Administering the Kerberos Server

 

 

 

 

The kadmin and kadminl Utilities

 

 

Administration Utilities

 

 

Table 8-4 describes the administrative utilities that you can use to

 

 

administer the Kerberos database.

Table 8-4

 

Administration Utilities

 

 

 

 

 

 

 

 

Name

 

Description

 

 

 

 

 

 

 

kadminl_ui

 

The local graphical interface that runs on

 

 

 

 

the primary security server.

 

 

 

 

 

 

 

kadminl

 

The local command-line administrator that

 

 

 

 

runs on the primary security server.

 

 

 

 

 

 

 

kadmin_ui

 

The remote GUI that can only be run by

 

 

 

 

administrative principals with the required

 

 

 

 

permissions. It runs on all secondary

 

 

 

 

security servers and any client system

 

 

 

 

where the utility is installed.

 

 

 

 

 

 

 

kadmin

 

The remote command-line administrator

 

 

 

 

that can only be run by administrative

 

 

 

 

principals with the required permissions. It

 

 

 

 

runs on all secondary security servers and

 

 

 

 

on any client system where the utility is

 

 

 

 

installed.

 

 

 

 

 

 

 

krb5_encrypt

 

The krb5_encrypt tool encrypts the

 

 

 

 

password with the master key that is

 

 

 

 

located in the stash file.

 

 

 

 

 

 

 

 

 

NOTE

 

You cannot use the command-line administrator to control

 

 

administrative permissions, maximum ticket lifetimes and renew times

 

 

or the addition of new realms. Therefore, HP recommends that you use

 

 

the GUI administrative utility for all administrative purposes.

 

 

 

 

 

Chapter 8

131