Jump to content United States-English
HP.com Home Products and Services Support and Drivers Solutions How to Buy
» Contact HP
More options
HP.com home
Kerberos Server Version 3.12 Administrator's Guide: HP-UX 11i v3 > Chapter 7 Configuring the Primary and Secondary Security Server

Configuring the Secondary Security Servers with LDAP

» 

Technical documentation

Complete book in PDF
» Feedback
Content starts here

 » Table of Contents

 » Glossary

 » Index

You can now configure the secondary security servers. Assuming that you are setting up the primary security server so that you can easily switch the primary security server with one of the secondary security servers, you must perform each of the steps on the primary security server as well as on the secondary security server.

All secondary security servers require the following basic configuration tasks:

  • Copying the Kerberos configuration files.

  • Creating a stash file using the kdb_stash utility.

Copying the Kerberos Configuration File

Each secondary security server must have a copy of the Kerberos configuration files (krb.conf)from the primary security server. The krb.conf file is located at:

/opt/krb5/krb.conf

Following lists the default configuration files required on the secondary security server:

  • krb.conf

  • krb.realms

  • krb5_ldap.conf

  • krb5_schema.conf

  • krb5_map.conf

Creating a stash file using the kdb_stash utility

You must create a stash file using the kdb_stash utility. This utility stores the master key in a stash file that the Kerberos server accesses when the security server daemons start up. You must specify the same key type and master password that was specified when the database was created.If you run the kdb_create utility with the -s option, a stash file is created automatically.

NOTE: The kdb_stash utility requires super user privileges to execute.
Printable version
Privacy statement Using this site means you accept its terms Feedback to webmaster
© 2007 Hewlett-Packard Development Company, L.P.