Cisco WS-X6066-SLB-APC - Content Switching Module Software Manual page 448

Catalyst 6000 series software configuration guide
Hide thumbs Also See for WS-X6066-SLB-APC - Content Switching Module:
Table of Contents

Advertisement

Configuring Authentication
Defining and Clearing a Private DES Key
You can define a private DES key for the switch. The private DES key can be used to encrypt the secret
key that the switch shares with the KDC so that when the show kerberos command is executed, the
secret key is not displayed in clear text. The key length should be eight characters or less.
To define a DES key, perform this task in privileged mode:
Task
Define a DES key for the switch.
This example shows how to define a DES key and verify the configuration:
kerberos> (enable) set key config-key abcd
Kerberos config key set to abcd
kerberos> (enable) show kerberos
Kerberos Local Realm:CISCO.COM
Kerberos server entries:
Realm:CISCO.COM,
Realm:CISCO.COM,
Kerberos Domain<->Realm entries:
Domain:cisco.com,
Kerberos Clients Mandatory
Kerberos Credentials Forwarding Disabled
Kerberos Pre Authentication Method set to Encrypted Unix Time Stamp
Kerberos config key:abcd
Kerberos SRVTAB Entries
Srvtab Entry 1:host/aspen-niners.cisco.edu@CISCO.EDU 0 933974942 1 1 8 12151><88?=>>3>11
kerberos> (enable)
To clear the DES key, perform this task in privileged mode:
Task
Clear a DES key from the switch.
This example shows how to clear the DES key:
Console> (enable) clear key config-key
Kerberos config key cleared
Console> (enable)
Encrypting a Telnet Session
After a user authenticates to the switch using Kerberos and wants to Telnet to another switch or host,
whether or not this will be a Kerberized Telnet depends on the authentication method that the Telnet
server uses. If the Telnet server uses Kerberos for authentication, you can choose to have all the
application data packets encrypted for the duration of the Telnet session. To encrypt the Telnet session,
select the encrypt kerberos option in the telnet command.
Catalyst 6000 Family Software Configuration Guide—Releases 6.3 and 6.4
21-38
Server:170.20.2.1,
Port:750
Server:172.20.2.1,
Port:750
Realm:CISCO.COM
Chapter 21
Configuring Switch Access Using AAA
Command
set key config-key string
Command
clear key config-key string
78-13315-02

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents