217
1.877.877.2269
BLACKBOX.COM
NEED HELP?
LEAVE THE TECH TO US
LIVE 24/7
TECHNICAL
SUPPORT
1.877.877.2269
CHAPTER 10: AUTHENTICATION
Set a CLI Management Session Timeout in minutes. This specifies the ssh console session idle timeout. The default setting is to
never expire.
Set a Console Server Session Timeout in minutes.
This specifies the pmshell serial console server session idle timeout. The default setting is to never expire.
10.1.11 KERBEROS AUTHENTICATION
Kerberos authentication can be used with UNIX and Windows (Active Directory) Kerberos servers. This form of authentication does
not provide group information, so a local user with the same username must be created, and permissions set.
NOTE: Kerberos is sensitive to time differences between the Key Distribution Center (KDC) authentication server and the client
device. Make sure that NTP is enabled, and the time zone is set correctly on the console server.
FIGURE 10-9.
When authenticating against Active Directory, the Kerberos Realm will be the domain name, and the Master KDC will be the address
of the primary domain controller.
10.1.12 KERBEROS AUTHENTICATION
Console servers running firmware V3.5.2u3 or later include the Serial & Network > Authentication > Authentication Testing tab. This
tab enables the connection to the remote authentication server to be tested.
FIGURE 10-10.