
46
Installing and Administering
Kerberos
This section covers the installation of the MIT Kerberos implementation as well as
some aspects of administration. This section assumes you are familiar with the basic
concepts of Kerberos (see also
Chapter 45, Network Authentication—Kerberos
(page 833)).
46.1 Choosing the Kerberos Realms
The domain of a Kerberos installation is called a realm and is identified by a name,
such as
FOOBAR.COM
or simply
ACCOUNTING
. Kerberos is case-sensitive, so
foobar.com
is actually a different realm than
FOOBAR.COM
. Use the case you prefer.
It is common practice, however, to use uppercase realm names.
It is also a good idea to use your DNS domain name (or a subdomain, such as
ACCOUNTING.FOOBAR.COM
). As shown below, your life as an administrator can be
much easier if you configure your Kerberos clients to locate the KDC and other Kerberos
services via DNS. To do so, it is helpful if your realm name is a subdomain of your
DNS domain name.
Unlike the DNS name space, Kerberos is not hierarchical. You cannot set up a realm
named
FOOBAR.COM
, have two “subrealms” named
DEVELOPMENT
and
ACCOUNTING
underneath it, and expect the two subordinate realms to somehow inherit principals
from
FOOBAR.COM
. Instead, you would have three separate realms for which you
would have to configure crossrealm authentication for users from one realm to interact
with servers or other users from another realm.
Installing and Administering Kerberos
841
Summary of Contents for LINUX ENTERPRISE SERVER 10 - INSTALLATION AND ADMINISTRATION 11-05-2007
Page 1: ...SUSE Linux Enterprise Server www novell com 10 May 11 2007 Installation and Administration...
Page 14: ......
Page 19: ...Part I Deployment...
Page 20: ......
Page 60: ......
Page 128: ......
Page 243: ...Part II Administration...
Page 244: ......
Page 274: ......
Page 312: ......
Page 348: ......
Page 380: ......
Page 381: ...Part III System...
Page 382: ......
Page 438: ......
Page 452: ......
Page 478: ......
Page 486: ......
Page 498: ......
Page 512: ......
Page 558: ......
Page 559: ...Part IV Services...
Page 560: ......
Page 652: ......
Page 670: ......
Page 742: ......
Page 754: ......
Page 796: ......
Page 817: ...Part V Security...
Page 818: ......
Page 858: ......
Page 886: ......
Page 910: ......
Page 911: ...Part VI Troubleshooting...
Page 912: ......
Page 924: ......