb5 のインストール経路、実行ファイル、メタデータ、AI エージェント向けセキュリティノートを確認します。

## インストール

```sh
sudo av install brew:krb5
```

追加のインストールコマンド:

### macOS

- Homebrew (100%):

```sh
brew install krb5
```

  証拠: local Homebrew formula metadata

### Linux

- apk (92%):

```sh
sudo apk add krb5
```

  証拠: Alpine Linux edge package indexes: krb5 from https://dl-cdn.alpinelinux.org/alpine/edge/main/x86_64/APKINDEX.tar.gz

- Nix (92%):

```sh
nix profile install nixpkgs#krb5
```

  証拠: nixpkgs package indexes: pkgs/by-name/kr/krb5/package.nix from https://api.github.com/repos/NixOS/nixpkgs/git/trees/master?recursive=1

- pacman (92%):

```sh
sudo pacman -S krb5
```

  証拠: Arch Linux sync databases: krb5 from https://geo.mirror.pkgbuild.com/core/os/x86_64/core.db.tar.gz

- zypper (92%):

```sh
sudo zypper install krb5
```

  証拠: openSUSE Tumbleweed package metadata: krb5 from https://download.opensuse.org/tumbleweed/repo/oss/repodata/50b07339cb64c8ed4091bdbabddadc1ff5737b090e478818a195b40d8a3292861a879139b4a3987c31109699fde9fbf4a716367ddf4eef77da75f96e3193d6ed-primary.xml.zst

- Debian apt (92%):

```sh
sudo apt install krb5-admin-server
```

  証拠: Debian stable package indexes: krb5-admin-server from https://deb.debian.org/debian/dists/stable/main/binary-amd64/Packages.xz

- dnf (92%):

```sh
sudo dnf install krb5-devel
```

  証拠: Fedora Rawhide package metadata: krb5-devel from https://dl.fedoraproject.org/pub/fedora/linux/development/rawhide/Everything/x86_64/os/repodata/07190dc5ae9f35ae73866675fed6d95fe6e8d9fe22c9d7cdf85862cb2ed24a4c-primary.xml.zst

## パッケージ情報

- **パッケージキー:** brew:krb5
- **パッケージマネージャ:** Homebrew
- **バージョン:** 1.22.2
- **ソース概要:** Network authentication protocol
- **ホームページ:** <https://web.mit.edu/kerberos/>
- **最終更新:** 2026-07-18T21:10:59-04:00
- **生成日時:** 2026-08-03T19:37:03+00:00

## 実行可能ファイル

- compile_et (エイリアス)
- gss-client (エイリアス)
- gss-server (エイリアス)
- k5srvutil (エイリアス)
- kadmin (エイリアス)
- kadmin.local (エイリアス)
- kadmind (エイリアス)
- kdb5_util (エイリアス)
- kdestroy (エイリアス)
- kinit (エイリアス)
- klist (エイリアス)
- kpasswd (エイリアス)
- kprop (エイリアス)
- kpropd (エイリアス)
- kproplog (エイリアス)
- krb5-config (エイリアス)
- krb5-send-pr (エイリアス)
- krb5kdc (エイリアス)
- ksu (エイリアス)
- kswitch (エイリアス)
- ktutil (エイリアス)
- kvno (エイリアス)
- sclient (エイリアス)
- sim_client (エイリアス)
- sim_server (エイリアス)
- sserver (エイリアス)
- uuclient (エイリアス)
- uuserver (エイリアス)

## インストール挙動

- Bottle: 利用不可

## バージョンと鮮度

- ページ生成日: 2026-08-03
- マネージャ版: 1.22.2
## プロジェクトの歴史と使われ方

MIT Kerberos is the reference implementation of the Kerberos network authentication protocol. Among packages in this batch, krb5 has the deepest systems history: it is both a protocol suite and a user/admin toolchain whose commands, libraries, config files, credential caches, and keytabs became standard Unix security plumbing.

### プロジェクトの歴史

Kerberos was designed and implemented at MIT's Project Athena to solve open-network authentication problems for distributed workstations and services. MIT's overview describes it as a network authentication protocol using secret-key cryptography so clients and servers can prove identities over insecure networks.

The historical MIT dialogue about Kerberos was originally written in February 1988 and later updated with a Kerberos V5 afterword. Kerberos V5 was standardized by RFC 1510 and then clarified and superseded by RFC 4120 in July 2005.

MIT continues to publish krb5 source releases, documentation, user tools, administrator tools, GSS-API support, protocol documentation, and release notes. The public GitHub repository is described as a mirror of the MIT krb5 repository, while MIT's own web pages remain the authoritative release and documentation surface.

### 採用の歴史

Kerberos spread from MIT academic infrastructure into Unix, enterprise, and vendor authentication systems because it provided single sign-on semantics without sending reusable passwords to each service. MIT's site states that Kerberos is available in many commercial products as well as free source form.

Package-manager adoption is unusually broad because krb5 is not just an end-user utility: development headers, client commands such as kinit and klist, KDC/admin daemons, GSS-API libraries, keytab utilities, and service integrations all depend on it.

### 使われ方

The CLI workflow centers on acquiring tickets with kinit, inspecting credential caches with klist, destroying tickets with kdestroy, changing passwords with kpasswd, and administering principals and keytabs with kadmin and ktutil. System operation uses /etc/krb5.conf for realm and library configuration, credential caches such as /tmp/krb5cc_%{uid}, and keytabs such as /etc/krb5.keytab.

For package maintainers, krb5 is a security-sensitive dependency that touches command-line tools, libraries, daemons, PAM or GSS-API consumers, protocol compatibility, encryption-type deprecations, and CVE-driven patch releases.

### パッケージ好きにとっての重要性

krb5 is the kind of package that reveals the difference between an executable and an infrastructure component. Installing it may provide dozens of commands, shared libraries, config-file semantics, daemon behavior, protocol wire compatibility, and ABI/API commitments used by unrelated packages.

It is also a long-lived example of protocol packaging: the package has to track IETF standards, MIT release engineering, vendor interoperability, and security defaults such as DES, Triple-DES, RC4, PKINIT, PAC, and GSS-API changes over decades.

### タイムライン

- 1988: Bill Bryant wrote MIT's Kerberos design dialogue, reflecting the Project Athena authentication model.
- 1996: MIT krb5 1.0-era releases entered the historical release archive.
- 2005-07: RFC 4120 specified Kerberos V5 and obsoleted RFC 1510.
- 2012-05-12: The public GitHub mirror repository was created.
- 2026-01-29: MIT released krb5-1.22.2.

### Related projects

- Related standards and APIs include RFC 4120 Kerberos V5 and GSS-API integrations. Related implementations and deployments include vendor Kerberos products and operating-system authentication stacks that consume MIT krb5 libraries or interoperate with the protocol.

### ソース

- <https://github.com/krb5/krb5>
- <https://web.mit.edu/kerberos/>
- <https://web.mit.edu/kerberos/dialogue.html>
- <https://web.mit.edu/kerberos/historical.html>
- <https://web.mit.edu/kerberos/krb5-1.22/>
- <https://web.mit.edu/kerberos/krb5-latest/doc>
- <https://www.rfc-editor.org/rfc/rfc4120>


## セキュリティノート

broad file, network, media, or database tool signal.

- **Geiger リスク:** blue / 中
- broad file, network, media, or database tool signal


## Configuration and credential file locations

These source-backed paths show where this package keeps local settings or durable credentials. Automic Vault can use them as review targets for secret scanning, migration, and command approval.


## Configuration files

- Unix: /etc/krb5.conf

## Credential files

- Unix: /tmp/krb5cc_%{uid}, /etc/krb5.keytab
## 他のパッケージマネージャ記録

- Debian apt - krb5-admin-server - 1.21.3-5+deb13u1: normalized package name match | Debian stable package indexes: krb5-admin-server from https://deb.debian.org/debian/dists/stable/main/binary-amd64/Packages.xz | MIT Kerberos master server (kadmind) | https://web.mit.edu/kerberos/
- Debian apt - krb5-doc - 1.21.3-5+deb13u1: normalized package name match | Debian stable package indexes: krb5-doc from https://deb.debian.org/debian/dists/stable/main/binary-amd64/Packages.xz | documentation for MIT Kerberos | https://web.mit.edu/kerberos/
- Debian apt - krb5-gss-samples - 1.21.3-5+deb13u1: normalized package name match | Debian stable package indexes: krb5-gss-samples from https://deb.debian.org/debian/dists/stable/main/binary-amd64/Packages.xz | MIT Kerberos GSS Sample applications | https://web.mit.edu/kerberos/
- Debian apt - krb5-k5tls - 1.21.3-5+deb13u1: normalized package name match | Debian stable package indexes: krb5-k5tls from https://deb.debian.org/debian/dists/stable/main/binary-amd64/Packages.xz | TLS plugin for MIT Kerberos | https://web.mit.edu/kerberos/
- Debian apt - krb5-kdc - 1.21.3-5+deb13u1: normalized package name match | Debian stable package indexes: krb5-kdc from https://deb.debian.org/debian/dists/stable/main/binary-amd64/Packages.xz | MIT Kerberos key server (KDC) | https://web.mit.edu/kerberos/
- Debian apt - krb5-kdc-ldap - 1.21.3-5+deb13u1: normalized package name match | Debian stable package indexes: krb5-kdc-ldap from https://deb.debian.org/debian/dists/stable/main/binary-amd64/Packages.xz | MIT Kerberos key server (KDC) LDAP plugin | https://web.mit.edu/kerberos/
- Debian apt - krb5-kpropd - 1.21.3-5+deb13u1: normalized package name match | Debian stable package indexes: krb5-kpropd from https://deb.debian.org/debian/dists/stable/main/binary-amd64/Packages.xz | MIT Kerberos key server (Slave KDC Support) | https://web.mit.edu/kerberos/
- Debian apt - krb5-locales - 1.21.3-5+deb13u1: normalized package name match | Debian stable package indexes: krb5-locales from https://deb.debian.org/debian/dists/stable/main/binary-amd64/Packages.xz | internationalization support for MIT Kerberos | https://web.mit.edu/kerberos/
- Debian apt - krb5-multidev - 1.21.3-5+deb13u1: normalized package name match | Debian stable package indexes: krb5-multidev from https://deb.debian.org/debian/dists/stable/main/binary-amd64/Packages.xz | development files for MIT Kerberos without Heimdal conflict | https://web.mit.edu/kerberos/
- Debian apt - krb5-otp - 1.21.3-5+deb13u1: normalized package name match | Debian stable package indexes: krb5-otp from https://deb.debian.org/debian/dists/stable/main/binary-amd64/Packages.xz | OTP plugin for MIT Kerberos | https://web.mit.edu/kerberos/
- Debian apt - krb5-pkinit - 1.21.3-5+deb13u1: normalized package name match | Debian stable package indexes: krb5-pkinit from https://deb.debian.org/debian/dists/stable/main/binary-amd64/Packages.xz | PKINIT plugin for MIT Kerberos | https://web.mit.edu/kerberos/
- Debian apt - krb5-user - 1.21.3-5+deb13u1: normalized package name match | Debian stable package indexes: krb5-user from https://deb.debian.org/debian/dists/stable/main/binary-amd64/Packages.xz | basic programs to authenticate using MIT Kerberos | https://web.mit.edu/kerberos/
- Debian apt - libgssapi-krb5-2 - 1.21.3-5+deb13u1: normalized package name match | Debian stable package indexes: libgssapi-krb5-2 from https://deb.debian.org/debian/dists/stable/main/binary-amd64/Packages.xz | MIT Kerberos runtime libraries - krb5 GSS-API Mechanism | https://web.mit.edu/kerberos/
- Debian apt - libgssrpc4t64 - 1.21.3-5+deb13u1: normalized package name match | Debian stable package indexes: libgssrpc4t64 from https://deb.debian.org/debian/dists/stable/main/binary-amd64/Packages.xz | MIT Kerberos runtime libraries - GSS enabled ONCRPC | https://web.mit.edu/kerberos/
- Debian apt - libk5crypto3 - 1.21.3-5+deb13u1: normalized package name match | Debian stable package indexes: libk5crypto3 from https://deb.debian.org/debian/dists/stable/main/binary-amd64/Packages.xz | MIT Kerberos runtime libraries - Crypto Library | https://web.mit.edu/kerberos/
- Debian apt - libkadm5clnt-mit12 - 1.21.3-5+deb13u1: normalized package name match | Debian stable package indexes: libkadm5clnt-mit12 from https://deb.debian.org/debian/dists/stable/main/binary-amd64/Packages.xz | MIT Kerberos runtime libraries - Administration Clients | https://web.mit.edu/kerberos/


## Combined YAML source

View the package source record on GitHub. [combined/krb5.yml](https://github.com/mxcl/pkgdb/blob/main/combined/krb5.yml)


## ソース

- pkg.so package database
- Geiger risk classifier
- curated configuration and credential file locations
- curated package history
- pkgdb category and tag curation
- external package-manager database matches
- cross-ecosystem install command graph
