KerbNet System Administrator's Guide
Release: 1.2
Document Edition: 1.2
Last updated: March 31, 1997
Cygnus Solutions
Introduction
Why Should I use Kerberos?
KerbNet Documentation
Using This Manual
How Kerberos Works
Network Services and Their Client Programs
Kerberos Services and Their Client Programs
The Kerberos Database
Kerberos Realms
The Ticket-Granting Ticket
Network Services and the Master Database
The Keytab File
A Detailed Look at the User--Kerberos Interaction
Definitions
Administration of the Kerberos Database
Principals
Adding and Modifying Principals
Deleting Principals
Changing Attributes of Principals
Policies
Administrative Privileges
Other Information
Date Format
Administration Using the Admin GUI
The Principal Information Window
Starting Up
Listing Selected Principals
The File Menu
Refreshing Displayed Information
Exiting the Admin GUI
The Principal Menu
Adding Principals
Deleting Principals
Displaying and Modifying Information About a Principal
Renaming a Principal
Copying a Principal
Changing a Password
Deactivating a Principal
Reactivating a Principal
The Policy Menu
The Policy List Dialog
Creating a Policy
Deleting a Policy
Modifying a Policy
Copying a Policy
Administration Using the Command Line Program
Kadmin Options
Principals
Retrieving Information About a Principal
Attributes
Retrieving a List of Principals
Adding or Modifying Principals
Deleting Principals
Renaming Principals
Changing Passwords
Policies
Retrieving Policies
Retrieving the List of Policies
Adding or Modifying Policies
Deleting Policies
Manipulating the Kerberos Database
Dumping a Kerberos Database to a File
Restoring a Kerberos Database from a Dump File
Creating a Stash File
Creating and Destroying a Kerberos Database
Backing Up the Kerberos Database
Application Servers
About Keytabs
Keys and Key Version Numbers
Manipulating Keytabs Using the Admin GUI
Creating a Keytab
Modifying an existing Keytab
Manipulating Keytabs Using the Command Line
Adding Principals to Keytabs
Removing Principals from Keytabs
Listing Keytabs
Keytabs and Making Backups
Clock Skew
Getting Name Service Information Correct
Configuring Your Firewall to Work With KerbNet
Configuration Files
krb5.conf
[libdefaults]
[appdefaults]
[realms]
[domain_realm]
[logging]
[capaths]
[kdc]
Sample krb5.conf File
kdc.conf
[kdcdefaults]
[realms]
Sample kdc.conf File
Updates
Updating KDCs
Updating Clients and Application Servers
Support
Supported Functionalities
System Administrator Commands
kdb5_util
kadmin and kadmin.local
kprop and kpropd
Login and User Admin Commands
kinit
klist
kdestroy
kpasswd
login.krb5
xdm
User Commands
rsh and kshd
rcp
telnet and telnetd
rlogin and klogind
ftp and ftpd
ksu
Using send-pr
Appendix
Kerberos Error Messages
Kerberos V5 Library Error Codes
Kerberos V5 Database Library Error Codes
Kerberos V5 Magic Numbers Error Codes
ASN.1 Error Codes
GSSAPI Error Codes
kadmin Time Zones