Kerberos Client Version E.1.6.2.
© Copyright 2010 Hewlett-Packard Development Company, L.P Legal Notices Copyright 2010 Hewlett-Packard Development Company, L.P. Confidential computer software. Valid license from HP required for possession, use or copying. Consistent with FAR 12.211 and 12.212, Commercial Computer Software, Computer Software Documentation, and Technical Data for Commercial Items are licensed to the U.S. Government under vendor's standard commercial license.
Table of Contents 1 Kerberos Client E.1.6.2.07 Release Notes....................................................................5 Announcement.......................................................................................................................................5 Encryption Types Supported by Kerberos Client.............................................................................8 What Is New in This Version..................................................................................
List of Tables 1-1 1-2 1-3 1-4 4 Kerberos Client PA-RISC and Itanium Libraries............................................................................5 Kerberos Client Utilities..................................................................................................................8 Encryption Types supported by Kerberos Client E.1.6.2.07............................................................8 System Requirements for Installing Kerberos Client E.1.6.2.07..................................
1 Kerberos Client E.1.6.2.07 Release Notes Information in this document applies to the Web release of Kerberos Client E.1.6.2.07 for HP-UX 11i v3. Announcement Kerberos Client (krb5client) is a Web upgrade for KRB5-Client. KRB5-Client is a part of the core HP-UX 11i v3 operating system. HP-UX provides Kerberos Client software including libraries, header files, and utilities for implementing secured client/server applications in either 32-bit or 64-bit development environments.
Table 1-1 Kerberos Client PA-RISC and Itanium Libraries (continued) Architecture Library Name / Location Functionality PA-RISC 32–bit • /usr/lib/libk5crypto.sl -> /usr/lib/ libk5crypto.1 • /usr/lib/libk5crypto.1 -> /opt/krb5client/ lib/libk5crypto.1 64–bit • /usr/lib/pa20_64/libk5crypto.sl -> /usr/lib/ pa20_64/libk5crypto.1 • /usr/lib/pa20_64/libk5crypto.1 -> /opt/ krb5client/lib/pa20_64/libk5crypto.
Table 1-1 Kerberos Client PA-RISC and Itanium Libraries (continued) Architecture Library Name / Location Functionality Itanium 32–bit • /usr/lib/hpux32/libkrb5.so -> /usr/lib/ hpux32/libkrb5.so.1 • /usr/lib/hpux32/ libkrb5.so.1 -> /opt/ krb5client/lib/hpux32/libkrb5.so.1 64–bit • /usr/lib/hpux64/libkrb5.so -> /usr/lib/ hpux64/libkrb5.so.1 • /usr/lib/hpux64/libkrb5.so.1 -> /opt/ krb5client/lib/hpux64/libkrb5.so.1 Authenticate users, verify tickets, create authenticator, and manage the context.
Table 1-2 Kerberos Client Utilities Utility Function /usr/bin/kinit ->/opt/krb5client/bin/kinit 1 Obtains and caches the Kerberos ticket-granting ticket /usr/bin/klist -> /opt/krb5client/bin/klist Lists cached Kerberos tickets /usr/bin/kvno -> /opt/krb5client/bin/kvno Prints key version numbers of Kerberos principals /usr/bin/kpasswd -> /opt/krb5client/bin/ kpasswd Changes a user’s Kerberos password /usr/sbin/ktutil -> /opt/krb5client/sbin/ ktutil Maintains the Kerberos keytab file /usr/bin/kdes
Table 1-3 Encryption Types supported by Kerberos Client E.1.6.2.07 (continued) Encryption Type Description arcfour-hmac ArcFour with HMAC/md5 rc4-hmac ArcFour with HMAC/md5 This encryption type is an alias to the arcfour-hmac encryption type. If you specify rc4-hmac in the configuration file, then it’s behavior is the same as arcfour-hmac. arcfour-hmac-md5 ArcFour with HMAC/md5 This encryption type is an alias to the arcfour-hmac encryption type.
Kerberos Client version E.1.6.2.07 also supports the following features from Kerberos Client version 1.3.5: • SASL/GSS-API bind to Netscape Directory Server used to fail when SSL was enabled • Support for powerful cryptographic algorithms This version of Kerberos Client software supports 3DES, AES, and RC4 • Support for IPv6 IPv6 support is enabled on this version of Kerberos Client software • Support for TCP Kerberos Client libraries can now use TCP to connect to the Key Distribution Center (KDC).
Table 1-4 System Requirements for Installing Kerberos Client E.1.6.2.07 (continued) Component Requirement Disk space requirement for the complete KRB5CLIENT bundle 36 MB Software availability in native languages English only Patch Requirements Patch PHSS_40655 is required for Kerberos Client E.1.6.2.07. Installing Kerberos Client E.1.6.2.07 To install Kerberos Client E.1.6.2.07, complete the following steps: 1. 2. 3. 4. 5. Log in as superuser.
QXCR1000999089 Defect Description: NFS is not compatible with Kerberos Client Version 1.6.2 and later. Resolution: This issue is resolved. Related Documentation For more information about Kerberos Client, see Configuration Guide for Kerberos Client Products on HP-UX (5991-7718), at: http://docs.hp.com/en/internet.html#Kerberos. 12 Kerberos Client E.1.6.2.