21-39
Catalyst 6000 Family Software Configuration Guide—Releases 6.3 and 6.4
78-13315-02
Chapter 21 Configuring Switch Access Using AAA
Configuring Authentication
To encrypt a Telnet session, perform this task:
This example shows how to configure a Telnet session for Kerberos authentication and encryption:
Console> (enable)
telnet encrypt kerberos
Displaying and Clearing Kerberos Configurations
These commands can be used to display and clear Kerberos configurations on the switch:
•
show kerberos
•
show kerberos creds
•
clear kerberos creds
To display the Kerberos configuration, perform this task in privileged mode:
This example shows how to display the Kerberos configuration:
kerberos> (enable)
show kerberos
Kerberos Local Realm:CISCO.COM
Kerberos server entries:
Realm:CISCO.COM, Server:187.0.2.1, Port:750
Realm:CISCO.COM, Server:187.20.2.1, Port:750
Kerberos Domain<->Realm entries:
Domain:cisco.com, Realm:CISCO.COM
Kerberos Clients NOT Mandatory
Kerberos Credentials Forwarding Enabled
Kerberos Pre Authentication Method set to None
Kerberos config key:
Kerberos SRVTAB Entries
Srvtab Entry 1:host/[email protected] 0 932423923 1 1 8 03;;5>00>50;0=0=0
Srvtab Entry 2:host/[email protected] 0 933974942 1 1 8 00?58:127:223=:;9
kerberos> (enable)
To display the Kerberos credentials, perform this task in privileged mode:
This example shows how to display the Kerberos credentials:
Console> (enable)
show kerberos creds
No Kerberos credentials.
Console> (enable)
Task
Command
Encrypt a Telnet session.
telnet encrypt kerberos
host
Task
Command
Display the Kerberos configuration.
show kerberos
Task
Command
Display the Kerberos credentials.
show kerberos creds