
When you make tape backups of the Kerberos database (
/var/lib/kerberos/
krb5kdc/principal
), do not back up the stash file (which is in
/var/lib/
kerberos/krb5kdc/.k5.EXAMPLE.COM
). Otherwise, everyone able to read the
tape could also decrypt the database. Therefore, it is also a good idea to keep a copy of
the pass phrase in a safe or some other secure location, because you need it to restore
your database from backup tape after a crash.
To create the stash file and the database, run:
$> kdb5_util create -r EXAMPLE.COM -s
Initializing database '/var/lib/kerberos/krb5kdc/principal' for realm
'EXAMPLE.COM',
master key name 'K/[email protected]'
You will be prompted for the database Master Password.
It is important that you NOT FORGET this password.
Enter KDC database master key: <= Type the master password.
Re-enter KDC database master key to verify: <= Type it again.
$>
To verify that it did anything, use the list command:
$>kadmin.local
kadmin> listprincs
kadmin/[email protected]
kadmin/[email protected]
krbtgt/[email protected]
This shows that there are now a number of principals in the database. All of these are
for internal use by Kerberos.
46.4.3 Creating a Principal
Next, create two Kerberos principals for yourself: one normal principal for your everyday
work and one for administrative tasks relating to Kerberos. Assuming your login name
is
newbie
, proceed as follows:
kadmin.local
kadmin> ank newbie
[email protected]'s Password: <type password here>
Verifying password: <re-type password here>
Installing and Administering Kerberos
845
Содержание LINUX ENTERPRISE SERVER 10 - INSTALLATION AND ADMINISTRATION 11-05-2007
Страница 1: ...SUSE Linux Enterprise Server www novell com 10 May 11 2007 Installation and Administration...
Страница 14: ......
Страница 19: ...Part I Deployment...
Страница 20: ......
Страница 60: ......
Страница 128: ......
Страница 243: ...Part II Administration...
Страница 244: ......
Страница 274: ......
Страница 312: ......
Страница 348: ......
Страница 380: ......
Страница 381: ...Part III System...
Страница 382: ......
Страница 438: ......
Страница 452: ......
Страница 478: ......
Страница 486: ......
Страница 498: ......
Страница 512: ......
Страница 558: ......
Страница 559: ...Part IV Services...
Страница 560: ......
Страница 652: ......
Страница 670: ......
Страница 742: ......
Страница 754: ......
Страница 796: ......
Страница 817: ...Part V Security...
Страница 818: ......
Страница 858: ......
Страница 886: ......
Страница 910: ......
Страница 911: ...Part VI Troubleshooting...
Страница 912: ......
Страница 924: ......