Administration
Manual Administration Using kadmin
The Local
To log in to the Remote Administrator, kadmin, you must use a principal account that has an entry in the admin_acl_file. For complete access to all the functions, use an unrestricted administrative principal account, one with the ‘*’ permissions in the admin_acl_file. At a minimum, the account must have the inquire privileges. For more information on administrative permissions, refer to “admin_acl_file” on page 95.
When you start the kadmin, a principal name must be specified at the command line prompt, else the default login name, with the admin instance appended to it, is used. If the
The kadmin has two mechanisms to authenticate the administrator. The first mechanism prompts administrators for a password. Then second uses the
All communications between the kadmin client and the
Once you have been authenticated, use the kadmin commands to manage the principal database. The kadmin commands have been discussed in the subsequent sections of this chapter.
NOTE | The | |
| cannot be used to control the following parameters of the user principals: | |
| • | administrative permissions |
| • | default group prinicpal |
| • maximum ticket lifetime and renew times | |
| • | adding new realms |
| • | alter key types |
Chapter 6 | 171 |