
628
Novell eDirectory 8.8 Administration Guide
n
ov
do
cx (e
n)
11
Ju
ly 20
08
E.3.3 Managing a Service Principal
This section discusses the following:
“Creating a Service Principal for an LDAP Server” on page 628
“Extracting the Key of the Service Principal for eDirectory” on page 629
“Creating a Service Principal Object in eDirectory” on page 629
“Viewing the Kerberos Service Principal Keys” on page 630
“Deleting a Kerberos Service Principal Object” on page 630
“Setting a Password for the Kerberos Service Principal” on page 631
Creating a Service Principal for an LDAP Server
Use the Kerberos Administration tool that is available with your KDC to create the eDirectory
service principal with the encryption type and salt type as DES-CBC-CRC and Normal,
respectively.
The name of the principal must be ldap/
MYHOST.MYDNSDOMAIN
@
REALMNAME
.
For example, if you are using MIT KDC, execute the following command:
kadmin:addprinc -randkey -e aes256-cts:normal ldap/
server.novell.com@MITREALM
For example, if you are using Heimdal KDC, execute the following command:
kadmin -l
kadmin> add --random-key ldap/server.novell.com@MITREALM
To delete the unsupported encryption types for the service principal, execute the following
command:
kadmin> del_enctype ldap/MYHOST.MYDNSDOMAIN@MYREALM des-cbc-
md4
kadmin> del_enctype ldap/MYHOST.MYDNSDOMAIN@MYREALM des-cbc-
md5
kadmin> del_enctype ldap/MYHOST.MYDNSDOMAIN@MYREALM des3-cbc-sha1
where
MYHOST.MYDNSDOMAIN
is the host name and
MYREALM
is the Kerberos realm.
IMPORTANT:
The hostname of service principal created must be in lowercase. Authentication
fails if the hostname is in uppercase. For example, if the hostname is myHost.com, the hostname
syntax of the ldap service principal should look like
ldap/myhost.com@<realmname>
.
Best Practice
All the keys should be preferably of type AES256.
Change the LDAP service principal keys regularly. Whenever you change the LDAP service
principal keys, ensure that you update the principal object in eDirectory.
Содержание EDIRECTORY 8.8 SP3
Страница 4: ...novdocx en 11 July 2008...
Страница 72: ...72 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Страница 120: ...120 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Страница 132: ...132 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Страница 190: ...190 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Страница 238: ...238 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Страница 262: ...262 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Страница 288: ...288 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Страница 320: ...320 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Страница 348: ...348 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Страница 388: ...388 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Страница 492: ...492 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Страница 586: ...586 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Страница 599: ...The eDirectory Management Toolbox 599 novdocx en 11 July 2008 Click Help for details...
Страница 600: ...600 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Страница 614: ...614 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...