Files; Home/.Klogin; Tmp/Tkt<Uid - IBM RS/6000 SP Problem Determination Manual

Hide thumbs Also See for RS/6000 SP:
Table of Contents

Advertisement

This soft copy for use by IBM employees only.
The Kerberos database contains the name of the authentication realm and all
the principals' names and their keys. The database files can be converted to an
ASCII file by the script /usr/lpp/ssp/kerberos/etc/ kdb_util dump. Use kdb_util
load to convert the ASCII file back to binary.

3.6 Files

The files described in this section are used by Kerberos.
3.6.1 /.k
The master key cache file contains the DES key derived from the master
password. The master password is supplied initially by the administrator when
the primary authentication server is created. The corresponding DES key is
saved in /.k using the
daemon and the database utility commands read the master key from this file
instead of prompting for the master password. If the /.k file is deleted, these
commands will still execute successfully; however, the user will be prompted for
the master password. The kadmind daemon cannot be successfully respawned
if the /.k file is removed. The
file. The user will, however, be prompted for the master password.
Note: Without a /.k file, the Kerberos server cannot be started automatically
during an unattended reboot of the master server.

3.6.2 $HOME/.klogin

The .klogin file contains a list of principals (name.instance@realm). This file
specifies the remote principals authorized to invoke commands on the local user
account. For example, the root user's .klogin file contains a list of principals that
are authorized to invoke processes as the root user with the Kerberos remote
commands (rsh and rcp).
Notes:
1. Only add principals to root' s .klogin file on the Control Workstation.
2. Do not delete any principals which already exist.
3. The root user must always have a .klogin file, and the root user must be
4. The root .klogin is distributed to the nodes during installation or
3.6.3 /tmp/tkt<uid>
The tkt<uid> file contains the tickets owned by a client (user). The first ticket
in the file is the ticket-granting ticket. The ticket cache file is created when the
user executes the
be used to change the default location and name for the ticket cache file. The
klist command displays the contents of the current cache file. The kdestroy
command deletes the current cache file.
/usr/lpp/ssp/kerberos/etc/kstash
listed in the file.
customization. Use dsh to update the nodes' .klogin file after changing it on
the Control Workstation.
kinit
command. The KRBTKFILE environment variable may
kstash
command can be used to recreate the /.k
command. The kadmind
77
Chapter 3. K e r b e r o s

Advertisement

Table of Contents
loading

Table of Contents