Manuals
/
HP
/
Computer Equipment
/
Software
HP
UX Kerberos Data Security Software
manual
278
Models:
UX Kerberos Data Security Software
1
278
285
285
Download
285 pages
23.05 Kb
275
276
277
278
279
280
281
282
Troubleshooting
Install
Error codes
Password
Editing the Default File
Symbols
Administration
Maintenance
Authentication Problems Occur
Diagnostic Tools Summary
Page 278
Image 278
Troubleshooting
Reporting Problems to Your
Hewlett-Packard
Support Contact
278
Chapter 9
Page 277
Page 279
Page 278
Image 278
Page 277
Page 279
Contents
Edition
Manufacturing Part Number T1417-90003 E0602
Legal Notices
Page
Page
Contents
Administration
Contents
Contents
Inter-realm
Troubleshooting
Glossary Index
Contents
Tables
Tables
Figures
Figures
Preface
Related Software Products
Accessing the World Wide Web
Audience
Related Documentation
Related Request for Comments RFCs
Conventions
Width
Using This Manual
Glossary Index
Overview
Chapter Overview
How The Kerberos Server Works
Configuring and Administering the Kerberos Server on HP-UX
Authentication Process
Authentication Process
Step
TGT
Authentication Process
Authentication Process
Krbtgt/REALM Name is the ticket-granting principal. This is
DES vs 3DES Key Type Settings
Must be assigned a key type or default keys issued by
Is added to the database. The krbtgt/REALM NAMEprincipal
Installation
Installation
Before Installing The Kerberos Server
Hardware Requirements
Software Requirements
Installing The Kerberos Server
With SD-UX
Installing The Kerberos Server Chapter
Migration
Migration
Policy Migration on Step-wise Procedure For Migration on
Policy Migration
Step-wise Procedure For Migration
For version 2.0 of the Kerberos Server, as described in Step
On successful completion the following message is displayed
Step-wise Procedure For Migration Chapter
Interoperability With Windows
Interoperability With Windows
Chapter Overview
Understanding the Terminology
Understanding the Terminology
Table of Analogous Terms
Table of Analogous Terms HP’s Kerberos Server Windows
HP’s Kerberos Server and Windows 2000 Interoperability
Case
Establishing Trust Between HP’s Kerberos Servers and Windows
Single Realm Domain Authentication
Inter-Realm Inter-Domain Authentication
Encryption Considerations
Special Considerations for Interoperability
Database Considerations
Postdated Tickets
Special Considerations for Interoperability Chapter
Configuration
Configuration
File
Configuration Files For The Kerberos Server
Security Server Files That Require Configuration
Auto-Configuration of the Security Server
Auto-Configuration of the Security Server
Return to the main menu
Manual Configuration Of The Kerberos Server
Editing the Configuration Files
Manual Configuration Of The Kerberos Server
Krb.conf
Krb.conf Format
Realm
Sample krb.conf File
Reference
Krb.realms
Krb.realms Format
Krb.realms
Sample krb.realms
Sample krb.realms Chapter
Configuring The Primary Server
Creating The Principal Database After Installation
Administrator
Add An Administrative Principal
To add an administrative principal using
Run Command-Line-Administrator,kadmin
Create The host/fqdn principal And Extract Its Service Key
Start the Kerberos daemons
Define Secondary Server Network Locations
Security Policies
Password Policy File
Adminaclfile
Starting the Security Server
Summary
Sbin/initd/krbsrv start
Copy the Kerberos Configuration File
Configuring The Secondary Security Servers
Create the Principal Database
Create a host/fqdn Principal and Extract Its Key
Administration
Administration
Administering the Kerberos Database
Kadmind
Adminaclfile
Assigning Administrative Permissions
List prinicpal. This is redundant with i or
Adding Entries to the adminaclfile
How the r/R Modifiers Work
Creating Administrative Accounts
Using Restricted Adminsitrator
100
Default Password Policy Settings for the base group
Password Policy File
Editing the Default File
Password Policy setting Default
102
Principals
104
Adding New Service Principals
Adding User Principals
Reserved Service Principals
Chapter 107
Do not remove or modify this principal entry
Remove Special Privilege Settings
Removing User Principals
Protecting Secret Keys
Removing Service Principals
Kadmin Vs kadminl
Administration Tools
Administration Tools Tool Name Tool Description
Administrator
Standard Functionality of the Administrator
Apply
Local Administrator kadminlui
Usage of kadminlui
Chapter 117
Principals Tab
Principals Tab
Chapter 119
General Tab Principal Information window
General Tab Principal Information Window
Chapter 121
Adding Principals to the Database
To add a principal
Same settings
To simultaneously add multiple principals with
Creating an Administrative Principal
To create an administrative principal
Chapter 125
Search Criteria
Finding a Principal
To search for a principal
Chapter 127
128
Deleting a Principal
To delete a user principal
Loading Default Values for a Principal
To reload the default values for a principal
To restore previously saved values for a principal
Restoring Previously Saved Values for a Principal
Changing Ticket Information
To change ticket information
Chapter 133
Rules for Setting Maximum Ticket Lifetime
Example
Rules for Setting Maximum Renew Time
Examples
Changing Password Information
To change the password information
A principal’s password. You must inform the principal
Password at their next logon
Window
Password Tab Principal Information
Password Tab Principal Information Window
Chapter 139
Change Password window Password tab
Change Password Window Password Tab
Chapter 141
Changing Key Types
To change a DES principal’s key type to 3DES
Chapter 143
Changing Principal Attributes
To change principal attributes
Attributes Tab Principal Information
Attributes Tab Principal Information Window
146
Chapter 147
148
Chapter 149
Deleting a Service Principal
To delete a service principal
Extracting Service Keys
To securely extract principal keys to the service key
152
Extract Service Key Table window
Extract Service Key Table Window
154
Using Groups to Control Settings
To edit the default group
Group Information window Principal
Group Information Window
Principal Attributes
Setting the Default Group Principal Attributes
Default Principal Attributes
Setting Administrative Permissions
To set administrative permissions
Administrative Permissions
Administrative Permissions
Chapter 161
162
Realms Tab
Realms Tab
Realm Information window Realms tab
10 Realm Information Window Realms Tab
Adding a Realm
To add a realm
Deleting a Realm
To delete a realm
Remote Administrator kadminui
168
Administration
Manual Administration Using kadmin
Chapter 171
Add a New Principal
Add Random Key
Delete a Principal
Specify New Password
Change Password to a New Randomly Generated Password
Extract a Principal
List the Attributes of a Principal
Modifying a Principal
To modify the principal admin, you need to do the following
Number of Authentication failures fcnt
Key Version Number Attribute
Attributes
Allow Postdated Attribute
Allow Renewable Attribute
Allow Forwardable Attribute
Allow Proxy Attribute
Require Preauthentication Attribute
Allow Duplicate Session Key Attribute
Require Password Change Attribute
Allow as Service Attribute
Lock Principal Attribute
Require Initial Authentication Attribute
Following
Authentication Set As Password Change Service Attribute
Tgtbased
Password Expiration Attribute
Principal Expiration Attribute
Maximum Ticket Lifetime Attribute
Salt Type Attribute
Maximum Renew Time Attribute
Key Type Attribute
Chapter 189
Principal Database Utilities
Principal Database Utilities If you want to Use This Tool
Creating the Kerberos Database
192
Database Encryption
Database Master Password
Destroying the Kerberos Database
Dumping the Kerberos Database
Loading the Kerberos Database
Stashing the Master Key
Chapter 199
Situations that require Starting and Stopping Daemons
Services Situation Daemons and Services
Starting and Stopping Daemons
Protecting Security Server Secrets
Maintenance Tasks
Master Password
Host/fqdn@REALM
Backing Up Primary Server Data
Special Note on Backing up the Principal Database
Chapter 203
Removing Unused Space From the Database
Chapter 205
206
Propagation
208
Propagation Hierarchy
Propagation Relationships
Maintaining Secret Keys In The Key Table File
Service Key Table v5srvtab
Extracting a Key to the Service Key Table File
Creating a New Service Key Table File
Deleting Older Keys From the Service Key Table File
Propagation Tools
Propagation Tools If You Want To Use This Tool
Chapter 213
Kpropd
Mkpropcf
216
Kpropd.ini
Defaultvalues section
Sections
Chapter 219
Secsrvname Section
Examples
All servers contain the following entries
222
Prpadmin
Setting Up Propagation
Chapter 225
226
Chapter 227
228
Monitoring the Log File
Critical Error Messages
Monitoring Propagation
Monitoring Propagation Queue Files
Monitoring for Old File Date and Large File Size
Principal.ok Time Stamp Does Not Update
Comparing the Database to its Copies
Authentication Problems Occur
Administration Appears Normal
Number of Principals Does Not Match
Log Files Indicate Problems
Authentication Tests Succeed
Kdbdump
Restarting Propagation Using the Simple Process
Restarting Propagation Using the Full Dump Method
Propagation Failure
Converting a Secondary Server to a Primary Server
Restarting Services
Cleaning the Temp Directory
238
Primary Servers That Support Multiple Realms
Configuring for Multi-realm Enterprises
Number of Realms per Database
Database Propagation for Multi-realm Databases
Multiple Primary Servers That Support a Single Realm
Adding More Realms to a Multi-realm Database
To Configure a propagation in a multi-realm environment
242
Inter-realm
244
Two-way Trust
Considering Trust Relationships
One-way Trust
Hierarchical Trust
Other Types Of Trust
Chapter 247
248
Chapter 249
Configuring Direct Trust Relationships
Direct Trust Relationship Example
Hierarchical Inter-realm Example
Hierarchical Inter-realm Trust
Hierarchical Chain of Trust
Hierarchical Inter-realm Configuration
254
Chapter 255
256
Chapter 257
258
Troubleshooting
260
Chapter 261
Characterizing the Problem
Chapter 263
Diagnostic Tools Summary
Diagnostic Tools
Logging Capabilities
Troubleshooting Kerberos
Error Messages
Services Checklist
Unix Syslog File
Troubleshooting Techniques
Table of Errors Messages
Chapter 269
270
Locking and Unlocking Accounts
General Errors
Forgotten Passwords
Clock Synchronization
Typical User Error Messages
Decrypt integrity check failed
Service key not available while getting initial ticket
Administrative Error Messages
Password has expired while getting initial ticket
Action
Chapter 275
Reporting Problems to Your Hewlett-Packard Support Contact
Chapter 277
278
Glossary
Glossary
Glossary 281
Ticket-granting-ticket
Symbols
Index
284
285
Top
Page
Image
Contents