DETAILED STEPS
Step 1
Use the
su
command to become root on the host running the KDC.
Step 2
Use the
kdb5_edit
program to configure the commands in the next steps.
The Kerberos realm name in the following steps must be in uppercase characters.
Note
Step 3
Use the
ank
(add new key) command in privileged EXEC mode to add a user to the KDC. This command prompts for
a password that the user must enter to authenticate the router. For example:
Example:
Device #
ank username@REALM
Step 4
Use the
ank
command to add a privileged instance of a user. For example:
Device #
ank username/instance@REALM
Example
The following example adds the user
loki
to the Kerberos realm COMPANY.COM:
Privileged instances can be created to allow network administrators to connect to the router at the enable level
so that a clear text password is not used to avoid compromising security and to enter enabled modes. See the
Enabling Kerberos Instance Mapping, on page 991
for more information on mapping Kerberos instances to
various Cisco IOS privilege levels.
Creating and Extracting a SRVTAB on the KDC
All devices authenticated through Kerberos must have a SRVTAB that contains the password or randomly
generated key for the service principal key that was entered into the KDC database. A service principal key
must be shared with the host running that service. To do this, the SRVTAB entry must be saved (extracted)
to a file and copied to the device and all hosts in the Kerberos realm.
Follow these steps to make a SRVTAB entry and extract this SRVTAB to a file on the KDC in privileged
EXEC mode:
SUMMARY STEPS
1.
Use the
ark
(add random key) command to add a network service supported by a host or device to the
KDC. For example:
2.
Use the kdb5_edit command
xst
to write an SRVTAB entry to a file. For example:
3.
Use the
quit
command to exit the kdb5_edit program.
Consolidated Platform Configuration Guide, Cisco IOS Release 15.2(4)E (Catalyst 2960-X Switches)
986
How to Configure Kerberos
Summary of Contents for Catalyst 2960 Series
Page 96: ......
Page 196: ......
Page 250: ......
Page 292: ......
Page 488: ......
Page 589: ...P A R T VI Cisco Flexible NetFlow Configuring NetFlow Lite page 509 ...
Page 590: ......
Page 619: ...P A R T VII QoS Configuring QoS page 539 Configuring Auto QoS page 645 ...
Page 620: ......
Page 750: ......
Page 1604: ......
Page 1740: ......
Page 2105: ...P A R T XII Configuring Cisco IOS IP SLAs Configuring Cisco IP SLAs page 2025 ...
Page 2106: ......
Page 2118: ......
Page 2164: ......