| United States-English |
|
|
|
![]() |
Kerberos Server Version 3.12 Administrator's Guide: HP-UX 11i v3 > Chapter 7 Configuring the Primary
and Secondary Security ServerConfiguring the Secondary Security Servers with C-Tree |
|
You can now configure the secondary security servers. Assuming that you are setting up the primary security server so that you can easily switch the primary security server with one of the secondary security servers, you must perform each of the steps on the primary security server as well as on the secondary security server. All secondary security servers require the following basic configuration tasks:
By default, the Kerberos security server uses DES3 to encrypt the principal database. If you are using DES encryption to secure your principal database, use the following command:
where enctype is DES-CBC-CRC, DES-CBC-MD5, or DES3-CBC-MD5. You can also specify 1 for DES-CBC-CRC, 3 for DES-CBC-MD5, and 5 for DES3-CBC-MD5. Each secondary security server must have a copy of the Kerberos configuration files from the primary security server. The following is the default path and file name:
Following lists the default configuration files required on the secondary security server:
To allow principal database propagation, each secondary security server must contain a host/<fqdn> principal. You must also extract the key for the host/<fqdn> principal to that service key table file of the server. You can create a host/<fqdn> principal and extract its key on a secondary security server by using the same procedure that is used on the primary security server. You need not log on as a root user to perform these tasks on a secondary security server. You can run kadmin and log on using the administrative principal name and password when prompted. For more information, see “Create the host/<fqdn> Principal and Extracting the Service Key”. Each KDC must have a host service principal in the Kerberos database. You can create a host service principal from any host if the kadmind daemon is running. |
||||||||||||||||||||||||||||||||||||||||||||||||||||
|
|||||||||||||||