This soft copy for use by IBM employees only.
3.6.4 /etc/krb-srvtab
The server key file, /etc/krb-srvtab, contains the names and private keys of the
local instances of Kerberos-protected services. During the setup of the Control
Workstation or the nodes, the keys for service principals are stored in the
authenticated database (for use by the authentication server) and in the file
/etc/krb-srvtab (for use by the services themselves). So, every node and the
Control Workstation includes an /etc/krb-srvtab file that contains the keys for the
services provided on that host. On the Control Workstation, the hardmon and
rcmd service principals are in this file:
root@sp21cw0 / > klist -srvtab
Server key file:
/etc/krb-srvtab
Service
Instance
Realm
Key Version
------------------------------------------------------
hardmon sp21tr0 SP21CW0 1
rcmd
sp21tr0 SP21CW0 1
hardmon sp21cw0 SP21CW0 1
rcmd
sp21cw0 SP21CW0 1
Figure 26. Example of /etc/krb-srvtab from the Control Workstation
On the nodes, the rcmd service principals are in this file:
root@sp21n01 / > klist -srvtab
Server key file:
/etc/krb-srvtab
Service
Instance
Realm
Key Version
------------------------------------------------------
rcmd
sp21n01 SP21CW0 1
Figure 27. Example of /etc/krb-srvtab f r o m a Node
Note:
Always ensure that the service keys contained in the authentication
database and in the /etc/krb-srvtab files on the nodes match. The
/usr/lpp/ssp/kerberos/etc/ext_srvtab
command can be used to create new
server key files for each node.
3.6.5 /etc/krb.conf
The SP authentication configuration file, /etc/krb.conf, defines the local
authentication realm and the location of authentication servers for known realms.
The first line contains the name of the local authentication realm. Subsequent
lines specify the authentication server for a realm.
This file is created by the setup_authent script on the primary authentication
server. You may supply your own krb.conf file before running setup_authent if
you want to use a non-default realm name (the default realm name is the
domain portion of the primary authentication server
′
s hostname converted to
uppercase).
root@sp21n01 / > cat /etc/krb.conf
SP21CW0
SP21CW0 sp21cw0 admin server
Figure 28. Example of a /etc/krb.conf File
78
SP PD Guide
Содержание RS/6000 SP
Страница 2: ......
Страница 14: ...This soft copy for use by IBM employees only xii SP PD Guide...
Страница 16: ...This soft copy for use by IBM employees only xiv SP PD Guide...
Страница 106: ...This soft copy for use by IBM employees only 86 SP PD Guide...
Страница 178: ...This soft copy for use by IBM employees only 158 SP PD Guide...
Страница 214: ...This soft copy for use by IBM employees only 194 SP PD Guide...
Страница 248: ...This soft copy for use by IBM employees only 228 SP PD Guide...
Страница 250: ...This soft copy for use by IBM employees only Figure 102 setup_authent Script Flow Chart 2 7 230 SP PD Guide...
Страница 252: ...This soft copy for use by IBM employees only Figure 104 setup_authent Script Flow Chart 4 7 232 SP PD Guide...
Страница 254: ...This soft copy for use by IBM employees only Figure 106 setup_authent Script Flow Chart 6 7 234 SP PD Guide...
Страница 258: ...This soft copy for use by IBM employees only Figure 110 install_cw Script Flow Chart 3 3 238 SP PD Guide...
Страница 260: ...This soft copy for use by IBM employees only Figure 112 setup_server Script Flow Chart 2 23 240 SP PD Guide...
Страница 262: ...This soft copy for use by IBM employees only Figure 114 setup_server Script Flow Chart 4 23 242 SP PD Guide...
Страница 264: ...This soft copy for use by IBM employees only Figure 116 setup_server Script Flow Chart 6 23 244 SP PD Guide...
Страница 266: ...This soft copy for use by IBM employees only Figure 118 setup_server Script Flow Chart 8 23 246 SP PD Guide...
Страница 268: ...This soft copy for use by IBM employees only Figure 120 setup_server Script Flow Chart 10 23 248 SP PD Guide...
Страница 270: ...This soft copy for use by IBM employees only Figure 122 setup_server Script Flow Chart 12 23 250 SP PD Guide...
Страница 272: ...This soft copy for use by IBM employees only Figure 124 setup_server Script Flow Chart 14 23 252 SP PD Guide...
Страница 274: ...This soft copy for use by IBM employees only Figure 126 setup_server Script Flow Chart 16 23 254 SP PD Guide...
Страница 276: ...This soft copy for use by IBM employees only Figure 128 setup_server Script Flow Chart 18 23 256 SP PD Guide...
Страница 278: ...This soft copy for use by IBM employees only Figure 130 setup_server Script Flow Chart 20 23 258 SP PD Guide...
Страница 280: ...This soft copy for use by IBM employees only Figure 132 setup_server Script Flow Chart 22 23 260 SP PD Guide...
Страница 284: ...This soft copy for use by IBM employees only Figure 136 rc switch Script Flow Chart 3 8 264 SP PD Guide...
Страница 286: ...This soft copy for use by IBM employees only Figure 138 rc switch Script Flow Chart 5 8 266 SP PD Guide...
Страница 288: ...This soft copy for use by IBM employees only Figure 140 rc switch Script Flow Chart 7 8 268 SP PD Guide...
Страница 290: ...This soft copy for use by IBM employees only 270 SP PD Guide...
Страница 292: ...This soft copy for use by IBM employees only 272 SP PD Guide...
Страница 300: ...This soft copy for use by IBM employees only 280 SP PD Guide...
Страница 304: ...This soft copy for use by IBM employees only 284 SP PD Guide...
Страница 308: ...This soft copy for use by IBM employees only 288 SP PD Guide...
Страница 310: ...This soft copy for use by IBM employees only 290 SP PD Guide...
Страница 316: ...IBML This soft copy for use by IBM employees only Printed in U S A SG24 4778 00...