C
HAPTER
12:
C
OMMAND
L
INE
I
NTERFACE
147
•
The above 3 machines should be pingable by FQDN. Get the hosts file using
gethostnamefile from the Kerberos menu.
•
Use klist to check the ticket expiration.
Most of the kadmin error messages are associated with ticket expiration
•
Kadmin: -List principal and add missing principal if it doesn’t already exist in the KDC
database.
•
Browser rule : Do not include the REALM part when the browser prompts for principal.
•
Telnet access : Use –x –l and –k option appropriately. Telnet will initially print that
authentication
Key and Definitions:
1.
For KDC, Kadmind, the application server and client machine, refer to : the MIT
Kerberos FAQ [ http://www.cmf.nrl.navy.mil/CCS/people/kenh/kerberos-faq.html ]
2.
FQDN : Fully Qualified Domain Name
Note: Information about setting up KDC kadmind is not in the scope of this document. Use
the references mentioned in this section for this information.
Kerberos Command Example
1) admin > Security > Kerberos > getkrbconfig ip 192.168.52.197
login vijay password vijayv path /home/vijay/krb5.conf
Success
2)
kadmin: addprinc
host/dsx-182.domain.com@REALM
kadmin: addprinc
HTTP/[email protected]
Loginsettings Commands
The
loginsettings
command menu provides access to the commands used to configure the
systemwide login settings. The loginsettings commands are listed in the table below.
Table 62 Loginsettings Commands
C
OMMAND
D
ESCRIPTION
idletimeout
Set systemwide idletimeout.
inactiveloginexpiry
Configure local login expiry time.
invalidloginretries
Configure local login max number of retries.
localauth
Configure local authentication.
lockoutperiod Lockout
period
on invalid login attempt.
singleloginperuser
Restrict to a single login session per user.
strongpassword
Configure strong password rules.
unauthorizedportaccess
Unauthorized (Anonymous) port access.
idletimeout Command
The
idletimeout
command sets or changes the amount of idle time allowed before the system
disconnects the user.
The syntax of the idletimeout command is:
Содержание DOMINION SX -
Страница 1: ...Dominion SX User Guide Release 3 1 Copyright 2007 Raritan Inc DSX 0M E April 2007 255 60 2000 00...
Страница 2: ...This page intentionally left blank...
Страница 18: ...This page intentionally left blank...
Страница 22: ...4 DOMINION SX USER GUIDE This page intentionally left blank...
Страница 44: ...26 DOMINION SX USER GUIDE...
Страница 48: ...30 DOMINION SX USER GUIDE...
Страница 83: ...CHAPTER 8 SECURITY 65 Figure 59 SSL Client Certificate Screen...
Страница 104: ...86 DOMINION SX USER GUIDE...
Страница 170: ...152 DOMINION SX USER GUIDE...
Страница 174: ...156 DOMINION SX USER GUIDE...
Страница 196: ...178 DOMINION SX USER GUIDE Install the Dominion SX Server Certificate section that follows...
Страница 203: ...APPENDIX C CERTIFICATES 185...
Страница 204: ...186 DOMINION SX USER GUIDE...
Страница 212: ...194 DOMINION SX USER GUIDE...
Страница 225: ...APPENDIX F TROUBLESHOOTING 207 255 60 2000 00...