Jump to content United States-English
HP.com Home Products and Services Support and Drivers Solutions How to Buy
» Contact HP
More options
HP.com home
Kerberos Server Version 3.12 Administrator's Guide: HP-UX 11i v3 > Chapter 4 Interoperability with Windows 2000

Establishing Trust Between Kerberos Server and Windows 2000

» 

Technical documentation

Complete book in PDF
» Feedback
Content starts here

 » Table of Contents

 » Glossary

 » Index

To establish trust between Kerberos server KRB.REALM and Windows 2000 W2K.DOMAIN, complete the following steps:

  1. Add interrealm service principals to the Kerberos server realm. For more information, see “HP Kerberos Administrator”.

    • If the realm is the source realm, the name of the principal is krbtgt/W2K.DOMAIN@KRB.REALM.

    • If the realm is the target realm, the name of the principal is krbtgt/KRB.REALM@W2K.DOMAIN.

  2. On the Windows 2000 domain controller, use the Active Directory Domains and Trusts snap-in to create the trust relationship.

    • If the domain trusts the Kerberos server realm, add the realm name to the Domains that this domain trusts field.

    • If the Kerberos server realm trusts the Windows 2000 domain, add the realm name to the Domains that trust this domain’ field. Keep in mind that the passwords in steps 1 and 2 must be identical for the corresponding principals.

  3. Update the client configuration files or the DNS configuration with the name of the foreign KDC.

    • For the Kerberos server clients, perform the following steps:

      1. Add the Windows 2000 domain controller domain name and fully qualified domain name to the /etc/krb5.conf file of the client.

      2. Configure the [capaths] section for the direct trust relationship between the realms.

      3. Add the host-to-realm name mapping data for each available Windows 2000 service to the /etc/krb5.conf file of the client.

    • To invoke the Windows 2000 Ksetup tool on the Windows 2000 client, execute the following command:

      Ksetup/addkdc KRB.REALM <fqdn>

      NOTE: The fqdn qualifier specifies the fully qualified domain name of the Kerberos KDC.

  4. Reboot the Windows 2000 domain controller. You need not reboot the Kerberos server or client.

Printable version
Privacy statement Using this site means you accept its terms Feedback to webmaster
© 2007 Hewlett-Packard Development Company, L.P.