Etc/Krb-Srvtab; Etc/Krb.conf; Example Of /Etc/Krb-Srvtab From The Control Workstation; Example Of /Etc/Krb-Srvtab From A Node - IBM RS/6000 SP Problem Determination Manual

Hide thumbs Also See for RS/6000 SP:
Table of Contents

Advertisement

3.6.4 /etc/krb-srvtab

The server key file, /etc/krb-srvtab, contains the names and private keys of the
local instances of Kerberos-protected services. During the setup of the Control
Workstation or the nodes, the keys for service principals are stored in the
authenticated database (for use by the authentication server) and in the file
/etc/krb-srvtab (for use by the services themselves). So, every node and the
Control Workstation includes an /etc/krb-srvtab file that contains the keys for the
services provided on that host. On the Control Workstation, the hardmon and
rcmd service principals are in this file:
Figure 26. Example of /etc/krb-srvtab from the Control Workstation
On the nodes, the rcmd service principals are in this file:
Figure 27. Example of /etc/krb-srvtab from a Node
Note: Always ensure that the service keys contained in the authentication
database and in the /etc/krb-srvtab files on the nodes match. The
/usr/lpp/ssp/kerberos/etc/ext_srvtab
server key files for each node.

3.6.5 /etc/krb.conf

The SP authentication configuration file, /etc/krb.conf, defines the local
authentication realm and the location of authentication servers for known realms.
The first line contains the name of the local authentication realm. Subsequent
lines specify the authentication server for a realm.
This file is created by the setup_authent script on the primary authentication
server. You may supply your own krb.conf file before running setup_authent if
you want to use a non-default realm name (the default realm name is the
domain portion of the primary authentication server's hostname converted to
uppercase).
Figure 28. Example of a /etc/krb.conf File
78
SP PD Guide
root@sp21cw0 / > klist -srvtab
Server key file:
/etc/krb-srvtab
Service
Instance
------------------------------------------------------
hardmon
sp21tr0
rcmd
sp21tr0
hardmon
sp21cw0
rcmd
sp21cw0
root@sp21n01 / > klist -srvtab
Server key file:
/etc/krb-srvtab
Service
Instance
------------------------------------------------------
rcmd
sp21n01
root@sp21n01 / > cat /etc/krb.conf
SP21CW0
SP21CW0 sp21cw0 admin server
This soft copy for use by IBM employees only.
Realm
Key Version
SP21CW0
1
SP21CW0
1
SP21CW0
1
SP21CW0
1
Realm
Key Version
SP21CW0
1
command can be used to create new

Advertisement

Table of Contents
loading

Table of Contents