Kerberos Client Version C.1.3.5.
© Copyright 2010 Hewlett-Packard Development Company, L.P Legal Notices Copyright 2010 Hewlett-Packard Development Company, L.P. Confidential computer software. Valid license from HP required for possession, use or copying. Consistent with FAR 12.211 and 12.212, Commercial Computer Software, Computer Software Documentation, and Technical Data for Commercial Items are licensed to the U.S. Government under vendor's standard commercial license.
Table of Contents 1 Kerberos Client C.1.3.5.10 release notes......................................................................5 Announcement.......................................................................................................................................5 What is new in this version....................................................................................................................6 Features supported from Kerberos Client Version 1.3.5.................................
List of Tables 1-1 1-2 1-3 1-4 1-5 1-6 4 Kerberos Client PA-RISC and Itanium libraries.............................................................................5 Kerberos Client utilities...................................................................................................................5 Encryption types supported by Kerberos Client C.1.3.5.10............................................................6 System requirements for installing Kerberos Client C.1.3.5.10........................
1 Kerberos Client C.1.3.5.10 release notes Information in this document applies to Kerberos Client C.1.3.5.10 for HP-UX 11i v1. Announcement HP-UX provides Kerberos Client software including libraries, header files, and utilities for implementing secured client/server applications in either 32-bit or 64-bit development environments. Kerberos Client (KRB5-Client) is a part of the core HP-UX 11i v1 operating system. Table 1-1 lists the libraries that Kerberos Client supports on HP-UX 11i v1.
Table 1-2 Kerberos Client utilities (continued) Utility Function /usr/sbin/ktutil -> /opt/krb5client/sbin/ ktutil Maintains the Kerberos keytab file /usr/bin/kdestroy -> /opt/krb5client/bin/ kdestroy Destroys the user’s active Kerberos tickets Kerberos Client includes the following header files: • /usr/include/profile.h -> /opt/krb5client/include/profile.h • /usr/include/krb5.h -> /opt/krb5client/include/krb5.h • /usr/include/com_err.h -> /opt/krb5client/include/com_err.h • /usr/include/krb5/gssapi.
Table 1-3 Encryption types supported by Kerberos Client C.1.3.5.10 (continued) Encryption Type Description des-cbc-raw DES cbc mode raw des3-cbc-raw Triple DES cbc mode raw des3-cbc-sha1 Triple DES cbc mode with HMAC/sha1 des3-hmac-sha1 Triple DES cbc mode with HMAC/sha1 This encryption type is an alias to the des3-cbc-sha1 encryption type. If you specify des3-hmac-sha1 in the configuration file, then it’s behavior is the same as des3-cbc-sha1.
kernel threads. HP has fixed PAM Kerberos v 1.24 and Kerberos Client C.1.3.5.06. However, you must also install PHSS_28871 to resolve this defect. NOTE: You must have PAM Kerberos v1.24, Kerberos Client C.1.3.5.06, and patch PHSS_28871 installed on your system. Known limitation Kerberos Client Version C.1.3.5.10 libraries are not thread safe. Installation requirements for Kerberos Client C.1.3.5.10 on HP-UX 11i v1 This section discusses the prerequisites for installing Kerberos Client version C.1.3.5.
Table 1-6 Additional patches for Kerberos Client on HP-UX 11i v1 Patch/Product Description Included in the KRB5CLIENT Bundle? Patch PHCO_23578 Software Distributor Cumulative patch Yes PHSS_29487 GSS-API Version 1.0 cumulative Yes patch to enable 64-bit functionality of GSS-API with Kerberos backend PHCO_25568 Patch to enable users to use files to resolve host entries. Install the libnss_files cumulative patch PHCO_25568 on your system and add the following line to the /etc/ nsswitch.
7. 8. The swinstall window is displayed. Select Mark for Install in the Action menu to select the bundle and the patches that you want to install. Select Install in the Action menu. The Install Analysis window is displayed. 9. Select OK when Status displays a Ready message. The Install window is displayed and the Kerberos Client installation starts. 10. Select Done when the Status displays a Completed message. 11. Select File→Exit to exit from the swinstall window.