
893-741-B
A15-53
Using Model 5390 Security
Filters can apply to one particular physical interface on the Model 5390 server or to all Model 5390
interfaces and can affect incoming or outgoing packets. An interface is a SLIP port named asyn,
where n is the port number, a PPP port named asyn or synn (again, n is the port number), or the
Ethernet port (en0).
For more details on filtering, see Filtering starting on page A13-1.
Using Kerberos Authentication
The default ACP configuration authenticates a user by checking the user name and password against
entries in the acp_passwd file. You can configure ACP to use Kerberos instead of the default
authentication process.
When building the ACP/erpcd process, a Kerberos library routine (libkrb.a) is linked with the ACP
code. ACP prompts the user for a user name and password. However, instead of validating the user
name and password via the acp_passwd file, ACP opens a connection to the Kerberos server and
passes the user name and password to the Kerberos library routine for authentication. The Kerberos
library routine returns a ticket to ACP indicating whether or not the user is authenticated.
If the Kerberos server authenticates the user, it encrypts the ticket with the user’s password before
returning it to ACP. If the Kerberos server rejects the user, it returns an error code, and ACP refuses
the login attempt. In either case, ACP calls a separate Kerberos routine to destroy the returned ticket
after the validation process.
NOTE:
You need superuser privileges not only to configure the Model
5390 server for filtering but also to create or modify filters.
Summary of Contents for 5390
Page 28: ...893 741 B Figures xxviii ...
Page 44: ...893 741 B Preface xliv ...
Page 45: ......
Page 48: ......
Page 60: ...A1 12 893 741 B Introduction to the Model 5390 Server ...
Page 106: ...A3 18 893 741 B Configuring Ports ...
Page 142: ...A5 12 893 741 B Printers ...
Page 152: ...A6 10 893 741 B Modems ...
Page 168: ...A7 16 893 741 B Serial Line Internet Protocol SLIP ...
Page 224: ...A9 38 893 741 B Internetwork Packet Exchange IPX Protocol ...
Page 258: ...A11 12 893 741 B Dial up Networking ...
Page 289: ...893 741 B A12 31 Internet Protocol IP Routing that are possible ...
Page 506: ...A15 86 893 741 B Using Model 5390 Security ...
Page 507: ......
Page 544: ...B1 36 893 741 B Network Administration ...
Page 574: ...B2 30 893 741 B Simple Network Management Protocol SNMP ...
Page 575: ......
Page 606: ...C1 30 893 741 B na Commands ...
Page 676: ...C2 70 893 741 B Configuration Parameters ...
Page 772: ...C3 96 893 741 B Using the CLI Commands ...
Page 794: ...C5 12 893 741 B Network Protocols ...
Page 795: ......
Page 796: ... Appendix D1 Software Reference Part D Appendixes ...