User Manual
Command Reference Security Commands
12-156
12.11.6 Set/Define Authentication Kerberos
Specifies that a Kerberos database will be used for authentication. Specific Kerberos options are explained
in detail in the Kerberos section on page 11-11.
Restrictions Requires privileged user status.
Parameters Primary
Specifies the first database or server to be checked. A specific address may be
set with the address parameter, or the None parameter may be used to indicate
that the database or file will not be used.
If the SCS fails to authenticate the user using the primary database or server
(due to network failure, server failure, missing or incorrect username/
password), the secondary database or server (discussed below) will be
checked. If the user is authenticated at any point, the search process will stop
and the login will be permitted.
If the user cannot be authenticated using the secondary database or server, the
database or server with the next precedence level will be checked. If all
precedence levels fail to authenticate the user, the user is prevented from
logging in.
Secondary
Sets the secondary database or server to be checked. A specific address may be
set with the address parameter, or the None parameter may be used to indicate
that the server will not be used.
SET
DEFINE
AUTHENTICATION KERBEROS
PRIMARY
address
NONE
SECONDARY
address
NONE
PRECEDENCE prec_num
PRINCIPLE string
INSTANCE string
AUTHENTICATOR password
ENCRYPTION
AFS
MIT
KVNO kvno_num
MAXTRIES tries
PORT PortNum
REALM string
TIMEOUT num