Configuring the Kerberos Server with LDAP

Configuration Files for LDAP Integration

attributetypes: ( hpKrbModifyTimestamp-oid NAME ’hpKrbModifyTimestamp’

DESC ’The date and time when the identity specified in the hpKrbModifiersName attribute made the last modification’ SYNTAX 1.3.6.1.4.1.1466.115.121.1.27

SINGLE-VALUE )

attributetypes: ( hpKrbAttributes-oid NAME ’hpKrbAttributes’

DESC ’A value containing one or more flags’

SYNTAX 1.3.6.1.4.1.1466.115.121.1.27

SINGLE-VALUE )

attributetypes: ( hpKrbPolicyName-oid NAME ’hpKrbPolicyName’

DESC ’The Kerberos password policy to which this principal subscribes to’

EQUALITY caseExactMatch

SYNTAX 1.3.6.1.4.1.1466.115.121.1.15

SINGLE-VALUE )

attributetypes: ( hpKrbKeyVersion-oid NAME ’hpkrbAuthzData’

DESC ’Other Authorization Data.’

SYNTAX 1.3.6.1.4.1.1466.115.121.1.40

SINGLE-VALUE ) add: objectClasses

objectClasses: ( hpKrbPrincipal-oid NAME ’hpKrbKeyVersion’

DESC ‘Version of a secret key; a monotomic increasing number beginning with 1’

SYNTAX 1.3.6.1.4.1.1466.115.121.1.27

SINGLE-VALUE )

attributetypes: ( hpKrbKeyData-oid NAME ’hpKrbKeyData’

DESC ’A set of values with each value containing an encrypted key and information about the encrypted key.’

SYNTAX 1.3.6.1.4.1.1466.115.121.1.40 ) attributetypes: ( hpkrbAuthzData-oid NAME ’hpKrbPrincipal’

DESC ’An auxiliary class for use in configuring an entry to represent a Kerberos principal.’

SUP top Auxiliary MAY ( hpKrbPrincipalName $ hpKrbMaxTicketAge $ hpKrbMaxRenewAge $ hpKrbAccountExpires $ hpKrbPasswordExpireTime $ hpKrbPwdLastSet $ hpKrbLastLogon $ hpKrbBadPasswordTime $ hpKrbBadPwdCount $ hpKrbModifiersName $ hpKrbModifyTimestamp $ hpKrbAttributes $ hpKrbPolicyName $ hpkrbAuthzData) )

80

Chapter 6