HP
UX Kerberos Data Security Software
manual
Troubleshooting
Install
Error messages
Password
Editing the Default File
Symbols
Administration
Maintenance
Authentication Problems Occur
Diagnostic Tools Summary
Page 189
Administration
Manual Administration Using kadmin
This attribute cannot be set with
Command-Line-Administrator
.
Chapter 6
189
Page 188
Page 190
Image 189
Page 188
Page 190
Contents
Manufacturing Part Number T1417-90003 E0602
Edition
Legal Notices
Page
Page
Contents
Administration
Contents
Contents
Inter-realm
Troubleshooting
Glossary Index
Contents
Tables
Tables
Figures
Figures
Preface
Audience
Accessing the World Wide Web
Related Software Products
Related Documentation
Related Request for Comments RFCs
Width
Conventions
Using This Manual
Glossary Index
Overview
Chapter Overview
How The Kerberos Server Works
Configuring and Administering the Kerberos Server on HP-UX
Authentication Process
Step
Authentication Process
TGT
Authentication Process
Authentication Process
Must be assigned a key type or default keys issued by
DES vs 3DES Key Type Settings
Krbtgt/REALM Name is the ticket-granting principal. This is
Is added to the database. The krbtgt/REALM NAMEprincipal
Installation
Installation
Before Installing The Kerberos Server
Hardware Requirements
Software Requirements
Installing The Kerberos Server
With SD-UX
Installing The Kerberos Server Chapter
Migration
Migration
Policy Migration on Step-wise Procedure For Migration on
Policy Migration
Step-wise Procedure For Migration
For version 2.0 of the Kerberos Server, as described in Step
On successful completion the following message is displayed
Step-wise Procedure For Migration Chapter
Interoperability With Windows
Interoperability With Windows
Chapter Overview
Understanding the Terminology
Understanding the Terminology
Table of Analogous Terms HP’s Kerberos Server Windows
Table of Analogous Terms
Case
HP’s Kerberos Server and Windows 2000 Interoperability
Establishing Trust Between HP’s Kerberos Servers and Windows
Single Realm Domain Authentication
Inter-Realm Inter-Domain Authentication
Database Considerations
Special Considerations for Interoperability
Encryption Considerations
Postdated Tickets
Special Considerations for Interoperability Chapter
Configuration
Configuration
Configuration Files For The Kerberos Server
Security Server Files That Require Configuration
File
Auto-Configuration of the Security Server
Auto-Configuration of the Security Server
Return to the main menu
Editing the Configuration Files
Manual Configuration Of The Kerberos Server
Manual Configuration Of The Kerberos Server
Krb.conf Format
Krb.conf
Realm
Sample krb.conf File
Reference
Krb.realms
Krb.realms Format
Krb.realms
Sample krb.realms
Sample krb.realms Chapter
Configuring The Primary Server
Creating The Principal Database After Installation
Add An Administrative Principal
To add an administrative principal using
Administrator
Run Command-Line-Administrator,kadmin
Create The host/fqdn principal And Extract Its Service Key
Start the Kerberos daemons
Define Secondary Server Network Locations
Password Policy File
Adminaclfile
Security Policies
Starting the Security Server
Summary
Sbin/initd/krbsrv start
Configuring The Secondary Security Servers
Create the Principal Database
Copy the Kerberos Configuration File
Create a host/fqdn Principal and Extract Its Key
Administration
Administration
Administering the Kerberos Database
Kadmind
Adminaclfile
Assigning Administrative Permissions
List prinicpal. This is redundant with i or
Adding Entries to the adminaclfile
Creating Administrative Accounts
Using Restricted Adminsitrator
How the r/R Modifiers Work
100
Editing the Default File
Password Policy File
Default Password Policy Settings for the base group
Password Policy setting Default
102
Principals
104
Adding User Principals
Adding New Service Principals
Reserved Service Principals
Chapter 107
Do not remove or modify this principal entry
Removing User Principals
Remove Special Privilege Settings
Protecting Secret Keys
Removing Service Principals
Administration Tools
Kadmin Vs kadminl
Administration Tools Tool Name Tool Description
Administrator
Apply
Standard Functionality of the Administrator
Usage of kadminlui
Local Administrator kadminlui
Chapter 117
Principals Tab
Principals Tab
Chapter 119
General Tab Principal Information Window
General Tab Principal Information window
Chapter 121
To add a principal
Adding Principals to the Database
To simultaneously add multiple principals with
Same settings
To create an administrative principal
Creating an Administrative Principal
Chapter 125
Finding a Principal
To search for a principal
Search Criteria
Chapter 127
128
To delete a user principal
Deleting a Principal
To reload the default values for a principal
Loading Default Values for a Principal
Restoring Previously Saved Values for a Principal
To restore previously saved values for a principal
To change ticket information
Changing Ticket Information
Chapter 133
Example
Rules for Setting Maximum Ticket Lifetime
Examples
Rules for Setting Maximum Renew Time
To change the password information
Changing Password Information
Password at their next logon
A principal’s password. You must inform the principal
Password Tab Principal Information
Password Tab Principal Information Window
Window
Chapter 139
Change Password Window Password Tab
Change Password window Password tab
Chapter 141
To change a DES principal’s key type to 3DES
Changing Key Types
Chapter 143
To change principal attributes
Changing Principal Attributes
Attributes Tab Principal Information Window
Attributes Tab Principal Information
146
Chapter 147
148
Chapter 149
To delete a service principal
Deleting a Service Principal
To securely extract principal keys to the service key
Extracting Service Keys
152
Extract Service Key Table Window
Extract Service Key Table window
154
To edit the default group
Using Groups to Control Settings
Group Information window Principal
Group Information Window
Setting the Default Group Principal Attributes
Default Principal Attributes
Principal Attributes
To set administrative permissions
Setting Administrative Permissions
Administrative Permissions
Administrative Permissions
Chapter 161
162
Realms Tab
Realms Tab
10 Realm Information Window Realms Tab
Realm Information window Realms tab
To add a realm
Adding a Realm
To delete a realm
Deleting a Realm
Remote Administrator kadminui
168
Administration
Manual Administration Using kadmin
Chapter 171
Add Random Key
Add a New Principal
Specify New Password
Change Password to a New Randomly Generated Password
Delete a Principal
Extract a Principal
Modifying a Principal
List the Attributes of a Principal
Number of Authentication failures fcnt
To modify the principal admin, you need to do the following
Attributes
Key Version Number Attribute
Allow Renewable Attribute
Allow Postdated Attribute
Allow Forwardable Attribute
Allow Proxy Attribute
Allow Duplicate Session Key Attribute
Require Preauthentication Attribute
Require Password Change Attribute
Lock Principal Attribute
Allow as Service Attribute
Following
Require Initial Authentication Attribute
Tgtbased
Authentication Set As Password Change Service Attribute
Password Expiration Attribute
Maximum Ticket Lifetime Attribute
Principal Expiration Attribute
Maximum Renew Time Attribute
Key Type Attribute
Salt Type Attribute
Chapter 189
Principal Database Utilities If you want to Use This Tool
Principal Database Utilities
Creating the Kerberos Database
192
Database Encryption
Database Master Password
Destroying the Kerberos Database
Dumping the Kerberos Database
Loading the Kerberos Database
Stashing the Master Key
Chapter 199
Services Situation Daemons and Services
Starting and Stopping Daemons
Situations that require Starting and Stopping Daemons
Master Password
Maintenance Tasks
Protecting Security Server Secrets
Host/fqdn@REALM
Special Note on Backing up the Principal Database
Backing Up Primary Server Data
Chapter 203
Removing Unused Space From the Database
Chapter 205
206
Propagation
208
Propagation Relationships
Propagation Hierarchy
Service Key Table v5srvtab
Extracting a Key to the Service Key Table File
Maintaining Secret Keys In The Key Table File
Deleting Older Keys From the Service Key Table File
Creating a New Service Key Table File
Propagation Tools If You Want To Use This Tool
Propagation Tools
Chapter 213
Kpropd
Mkpropcf
216
Kpropd.ini
Sections
Defaultvalues section
Chapter 219
Secsrvname Section
All servers contain the following entries
Examples
222
Prpadmin
Setting Up Propagation
Chapter 225
226
Chapter 227
228
Critical Error Messages
Monitoring Propagation
Monitoring the Log File
Monitoring for Old File Date and Large File Size
Monitoring Propagation Queue Files
Comparing the Database to its Copies
Principal.ok Time Stamp Does Not Update
Administration Appears Normal
Authentication Problems Occur
Authentication Tests Succeed
Log Files Indicate Problems
Number of Principals Does Not Match
Kdbdump
Restarting Propagation Using the Simple Process
Propagation Failure
Restarting Propagation Using the Full Dump Method
Converting a Secondary Server to a Primary Server
Cleaning the Temp Directory
Restarting Services
238
Configuring for Multi-realm Enterprises
Number of Realms per Database
Primary Servers That Support Multiple Realms
Multiple Primary Servers That Support a Single Realm
Adding More Realms to a Multi-realm Database
Database Propagation for Multi-realm Databases
To Configure a propagation in a multi-realm environment
242
Inter-realm
244
Considering Trust Relationships
One-way Trust
Two-way Trust
Other Types Of Trust
Hierarchical Trust
Chapter 247
248
Chapter 249
Configuring Direct Trust Relationships
Direct Trust Relationship Example
Hierarchical Inter-realm Trust
Hierarchical Chain of Trust
Hierarchical Inter-realm Example
Hierarchical Inter-realm Configuration
254
Chapter 255
256
Chapter 257
258
Troubleshooting
260
Chapter 261
Characterizing the Problem
Chapter 263
Diagnostic Tools
Diagnostic Tools Summary
Troubleshooting Kerberos
Error Messages
Logging Capabilities
Unix Syslog File
Services Checklist
Troubleshooting Techniques
Table of Errors Messages
Chapter 269
270
General Errors
Forgotten Passwords
Locking and Unlocking Accounts
Clock Synchronization
Decrypt integrity check failed
Typical User Error Messages
Password has expired while getting initial ticket
Administrative Error Messages
Service key not available while getting initial ticket
Action
Chapter 275
Reporting Problems to Your Hewlett-Packard Support Contact
Chapter 277
278
Glossary
Glossary
Glossary 281
Ticket-granting-ticket
Index
Symbols
284
285
Related manuals
Manual
327 pages
9.34 Kb
Manual
13 pages
9.67 Kb
Related pages
Troubleshooting for Apple V888N
TFT LCD Monitor Specifications for Planar PL120
Error messages for Panasonic AJ-PD950
Typical Wiring Diagram Legend See page 24, 25 for York B1HH018
Precautions When Using a Finisher for Minolta Di620
Installere applikationer for Samsung GT-S6310DBANEE
Parts List for Desa RV125EDI
Country/Area Code List for Parental Lock for JVC DR-MH30S
Setting the Screen Aspect Ratio for Vizio E420VP
What settings are recommended for using health airflow in different climates?
Recommended settings for health airflow
Top
Page
Image
Contents