![Novell LINUX ENTERPRISE DESKTOP 11 Скачать руководство пользователя страница 107](http://html1.mh-extra.com/html/novell/linux-enterprise-desktop-11/linux-enterprise-desktop-11_manual_1711827107.webp)
6
Start the Kerberos Daemon
Once the KDC software is installed and properly
configured, start the Kerberos daemon to provide Kerberos service for your realm.
Refer to
Section “Starting the KDC”
(page 94) for details.
7
Create a Principal for Yourself
You need a principal for yourself. Refer to
Section “Creating a Principal”
(page 94) for details.
Setting Up the Database
Your next step is to initialize the database where Kerberos keeps all information about
principals. Set up the database master key, which is used to protect the database from
accidental disclosure, in particular when it is backed up to a tape. The master key is
derived from a pass phrase and is stored in a file called the stash file. This is so you do
not need to enter the password every time the KDC is restarted. Make sure that you
choose a good pass phrase, such as a sentence from a book opened to a random page.
When you make tape backups of the Kerberos database (
/var/lib/kerberos/
krb5kdc/principal
), do not back up the stash file (which is in
/var/lib/
kerberos/krb5kdc/.k5.EXAMPLE.COM
). Otherwise, everyone able to read the
tape could also decrypt the database. Therefore, it is also a good idea to keep a copy of
the pass phrase in a safe or some other secure location, because you need it to restore
your database from backup tape after a crash.
To create the stash file and the database, run:
$> kdb5_util create -r EXAMPLE.COM -s
Initializing database '/var/lib/kerberos/krb5kdc/principal' for realm
'EXAMPLE.COM',
master key name 'K/[email protected]'
You will be prompted for the database Master Password.
It is important that you NOT FORGET this password.
Enter KDC database master key:
<= Type the master password.
Re-enter KDC database master key to verify:
<= Type it again.
$>
To verify that it did anything, use the list command:
$>kadmin.local
kadmin> listprincs
K/[email protected]
kadmin/[email protected]
kadmin/[email protected]
krbtgt/[email protected]
Network Authentication with Kerberos
93
Содержание LINUX ENTERPRISE DESKTOP 11
Страница 1: ...SUSE Linux Enterprise Server www novell com 11 March 17 2009 Security Guide...
Страница 9: ...32 7 Managing Audit Event Records Using Keys 433 33 Useful Resources 435...
Страница 10: ......
Страница 29: ...Part I Authentication...
Страница 30: ......
Страница 55: ...Figure 4 2 YaST LDAP Server Configuration LDAP A Directory Service 41...
Страница 126: ......
Страница 127: ...Part II Local Security...
Страница 128: ......
Страница 158: ......
Страница 173: ...Part III Network Security...
Страница 174: ......
Страница 194: ......
Страница 197: ...Figure 16 2 Scenario 2 Figure 16 3 Scenario 3 Configuring VPN Server 183...
Страница 210: ......
Страница 228: ......
Страница 229: ...Part IV Confining Privileges with Novell AppArmor...
Страница 230: ......
Страница 274: ......
Страница 300: ......
Страница 328: ......
Страница 340: ......
Страница 342: ......
Страница 386: ......
Страница 387: ...Part V The Linux Audit Framework...
Страница 388: ......