
Kerberos can decrypt the ticket. It would be quite inconvenient for the system adminis-
trator if he had to obtain new tickets for the SSH daemon every eight hours or so.
Instead, the key required to decrypt the initial ticket for the host principal is extracted
by the administrator from the KDC once and stored in a local file called the keytab.
Services such the SSH daemon read this key and use it to obtain new tickets automati-
cally when needed. The default keytab file resides in
/etc/krb5.keytab
.
To create a host principal for
test.example.com
, enter the following commands
during your kadmin session:
kadmin -p newbie/admin
Authenticating as principal newbie/[email protected] with password.
Password for newbie/[email protected]:
kadmin: addprinc -randkey host/test.example.com
WARNING: no policy specified for host/[email protected];
defaulting
to no policy
Principal "host/[email protected]" created.
Instead of setting a password for the new principal, the
-randkey
flag tells
kadmin
to generate a random key. This is used here because no user interaction is wanted for
this principal. It is a server account for the machine.
Finally, extract the key and store it in the local keytab file
/etc/krb5.keytab
.
This file is owned by the superuser, so you must be
root
to execute the next command
in the kadmin shell:
kadmin: ktadd host/test.example.com
Entry for principal host/test.example.com with kvno 3, encryption type Triple
DES cbc mode with HMAC/sha1 added to keytab WRFILE:/etc/krb5.keytab.
Entry for principal host/test.example.com with kvno 3, encryption type DES
cbc mode with CRC-32 added to keytab WRFILE:/etc/krb5.keytab.
kadmin:
When completed, make sure that you destroy the admin ticket obtained with kinit above
with
kdestroy
.
854
Installation and Administration
Summary of Contents for LINUX ENTERPRISE SERVER 10 - INSTALLATION AND ADMINISTRATION 11-05-2007
Page 1: ...SUSE Linux Enterprise Server www novell com 10 May 11 2007 Installation and Administration...
Page 14: ......
Page 19: ...Part I Deployment...
Page 20: ......
Page 60: ......
Page 128: ......
Page 243: ...Part II Administration...
Page 244: ......
Page 274: ......
Page 312: ......
Page 348: ......
Page 380: ......
Page 381: ...Part III System...
Page 382: ......
Page 438: ......
Page 452: ......
Page 478: ......
Page 486: ......
Page 498: ......
Page 512: ......
Page 558: ......
Page 559: ...Part IV Services...
Page 560: ......
Page 652: ......
Page 670: ......
Page 742: ......
Page 754: ......
Page 796: ......
Page 817: ...Part V Security...
Page 818: ......
Page 858: ......
Page 886: ......
Page 910: ......
Page 911: ...Part VI Troubleshooting...
Page 912: ......
Page 924: ......