Specifying A Kerberos Server - Cisco WS-C4003 - Catalyst 4000 Chassis Switch Software Configuration Manual

Software guide
Table of Contents

Advertisement

Configuring Authentication
To configure the switch to authenticate to the KDC in a specified Kerberos realm, perform this task in
privileged mode:
Task
Define the default realm for the switch.
Note
Make sure that the realm is entered in uppercase letters. Kerberos will not authenticate users if the realm
is entered in lowercase letters.
This example shows how to define a local-realm and how to verify the configuration:
Console> (enable) set kerberos local-realm CISCO.COM
Kerberos local realm for this switch set to CISCO.COM.
Console> (enable) show kerberos
Kerberos Local Realm:CISCO.COM
Kerberos server entries:
Realm:CISCO.COM,
Kerberos Domain<->Realm entries:
Domain:cisco.com,
Kerberos Clients NOT Mandatory
Kerberos Credentials Forwarding Enabled
Kerberos Pre Authentication Method set to None
Kerberos config key:
Kerberos SRVTAB Entries
Srvtab Entry 1:host/niners.cisco.com@CISCO.COM 0 932423923 1 1 8 01;;8>00>50;0=0=0
Console> (enable)

Specifying a Kerberos Server

You can specify to the switch which KDC to use in a specific Kerberos realm. Optionally, you can also
specify the port number which the KDC is monitoring. The Kerberos server information you enter is
maintained in a table with one entry for each Kerberos realm. The maximum number of entries in the
table is 100.
To specify the Kerberos server, perform this task in privileged mode:
Task
Step 1
Specify which KDC to use in a given Kerberos
realm. Optionally, enter the port number the KDC
is monitoring. (The default port number is 750.)
Step 2
Clear the Kerberos server entry.
Software Configuration Guide—Catalyst 4000 Family, Catalyst 2948G, Catalyst 2980G, Releases 6.3 and 6.4
27-32
Server:187.0.2.1,
Port:750
Realm:CISCO.COM
Chapter 27
Configuring Switch Access Using AAA
Command
set kerberos local-realm kerberos-realm
Command
set kerberos server kerberos-realm {hostname |
ip-address} [port-number]
clear kerberos server kerberos-realm {hostname
| ip-address} [port-number]
78-12647-02

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

Catalyst 4000 seriesCatalyst 2948gCatalyst 2980g

Table of Contents