HP
UX Kerberos Data Security Software Policy Migration on Step-wise Procedure For Migration on
Troubleshooting
Install
Error codes
Password
Editing the Default File
Symbols
Administration
Maintenance
Authentication Problems Occur
Diagnostic Tools Summary
Page 43
Migration
Chapter Overview
Chapter Overview
•
“Policy Migration” on page 44
•
“Step-wise
Procedure For Migration” on page 45
Chapter 3
43
Page 42
Page 44
Image 43
Page 42
Page 44
Contents
Manufacturing Part Number T1417-90003 E0602
Edition
Legal Notices
Page
Page
Contents
Administration
Contents
Contents
Inter-realm
Troubleshooting
Glossary Index
Contents
Tables
Tables
Figures
Figures
Preface
Related Documentation
Accessing the World Wide Web
Audience
Related Software Products
Related Request for Comments RFCs
Width
Conventions
Using This Manual
Glossary Index
Overview
Chapter Overview
How The Kerberos Server Works
Configuring and Administering the Kerberos Server on HP-UX
Authentication Process
Step
Authentication Process
TGT
Authentication Process
Authentication Process
Is added to the database. The krbtgt/REALM NAMEprincipal
DES vs 3DES Key Type Settings
Must be assigned a key type or default keys issued by
Krbtgt/REALM Name is the ticket-granting principal. This is
Installation
Installation
Before Installing The Kerberos Server
Hardware Requirements
Software Requirements
Installing The Kerberos Server
With SD-UX
Installing The Kerberos Server Chapter
Migration
Migration
Policy Migration on Step-wise Procedure For Migration on
Policy Migration
Step-wise Procedure For Migration
For version 2.0 of the Kerberos Server, as described in Step
On successful completion the following message is displayed
Step-wise Procedure For Migration Chapter
Interoperability With Windows
Interoperability With Windows
Chapter Overview
Understanding the Terminology
Understanding the Terminology
Table of Analogous Terms HP’s Kerberos Server Windows
Table of Analogous Terms
Case
HP’s Kerberos Server and Windows 2000 Interoperability
Establishing Trust Between HP’s Kerberos Servers and Windows
Single Realm Domain Authentication
Inter-Realm Inter-Domain Authentication
Postdated Tickets
Special Considerations for Interoperability
Database Considerations
Encryption Considerations
Special Considerations for Interoperability Chapter
Configuration
Configuration
Security Server Files That Require Configuration
Configuration Files For The Kerberos Server
File
Auto-Configuration of the Security Server
Auto-Configuration of the Security Server
Return to the main menu
Editing the Configuration Files
Manual Configuration Of The Kerberos Server
Manual Configuration Of The Kerberos Server
Krb.conf Format
Krb.conf
Realm
Sample krb.conf File
Reference
Krb.realms
Krb.realms Format
Krb.realms
Sample krb.realms
Sample krb.realms Chapter
Configuring The Primary Server
Creating The Principal Database After Installation
To add an administrative principal using
Add An Administrative Principal
Administrator
Run Command-Line-Administrator,kadmin
Create The host/fqdn principal And Extract Its Service Key
Start the Kerberos daemons
Define Secondary Server Network Locations
Adminaclfile
Password Policy File
Security Policies
Starting the Security Server
Summary
Sbin/initd/krbsrv start
Create the Principal Database
Configuring The Secondary Security Servers
Copy the Kerberos Configuration File
Create a host/fqdn Principal and Extract Its Key
Administration
Administration
Administering the Kerberos Database
Kadmind
Adminaclfile
Assigning Administrative Permissions
List prinicpal. This is redundant with i or
Adding Entries to the adminaclfile
Using Restricted Adminsitrator
Creating Administrative Accounts
How the r/R Modifiers Work
100
Password Policy setting Default
Password Policy File
Editing the Default File
Default Password Policy Settings for the base group
102
Principals
104
Adding User Principals
Adding New Service Principals
Reserved Service Principals
Chapter 107
Do not remove or modify this principal entry
Removing User Principals
Remove Special Privilege Settings
Protecting Secret Keys
Removing Service Principals
Administration Tools
Kadmin Vs kadminl
Administration Tools Tool Name Tool Description
Administrator
Apply
Standard Functionality of the Administrator
Usage of kadminlui
Local Administrator kadminlui
Chapter 117
Principals Tab
Principals Tab
Chapter 119
General Tab Principal Information Window
General Tab Principal Information window
Chapter 121
To add a principal
Adding Principals to the Database
To simultaneously add multiple principals with
Same settings
To create an administrative principal
Creating an Administrative Principal
Chapter 125
To search for a principal
Finding a Principal
Search Criteria
Chapter 127
128
To delete a user principal
Deleting a Principal
To reload the default values for a principal
Loading Default Values for a Principal
Restoring Previously Saved Values for a Principal
To restore previously saved values for a principal
To change ticket information
Changing Ticket Information
Chapter 133
Example
Rules for Setting Maximum Ticket Lifetime
Examples
Rules for Setting Maximum Renew Time
To change the password information
Changing Password Information
Password at their next logon
A principal’s password. You must inform the principal
Password Tab Principal Information Window
Password Tab Principal Information
Window
Chapter 139
Change Password Window Password Tab
Change Password window Password tab
Chapter 141
To change a DES principal’s key type to 3DES
Changing Key Types
Chapter 143
To change principal attributes
Changing Principal Attributes
Attributes Tab Principal Information Window
Attributes Tab Principal Information
146
Chapter 147
148
Chapter 149
To delete a service principal
Deleting a Service Principal
To securely extract principal keys to the service key
Extracting Service Keys
152
Extract Service Key Table Window
Extract Service Key Table window
154
To edit the default group
Using Groups to Control Settings
Group Information window Principal
Group Information Window
Default Principal Attributes
Setting the Default Group Principal Attributes
Principal Attributes
To set administrative permissions
Setting Administrative Permissions
Administrative Permissions
Administrative Permissions
Chapter 161
162
Realms Tab
Realms Tab
10 Realm Information Window Realms Tab
Realm Information window Realms tab
To add a realm
Adding a Realm
To delete a realm
Deleting a Realm
Remote Administrator kadminui
168
Administration
Manual Administration Using kadmin
Chapter 171
Add Random Key
Add a New Principal
Change Password to a New Randomly Generated Password
Specify New Password
Delete a Principal
Extract a Principal
Modifying a Principal
List the Attributes of a Principal
Number of Authentication failures fcnt
To modify the principal admin, you need to do the following
Attributes
Key Version Number Attribute
Allow Renewable Attribute
Allow Postdated Attribute
Allow Forwardable Attribute
Allow Proxy Attribute
Allow Duplicate Session Key Attribute
Require Preauthentication Attribute
Require Password Change Attribute
Lock Principal Attribute
Allow as Service Attribute
Following
Require Initial Authentication Attribute
Tgtbased
Authentication Set As Password Change Service Attribute
Password Expiration Attribute
Maximum Ticket Lifetime Attribute
Principal Expiration Attribute
Key Type Attribute
Maximum Renew Time Attribute
Salt Type Attribute
Chapter 189
Principal Database Utilities If you want to Use This Tool
Principal Database Utilities
Creating the Kerberos Database
192
Database Encryption
Database Master Password
Destroying the Kerberos Database
Dumping the Kerberos Database
Loading the Kerberos Database
Stashing the Master Key
Chapter 199
Starting and Stopping Daemons
Services Situation Daemons and Services
Situations that require Starting and Stopping Daemons
Host/fqdn@REALM
Maintenance Tasks
Master Password
Protecting Security Server Secrets
Special Note on Backing up the Principal Database
Backing Up Primary Server Data
Chapter 203
Removing Unused Space From the Database
Chapter 205
206
Propagation
208
Propagation Relationships
Propagation Hierarchy
Extracting a Key to the Service Key Table File
Service Key Table v5srvtab
Maintaining Secret Keys In The Key Table File
Deleting Older Keys From the Service Key Table File
Creating a New Service Key Table File
Propagation Tools If You Want To Use This Tool
Propagation Tools
Chapter 213
Kpropd
Mkpropcf
216
Kpropd.ini
Sections
Defaultvalues section
Chapter 219
Secsrvname Section
All servers contain the following entries
Examples
222
Prpadmin
Setting Up Propagation
Chapter 225
226
Chapter 227
228
Monitoring Propagation
Critical Error Messages
Monitoring the Log File
Monitoring for Old File Date and Large File Size
Monitoring Propagation Queue Files
Comparing the Database to its Copies
Principal.ok Time Stamp Does Not Update
Administration Appears Normal
Authentication Problems Occur
Kdbdump
Log Files Indicate Problems
Authentication Tests Succeed
Number of Principals Does Not Match
Restarting Propagation Using the Simple Process
Propagation Failure
Restarting Propagation Using the Full Dump Method
Converting a Secondary Server to a Primary Server
Cleaning the Temp Directory
Restarting Services
238
Number of Realms per Database
Configuring for Multi-realm Enterprises
Primary Servers That Support Multiple Realms
Adding More Realms to a Multi-realm Database
Multiple Primary Servers That Support a Single Realm
Database Propagation for Multi-realm Databases
To Configure a propagation in a multi-realm environment
242
Inter-realm
244
One-way Trust
Considering Trust Relationships
Two-way Trust
Other Types Of Trust
Hierarchical Trust
Chapter 247
248
Chapter 249
Configuring Direct Trust Relationships
Direct Trust Relationship Example
Hierarchical Chain of Trust
Hierarchical Inter-realm Trust
Hierarchical Inter-realm Example
Hierarchical Inter-realm Configuration
254
Chapter 255
256
Chapter 257
258
Troubleshooting
260
Chapter 261
Characterizing the Problem
Chapter 263
Diagnostic Tools
Diagnostic Tools Summary
Error Messages
Troubleshooting Kerberos
Logging Capabilities
Unix Syslog File
Services Checklist
Troubleshooting Techniques
Table of Errors Messages
Chapter 269
270
Forgotten Passwords
General Errors
Locking and Unlocking Accounts
Clock Synchronization
Decrypt integrity check failed
Typical User Error Messages
Action
Administrative Error Messages
Password has expired while getting initial ticket
Service key not available while getting initial ticket
Chapter 275
Reporting Problems to Your Hewlett-Packard Support Contact
Chapter 277
278
Glossary
Glossary
Glossary 281
Ticket-granting-ticket
Index
Symbols
284
285
Related manuals
Manual
327 pages
9.34 Kb
Manual
13 pages
9.67 Kb
Related pages
All Procedure page
Incoming Procedure of LAN for Sony PCS-1
Driveline Length Check Procedure for Servis-Rhino FM60/72
Additional Procedures Battery Verification for Apple 575
Function Procedure Comments for First Alert FA168C-CN
Emergency Recovery Procedure for Axis Communications axis communications dome network camera
Procedure for Digi TS 4
Procedures for Menu Operation for JVC DLA-HD10KSU/E
Overview of the NAC Controller PEP Shutdown Procedure for Enterasys Networks 2S4082-25-SYS
Procedure of cleaning for Panasonic PT-DW5100U
Procedure Prepare for tests for Frymaster M2000
How do the
amp ratings
compare between the 6 kVA and 10 kVA models?
Top
Page
Image
Contents