Jump to content United States-English
HP.com Home Products and Services Support and Drivers Solutions How to Buy
» Contact HP
More options
HP.com home

Installing, Configuring and Administering the Kerberos Server V 2.0 on HP-UX 11i: HP 9000 Networking

» 

Technical documentation

Complete book in PDF
» Feedback
Content starts here

 » Table of Contents

 » Glossary

 » Index

HP Part Number: T1417-90003

Edition: Edition 2

Published: E0602


Table of Contents

Preface
Audience
Related Software Products
Related Documentation
Accessing the World Wide Web
Related Request for Comments (RFCs)
Conventions
Using This Manual
1 Overview
Chapter Overview
How The Kerberos Server Works
Authentication Process
DES vs 3DES Key Type Settings
2 Installation
Chapter Overview
Before Installing The Kerberos Server
Hardware Requirements
Software Requirements
Installing The Kerberos Server
3 Migration
Chapter Overview
Policy Migration
Step-wise Procedure For Migration
4 Interoperability With Windows 2000
Chapter Overview
Understanding the Terminology
Table of Analogous Terms
HP's Kerberos Server and Windows 2000 Interoperability
Establishing Trust Between HP's Kerberos Servers and Windows 2000
Single Realm (Domain) Authentication
Inter-Realm (Inter-Domain) Authentication
Special Considerations for Interoperability
Database Considerations
Encryption Considerations
Postdated Tickets
5 Configuration
Chapter Overview
Configuration Files For The Kerberos Server
Auto-Configuration of the Security Server
Manual Configuration Of The Kerberos Server
Editing the Configuration Files
krb.conf
krb.conf Format
Sample krb.conf File
krb.realms
krb.realms Format
Sample krb.realms
Configuring The Primary Server
Creating The Principal Database After Installation
Add An Administrative Principal
To add an administrative principal using the Administrator
To add an administrative principal using the Remote Command-Line-Administrator
Create The host/<fqdn> principal And Extract Its Service Key
Start the Kerberos daemons
Define Secondary Server Network Locations
Security Policies
Password Policy File
admin_acl_file
Starting the Security Server
Summary
Configuring The Secondary Security Servers
Create the Principal Database
Copy the Kerberos Configuration File
Create a host/<fqdn> Principal and Extract Its Key
6 Administration
Chapter Overview
Administering the Kerberos Database
kadmind
admin_acl_file
Assigning Administrative Permissions
Adding Entries to the admin_acl_file
Creating Administrative Accounts
Using Restricted Adminsitrator
Password Policy File
Editing the Default File
Principals
Adding User Principals
Adding New Service Principals
kadmin Vs kadminl
Administration Tools
Administrator
Standard Functionality of the Administrator
Local Administrator - kadminl_ui
Usage of kadminl_ui
Principals Tab
General Tab (Principal Information window)
Adding Principals to the Database
To add a principal
To simultaneously add multiple principals with the same settings
Creating an Administrative Principal
To create an administrative principal
Finding a Principal
To search for a principal
Search Criteria
Deleting a Principal
To delete a user principal
Loading Default Values for a Principal
To reload the default values for a principal
Restoring Previously Saved Values for a Principal
To restore previously saved values for a principal
Changing Ticket Information
To change ticket information
Rules for Setting Maximum Ticket Lifetime
Example
Rules for Setting Maximum Renew Time
Examples
Changing Password Information
To change the password information
Password Tab (Principal Information window)
Change Password window (Password tab)
Changing Key Types
To change a DES principal's key type to 3DES
Changing Principal Attributes
To change principal attributes
Attributes Tab (Principal Information window)
Deleting a Service Principal
To delete a service principal
Extracting Service Keys
To securely extract principal keys to the service key table
Extract Service Key Table window
Using Groups to Control Settings
To edit the default group
Group Information window (Principal Information window)
Principal Attributes
Setting Administrative Permissions
To set administrative permissions
Administrative Permissions
Realms Tab
Realm Information window (Realms tab)
Adding a Realm
To add a realm
Deleting a Realm
To delete a realm
Remote Administrator - kadmin_ui
Manual Administration Using kadmin
Add a New Principal
Add Random Key
Specify New Password
Change Password to a New Randomly Generated Password
Delete a Principal
Extract a Principal
List the Attributes of a Principal
Modifying a Principal
Principal Database Utilities
Creating the Kerberos Database
Database Encryption
Database Master Password
Destroying the Kerberos Database
Dumping the Kerberos Database
Loading the Kerberos Database
Stashing the Master Key
Starting and Stopping Daemons
Maintenance Tasks
Protecting Security Server Secrets
Backing Up Primary Server Data
Special Note on Backing up the Principal Database
Removing Unused Space From the Database
7 Propagation
Chapter Overview
Propagation Hierarchy
Propagation Relationships
Service Key Table (v5srvtab)
Maintaining Secret Keys In The Key Table File
Propagation Tools
kpropd
mkpropcf
kpropd.ini
Sections
prpadmin
Setting Up Propagation
Monitoring Propagation
Monitoring the Log File
Restarting Propagation Using the Simple Process
Restarting Propagation Using the Full Dump Method
Propagation Failure
Converting a Secondary Server to a Primary Server
Restarting Services
Cleaning the Temp Directory
Configuring for Multi-realm Enterprises
Number of Realms per Database
Primary Servers That Support Multiple Realms
Multiple Primary Servers That Support A Single Realm
Adding More Realms to a Multi-realm Database
Database Propagation for Multi-realm Databases
8 Inter-realm
Considering Trust Relationships
One-way Trust
Two-way Trust
Hierarchical Trust
Other Types Of Trust
Configuring for Multi-realm Enterprises
Number of Realms per Database
Primary Servers That Support Multiple Realms
Multiple Primary Servers That Support A Single Realm
Adding More Realms to a Multi-realm Database
Database Propagation for Multi-realm Databases
Configuring Direct Trust Relationships
Direct Trust Relationship Example
Hierarchical Inter-realm Trust
A Hierarchical Chain of Trust
Hierarchical Inter-realm Example
Hierarchical Inter-realm Configuration
9 Troubleshooting
Chapter Overview
Characterizing the Problem
Diagnostic Tools Summary
Troubleshooting Kerberos
Error Messages
Logging Capabilities
Services Checklist
Troubleshooting Techniques
General Errors
Forgotten Passwords
Locking and Unlocking Accounts
Clock Synchronization
Typical User Error Messages
Decrypt integrity check failed
Password has already been used or is too close to current one
Administrative Error Messages
Password has expired while getting initial ticket
Service key not available while getting initial ticket
Reporting Problems to Your Hewlett-Packard Support Contact
Glossary
Index
Printable version
Privacy statement Using this site means you accept its terms Feedback to webmaster
© 2002 Hewlett-Packard Development Company, L.P.