TD 92579EN
15 February 2012 / Ver. H
Installation and Operation Manual
IP-DECT Base Station & IP-DECT Gateway (software version 5.0.x)
64
The password used in the script is now possible to change to a more secret password from
the Kerberos server page.
It shall now be possible login to the Radio using the Kerberos login credentials, see
Log in
using Kerberos
on page 64.
Configure IPBS/IPBL as a client in a new system
Precondition: The IPBS/IPBL must have software version 4.1.x or higher.
The idea is to use the
Device Overview -> Add
to configure the Radios and the Kerberos
Client. By using this feature it is not needed to browse into each Radio for configuration.
The Radios are in broadcast mode which means none of them are attached to the Master
and configured. If any of the Radios are attached to the master and configured, the Radios
must be detached from the Master if this procedure shall work.
1
Select Device Overview > Radios.
2
Click "Add" to add the Radio to the Master.
3
In the
Add Radio
window, enter a name for the device. You can also add a Standby
Master IP Address.
4
Go to the
Kerberos
section and enter the following in the text fields:
Realm: Enter the realm name of the Kerberos server.
Host name: Optional.
User: Enter the same user name defined in the Kerberos server.
Password: Enter the same password defined in the Kerberos server.
Disable local authentication: Select the
Disable local authentication
check box
(recommended).
Overwrite existing: Select the
Overwrite existing
check box (optional).
5
Go to the
Authentication Servers
section.
6
In the
Realm/Domain
text field, enter the realm name specified in the Kerberos
server.
7
In the
Address
text field, enter the IP address of the Kerberos server. In the Kerberos
server enter 127.0.0.1 (localhost) as the IP address. The
Port
text field is filled out
automatically.
8
Click "OK".
Log in using Kerberos
1
Make sure that secure HTTPS protocol is used when logging in.
2
Login on the client using a server account. When prompted for user name, the
name of the realm has to be entered in front of the user name, separated by a
backslash in the following way: REALM\username.
Disable local authentication
It is recommended to disable local authentication after Kerberos authentication is
configured. It provides additional security and it is much easier to change the password of
a user account or delete a compromises user account on the Kerberos server than
changing the local user accounts on each IPBS/IPBL.
IMPORTANT:
Make sure that the Kerberos authentication is working properly before
disabling local authentication. If the Kerberos authentication is not
working and local authentication is disabled it is not possible to access the
IPBS/IPBL in any other way.