3.67.1. KrbRealm

This optional parameter is the name of the Kerberos realm that all Kerberos users are assumed to be in. Defaults to the default Kerberos realm defined by your Kerberos administrator.
Kerberos principal names are constructed by appending @KrbRealm to the RADIUS user name (after any RADIUS realm has been stripped off. So if a user tries to authenticate as user@realm.com, and KrbRealm is set to mykrb.com, then the Kerberos principal name that will be authenticated will be ‘user@mykerb.com’.
# All users are in this realm.