data:image/s3,"s3://crabby-images/32e34/32e3411831802147e328b8008e0508bbb16f5749" alt="Novell LINUX ENTERPRISE DESKTOP 11 Скачать руководство пользователя страница 117"
Services such the SSH daemon read this key and use it to obtain new tickets automati-
cally when needed. The default keytab file resides in
/etc/krb5.keytab
.
To create a host service principal for
jupiter.example.com
enter the following
commands during your kadmin session:
kadmin -p newbie/admin
Authenticating as principal newbie/[email protected] with password.
Password for newbie/[email protected]:
kadmin:
addprinc -randkey host/jupiter.example.com
WARNING: no policy specified for host/[email protected];
defaulting to no policy
Principal "host/[email protected]" created.
Instead of setting a password for the new principal, the
-randkey
flag tells
kadmin
to generate a random key. This is used here because no user interaction is wanted for
this principal. It is a server account for the machine.
Finally, extract the key and store it in the local keytab file
/etc/krb5.keytab
.
This file is owned by the superuser, so you must be
root
to execute the next command
in the kadmin shell:
kadmin:
ktadd host/jupiter.example.com
Entry for principal host/jupiter.example.com with kvno 3, encryption type
Triple
DES cbc mode with HMAC/sha1 added to keytab WRFILE:/etc/krb5.keytab.
Entry for principal host/jupiter.example.com with kvno 3, encryption type DES
cbc mode with CRC-32 added to keytab WRFILE:/etc/krb5.keytab.
kadmin:
When completed, make sure that you destroy the admin ticket obtained with kinit above
with
kdestroy
.
6.4.9 Enabling PAM Support for Kerberos
SUSE® Linux Enterprise Server comes with a PAM module named
pam_krb5
, which
supports Kerberos login and password update. This module can be used by applications,
such as console login, su, and graphical login applications like KDM, where the user
presents a password and would like the authenticating application to obtain an initial
Kerberos ticket on his behalf. To configure PAM support for Kerberos, use the following
command:
pam-config --add --krb5
Network Authentication with Kerberos
103
Содержание LINUX ENTERPRISE DESKTOP 11
Страница 1: ...SUSE Linux Enterprise Server www novell com 11 March 17 2009 Security Guide...
Страница 9: ...32 7 Managing Audit Event Records Using Keys 433 33 Useful Resources 435...
Страница 10: ......
Страница 29: ...Part I Authentication...
Страница 30: ......
Страница 55: ...Figure 4 2 YaST LDAP Server Configuration LDAP A Directory Service 41...
Страница 126: ......
Страница 127: ...Part II Local Security...
Страница 128: ......
Страница 158: ......
Страница 173: ...Part III Network Security...
Страница 174: ......
Страница 194: ......
Страница 197: ...Figure 16 2 Scenario 2 Figure 16 3 Scenario 3 Configuring VPN Server 183...
Страница 210: ......
Страница 228: ......
Страница 229: ...Part IV Confining Privileges with Novell AppArmor...
Страница 230: ......
Страница 274: ......
Страница 300: ......
Страница 328: ......
Страница 340: ......
Страница 342: ......
Страница 386: ......
Страница 387: ...Part V The Linux Audit Framework...
Страница 388: ......