Specifications

Managing Access Server Security
23-10
Username> smith.su@finance.acme.com
Password> (not echoed)
Local - 450 - Attempting to authenticate user:smith.su@finance.acme.com
Local - 451 - Authentication successful
Local>
Example: Authentication Using the First Portion of the User Name
If a default realm is configured, you have to enter only the first portion of the user
name as shown in the following example:
Username> smith
Password> (not echoed)
Local - 450 - Attempting to authenticate user: smith@finance.acme.com
Local - 451 - Authentication successful
Local>
Changing a User Name and Password
Once the network manager has set up the access server, users can change their
own passwords on the master KDC for their realm.
Example: Sample Kerberos User Authentication Session
The following example shows a sample session for changing a password. The
way that message 468 wraps may appear differently on your terminal screen.
Local> kpasswd
Username> smith
Old password> oldpassword (not echoed)
New password> newpassword (not echoed)
Verification> newpassword (not echoed)
Local -468- Attempting to change Kerberos password for user smith@finance.acme.com
Local -469- Kerberos password has been changed
Local>
Alternative Password Command
Instead of the KPASSWD command, you can also use the DEFINE KERBEROS
PASSWORD COMMAND as described in the Cabletron Network Access Software
Command Reference guide.
User Authentication Counters
This section describes the user authentication counters. These counters display
information that is useful for detecting problems.