570
Novell eDirectory 8.8 Administration Guide
no
vd
ocx (
E
NU)
01
F
ebr
ua
ry
200
6
Deleting a Realm Object
1
In iManager, click
Kerberos Management
>
Delete Realm
to open the Delete Realm page.
2
Select the realms that are to be deleted.
To select multiple realms, press Shift and select the realms or press Shift+Arrow keys.
3
Click
OK
.
4
Click
OK
again to confirm the delete operation or click
Cancel
to cancel the delete operation.
IMPORTANT:
Deleting a Realm object deletes all service principal objects under that Realm.
E.3.3 Managing a Service Principal
This section discusses the following:
•
“Creating a Service Principal for an LDAP Server” on page 570
•
“Extracting the Key of the Service Principal for eDirectory” on page 571
•
“Creating a Service Principal Object in eDirectory” on page 571
•
“Viewing the Kerberos Service Principal Keys” on page 572
•
“Deleting a Kerberos Service Principal Object” on page 572
•
“Setting a Password for the Kerberos Service Principal” on page 573
Creating a Service Principal for an LDAP Server
Use the Kerberos Administration tool that is available with your KDC to create the eDirectory
service principal with the encryption type and salt type as DES-CBC-CRC and Normal,
respectively.
The name of the principal must be ldap/
MYHOST.MYDNSDOMAIN
@
REALMNAME
.
For example, if you are using MIT KDC, execute the following command:
kadmin:addprinc -randkey -e des-cbc-crc:normal ldap/
server.novell.com@MITREALM
For example, if you are using Heimdal KDC, execute the following command:
kadmin -lkadmin> add --random-key ldap/server.novell.com@MITREALM
To delete the unsupported encryption types for the service principal, execute the following
command:
kadmin> del_enctype ldap/MYHOST.MYDNSDOMAIN@MYREALM des-cbc-
md4kadmin> del_enctype ldap/MYHOST.MYDNSDOMAIN@MYREALM des-cbc-
md5kadmin> del_enctype ldap/MYHOST.MYDNSDOMAIN@MYREALM des3-cbc-
sha1
where
MYHOST.MYDNSDOMAIN
is the host name and
MYREALM
is the Kerberos realm.
Summary of Contents for EDIRECTORY 8.8 - GUIDE
Page 4: ...novdocx ENU 01 February 2006...
Page 16: ...16 Novell eDirectory 8 8 Administration Guide novdocx ENU 01 February 2006...
Page 68: ...68 Novell eDirectory 8 8 Administration Guide novdocx ENU 01 February 2006...
Page 90: ...90 Novell eDirectory 8 8 Administration Guide novdocx ENU 01 February 2006...
Page 116: ...116 Novell eDirectory 8 8 Administration Guide novdocx ENU 01 February 2006...
Page 128: ...128 Novell eDirectory 8 8 Administration Guide novdocx ENU 01 February 2006...
Page 184: ...184 Novell eDirectory 8 8 Administration Guide novdocx ENU 01 February 2006...
Page 249: ...250 Novell eDirectory 8 8 Administration Guide novdocx ENU 01 February 2006...
Page 307: ...308 Novell eDirectory 8 8 Administration Guide novdocx ENU 01 February 2006...
Page 333: ...334 Novell eDirectory 8 8 Administration Guide novdocx ENU 01 February 2006...
Page 371: ...372 Novell eDirectory 8 8 Administration Guide novdocx ENU 01 February 2006...
Page 439: ...440 Novell eDirectory 8 8 Administration Guide novdocx ENU 01 February 2006...
Page 519: ...520 Novell eDirectory 8 8 Administration Guide novdocx ENU 01 February 2006...
Page 529: ...530 Novell eDirectory 8 8 Administration Guide novdocx ENU 01 February 2006...
Page 555: ...556 Novell eDirectory 8 8 Administration Guide novdocx ENU 01 February 2006...