⭐ 欢迎来到虫虫下载站! | 📦 资源下载 📁 资源专辑 ℹ️ 关于我们
⭐ 虫虫下载站

📄 kerberos.8krb

📁 <B>Digital的Unix操作系统VAX 4.2源码</B>
💻 8KRB
字号:
.TH kerberos 8krb.SH Namekerberos \- the kerberos daemon.SH Syntax.B /usr/etc/kerberos[.B \-p \fIpause_seconds\fP] [.B \-a \fImax_age\fP].br[.B \-l \fIlog_file\fP] [.B \-r \fIrealm\fP] [.B \-s] [.B \-n] [.B \-m].SH Description.NXR "Kerberos routines" "kerberos 8"The .PN kerberosdaemon is used by a Kerberos principal, X, to assistit in authenticating its identity to another Kerberos principal Y.In the ULTRIX environment, X would typically be an applicationrunning on one machine while Y would be an application running onanother machine.  Because X and Y run on separate machines, theauthentication of X by Y and Y by X is not an easy task.  If theyran on a single machine, A, the authentication of X could be performedeasily by Y.  All Y need do is ask A for the user ID ofX.  Since Y trusts the local machine, if the user ID of X is the user ID Y expects, then X must be X..PPIf Y were to authenticate Xwhen X runs on a different machine, B, using the same user ID method, then Y would be forced to trust the machine B to providea correct answer.  The security of this method breaks down assoon as any one machine that Y is willing to trust is subvertedby a hostile user.  In addition, it breaks as soon as any machinesthat cannot be trusted by Y are allowed on the physical network towhich A and B are connected.  Hostile users that have controlover these rogue machines can force them to produce messages thatlook as though they come from machine B..PPThe .PN kerberosdaemon serves as a single point of trust in a localarea network (LAN).  The authentication of X toY depends upon the trust that both X and Y have in the .PN kerberosdaemon.X trusts the.PN kerberosdaemon to give Y only enough information toauthenticate itself as Y to X, and Y trusts .PN kerberosto give X onlyenough information to authenticate itself as X to Y.  Y nolonger needs to trust B to authenticate X..PPIf X were to authenticate itself to Y, X would first communicate with the.PN kerberosdaemon in order to obtain a ticket that would allow it to authenticate to Y.  The ticket can be defined as the data thatX needs to authenticate itself to Y.  X passes the ticket to Y, along with other information, to authenticate itself toY.  Y then has the ability to send a message back to X in orderto authenticate its identity to X..PPThere is one .PN kerberosmaster daemon per LAN.  The difference betweena Kerberos master daemon and a Kerberos slave daemon is apparent in theway in which the Kerberos database on the machines on which they run isupdated.  The Kerberos database stores information about Kerberosprincipals.  It stores, for instance, the Data Encryption Standard (DES)encryption keythat is associated with each principal..PPThere is only one Kerberos database per LAN, to which updates to individual principal entriesshould be performed.This is the Kerberos master database.  The .PN kerberosdaemon that runson the machine which stores the Kerberos master database is the.PN kerberosmaster daemon.  All the other Kerberos databases in the LANare periodically updated by .MS kprop 8krband.MS kpropd 8krb ,based upon the data stored in the Kerberos master database.  Themachines that store this type of database run .PN kerberosslavedaemons..PPA \fBrealm\fP is the common name given to a group of principals.  Allprincipals stored in one Kerberos database belong to a single realm,and an individual.PN kerberosdaemon uses only oneKerberos database.So, a .PN kerberosdaemon only allowsone principal in the realm to authenticate another principal in therealm.  Inter-realm authentication is not supported in the ULTRIXversion of Kerberos..SH Options.TP 7.B \-pAllows the user to select the number of seconds that the .PN kerberosdaemon will pause, \fIpause_seconds\fP, after it hasencountered an unrecoverable error, and before it exits.  Thistime interval must be between five minutes (300), and one hour (3600).If neither this option nor the \fB-s\fP option is used, the.PN kerberosdaemon will pause forever before exiting..TP 7.B \-aAllows the user to specify the age in seconds, \fImax_age\fP, abovewhich the Kerberos database should be considered tooold for a Kerberos slave server to use.  The .PN kerberosdaemon determines the age of the Kerberos database bycomparing the lastmodification time of the .PN /var/dss/kerberos/dbase/principal.okfile with the current time.  The .PN principal.okfile is modifiedevery time the database is changed.  Since a Kerberos slaveserver receives its database in whole from the Kerberos master,this option specifies the maximum amount of time allowedbetween database transfers.  The time value must be between onehour (3600) and three days (259200).  If neither this optionnor the \fB-s\fP option is used, the maximum age of the databaseis infinite..TP 7.B \-lAllows the user to select a different file, \fIlog_file\fP, intowhich the.PN kerberosdaemon will place Kerberos log messages.If neither this option nor the \fB-s\fP option is used, the \fIlog_file\fPvalue is set to.PN /var/dss/kerberos/log/kerberos.log ..TP 7.B \-rAllows the user to change the name of the realm, \fIrealm\fP, forwhich the .PN kerberosdaemon will serve information.  If norealm name is specified with the \fB-r\fP option, the .PN kerberosdaemon will server the realm of which the local host isa member..TP 7.B \-sAllows the user to tell the .PN kerberosdaemon to use thedefault values for \fIpause_seconds\fP, \fImax_age\fP, and \fIlog_file\fPof a slave server.  If \fImax_age\fP hasnot been set with the \fB-a\fP option, the \fImax_age\fPvalue is set to the slave server default of one day (86400).If the \fIpause_seconds\fP value has not been set with the \fB-p\fPoption, the \fIpause_seconds\fP value is set to the slaveserver default of 5 minutes (300).  If the \fIlog_file\fP valuehas not been set with the \fB-l\fP option, the \fIlog_file\fP valueis set to the slave server default,.PN /var/dss/kerberos/log/kerberos_slave.log .Use of the \fB-s\fPoption is equivalent to using the following list of optionswith the .PN kerberosdaemon:.EX\-a 86400 \-p 300 \-l /var/dss/kerberos/log/kerberos_slave.log.EE.TP 7.B \-nAllows the user to tell the .PN kerberosdaemon that themaximum age of the Kerberos database should be infinite.This option is only useful if the \fB-s\fP option has beenselected by the user, but the maximum age of thedatabase should not be equal to the slave default (300),but should be infinite.  This option also overrides the \fB-a\fPoption..TP 7.B \-mAllows the user to run the .PN kerberosdaemon in manual mode.This implies that the master key of the Kerberos databasewill be input from .PN stdin .If this option is not used,the master key of the Kerberos database is read from the datafile.PN kstash(8krb) placed in the system..SH See Alsokdb_init(8krb), kdb_util(8krb), kdb_edit(8krb), kdb_destroy(8krb),kerberos(3krb), kprop(8krb) kpropd(8krb)

⌨️ 快捷键说明

复制代码 Ctrl + C
搜索代码 Ctrl + F
全屏模式 F11
切换主题 Ctrl + Shift + D
显示快捷键 ?
增大字号 Ctrl + =
减小字号 Ctrl + -