HP UX Kerberos Data Security Software manual Inter-realm

Page 9

Contents

Stashing the Master Key . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 198

Starting and Stopping Daemons . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 200

Maintenance Tasks . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 201

Protecting Security Server Secrets . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 201

Backing Up Primary Server Data . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 202

Special Note on Backing up the Principal Database . . . . . . . . . . . . . . . . . . . . . . . . 202

Removing Unused Space From the Database . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 204

7. Propagation

Chapter Overview . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 208 Propagation Hierarchy. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 209 Propagation Relationships . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 209 Service Key Table (v5srvtab) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 210 Maintaining Secret Keys In The Key Table File. . . . . . . . . . . . . . . . . . . . . . . . . . . . 210 Propagation Tools. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 212 kpropd . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 214 mkpropcf . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 215 kpropd.ini . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 217 Sections . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 218 prpadmin . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 223 Setting Up Propagation . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 224 Monitoring Propagation. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 229 Monitoring the Log File . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 229 Restarting Propagation Using the Simple Process . . . . . . . . . . . . . . . . . . . . . . . . . . 234 Restarting Propagation Using the Full Dump Method . . . . . . . . . . . . . . . . . . . . . . 235 Propagation Failure . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 235 Converting a Secondary Server to a Primary Server . . . . . . . . . . . . . . . . . . . . . . . . 236 Restarting Services . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 237 Cleaning the Temp Directory . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 237 Configuring for Multi-realm Enterprises . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 239 Number of Realms per Database . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 239 Primary Servers That Support Multiple Realms . . . . . . . . . . . . . . . . . . . . . . . . . . . 239 Multiple Primary Servers That Support A Single Realm . . . . . . . . . . . . . . . . . . . . 240 Adding More Realms to a Multi-realm Database . . . . . . . . . . . . . . . . . . . . . . . . . . . 240 Database Propagation for Multi-realm Databases . . . . . . . . . . . . . . . . . . . . . . . . . . 240

8. Inter-realm

Considering Trust Relationships . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 245

9

Image 9
Contents Manufacturing Part Number T1417-90003 E0602 EditionLegal Notices Page Page Contents Administration Contents Contents Inter-realm Troubleshooting Glossary Index Contents Tables Tables Figures Figures Preface Audience Accessing the World Wide WebRelated Software Products Related DocumentationRelated Request for Comments RFCs Width ConventionsUsing This Manual Glossary Index Overview Chapter Overview How The Kerberos Server Works Configuring and Administering the Kerberos Server on HP-UX Authentication Process Step Authentication ProcessTGT Authentication Process Authentication Process Must be assigned a key type or default keys issued by DES vs 3DES Key Type SettingsKrbtgt/REALM Name is the ticket-granting principal. This is Is added to the database. The krbtgt/REALM NAMEprincipalInstallation Installation Before Installing The Kerberos Server Hardware Requirements Software Requirements Installing The Kerberos Server With SD-UX Installing The Kerberos Server Chapter Migration Migration Policy Migration on Step-wise Procedure For Migration on Policy Migration Step-wise Procedure For Migration For version 2.0 of the Kerberos Server, as described in Step On successful completion the following message is displayed Step-wise Procedure For Migration Chapter Interoperability With Windows Interoperability With Windows Chapter Overview Understanding the Terminology Understanding the Terminology Table of Analogous Terms HP’s Kerberos Server Windows Table of Analogous TermsCase HP’s Kerberos Server and Windows 2000 InteroperabilityEstablishing Trust Between HP’s Kerberos Servers and Windows Single Realm Domain Authentication Inter-Realm Inter-Domain Authentication Database Considerations Special Considerations for InteroperabilityEncryption Considerations Postdated TicketsSpecial Considerations for Interoperability Chapter Configuration Configuration Configuration Files For The Kerberos Server Security Server Files That Require ConfigurationFile Auto-Configuration of the Security Server Auto-Configuration of the Security Server Return to the main menu Editing the Configuration Files Manual Configuration Of The Kerberos ServerManual Configuration Of The Kerberos Server Krb.conf Format Krb.confRealm Sample krb.conf File Reference Krb.realms Krb.realms Format Krb.realms Sample krb.realms Sample krb.realms Chapter Configuring The Primary Server Creating The Principal Database After Installation Add An Administrative Principal To add an administrative principal usingAdministrator Run Command-Line-Administrator,kadmin Create The host/fqdn principal And Extract Its Service Key Start the Kerberos daemons Define Secondary Server Network Locations Password Policy File AdminaclfileSecurity Policies Starting the Security Server Summary Sbin/initd/krbsrv start Configuring The Secondary Security Servers Create the Principal DatabaseCopy the Kerberos Configuration File Create a host/fqdn Principal and Extract Its Key Administration Administration Administering the Kerberos Database Kadmind Adminaclfile Assigning Administrative Permissions List prinicpal. This is redundant with i or Adding Entries to the adminaclfile Creating Administrative Accounts Using Restricted AdminsitratorHow the r/R Modifiers Work 100 Editing the Default File Password Policy FileDefault Password Policy Settings for the base group Password Policy setting Default102 Principals 104 Adding User Principals Adding New Service PrincipalsReserved Service Principals Chapter 107 Do not remove or modify this principal entry Removing User Principals Remove Special Privilege SettingsProtecting Secret Keys Removing Service Principals Administration Tools Kadmin Vs kadminlAdministration Tools Tool Name Tool Description Administrator Apply Standard Functionality of the AdministratorUsage of kadminlui Local Administrator kadminluiChapter 117 Principals Tab Principals TabChapter 119 General Tab Principal Information Window General Tab Principal Information windowChapter 121 To add a principal Adding Principals to the DatabaseTo simultaneously add multiple principals with Same settingsTo create an administrative principal Creating an Administrative PrincipalChapter 125 Finding a Principal To search for a principalSearch Criteria Chapter 127 128 To delete a user principal Deleting a PrincipalTo reload the default values for a principal Loading Default Values for a PrincipalRestoring Previously Saved Values for a Principal To restore previously saved values for a principalTo change ticket information Changing Ticket InformationChapter 133 Example Rules for Setting Maximum Ticket LifetimeExamples Rules for Setting Maximum Renew TimeTo change the password information Changing Password InformationPassword at their next logon A principal’s password. You must inform the principalPassword Tab Principal Information Password Tab Principal Information WindowWindow Chapter 139 Change Password Window Password Tab Change Password window Password tabChapter 141 To change a DES principal’s key type to 3DES Changing Key TypesChapter 143 To change principal attributes Changing Principal AttributesAttributes Tab Principal Information Window Attributes Tab Principal Information146 Chapter 147 148 Chapter 149 To delete a service principal Deleting a Service PrincipalTo securely extract principal keys to the service key Extracting Service Keys152 Extract Service Key Table Window Extract Service Key Table window154 To edit the default group Using Groups to Control SettingsGroup Information window Principal Group Information Window Setting the Default Group Principal Attributes Default Principal AttributesPrincipal Attributes To set administrative permissions Setting Administrative PermissionsAdministrative Permissions Administrative PermissionsChapter 161 162 Realms Tab Realms Tab10 Realm Information Window Realms Tab Realm Information window Realms tabTo add a realm Adding a RealmTo delete a realm Deleting a RealmRemote Administrator kadminui 168 Administration Manual Administration Using kadmin Chapter 171 Add Random Key Add a New PrincipalSpecify New Password Change Password to a New Randomly Generated PasswordDelete a Principal Extract a Principal Modifying a Principal List the Attributes of a PrincipalNumber of Authentication failures fcnt To modify the principal admin, you need to do the followingAttributes Key Version Number AttributeAllow Renewable Attribute Allow Postdated AttributeAllow Forwardable Attribute Allow Proxy Attribute Allow Duplicate Session Key Attribute Require Preauthentication AttributeRequire Password Change Attribute Lock Principal Attribute Allow as Service AttributeFollowing Require Initial Authentication AttributeTgtbased Authentication Set As Password Change Service AttributePassword Expiration Attribute Maximum Ticket Lifetime Attribute Principal Expiration AttributeMaximum Renew Time Attribute Key Type AttributeSalt Type Attribute Chapter 189 Principal Database Utilities If you want to Use This Tool Principal Database UtilitiesCreating the Kerberos Database 192 Database Encryption Database Master Password Destroying the Kerberos Database Dumping the Kerberos Database Loading the Kerberos Database Stashing the Master Key Chapter 199 Services Situation Daemons and Services Starting and Stopping DaemonsSituations that require Starting and Stopping Daemons Master Password Maintenance TasksProtecting Security Server Secrets Host/fqdn@REALMSpecial Note on Backing up the Principal Database Backing Up Primary Server DataChapter 203 Removing Unused Space From the Database Chapter 205 206 Propagation 208 Propagation Relationships Propagation HierarchyService Key Table v5srvtab Extracting a Key to the Service Key Table FileMaintaining Secret Keys In The Key Table File Deleting Older Keys From the Service Key Table File Creating a New Service Key Table FilePropagation Tools If You Want To Use This Tool Propagation ToolsChapter 213 Kpropd Mkpropcf 216 Kpropd.ini Sections Defaultvalues sectionChapter 219 Secsrvname Section All servers contain the following entries Examples222 Prpadmin Setting Up Propagation Chapter 225 226 Chapter 227 228 Critical Error Messages Monitoring PropagationMonitoring the Log File Monitoring for Old File Date and Large File Size Monitoring Propagation Queue FilesComparing the Database to its Copies Principal.ok Time Stamp Does Not UpdateAdministration Appears Normal Authentication Problems OccurAuthentication Tests Succeed Log Files Indicate ProblemsNumber of Principals Does Not Match KdbdumpRestarting Propagation Using the Simple Process Propagation Failure Restarting Propagation Using the Full Dump MethodConverting a Secondary Server to a Primary Server Cleaning the Temp Directory Restarting Services238 Configuring for Multi-realm Enterprises Number of Realms per DatabasePrimary Servers That Support Multiple Realms Multiple Primary Servers That Support a Single Realm Adding More Realms to a Multi-realm DatabaseDatabase Propagation for Multi-realm Databases To Configure a propagation in a multi-realm environment 242 Inter-realm 244 Considering Trust Relationships One-way TrustTwo-way Trust Other Types Of Trust Hierarchical TrustChapter 247 248 Chapter 249 Configuring Direct Trust Relationships Direct Trust Relationship Example Hierarchical Inter-realm Trust Hierarchical Chain of TrustHierarchical Inter-realm Example Hierarchical Inter-realm Configuration 254 Chapter 255 256 Chapter 257 258 Troubleshooting 260 Chapter 261 Characterizing the Problem Chapter 263 Diagnostic Tools Diagnostic Tools SummaryTroubleshooting Kerberos Error MessagesLogging Capabilities Unix Syslog File Services ChecklistTroubleshooting Techniques Table of Errors Messages Chapter 269 270 General Errors Forgotten PasswordsLocking and Unlocking Accounts Clock Synchronization Decrypt integrity check failed Typical User Error MessagesPassword has expired while getting initial ticket Administrative Error MessagesService key not available while getting initial ticket ActionChapter 275 Reporting Problems to Your Hewlett-Packard Support Contact Chapter 277 278 Glossary Glossary Glossary 281 Ticket-granting-ticket Index Symbols284 285
Related manuals
Manual 327 pages 9.34 Kb Manual 13 pages 9.67 Kb