User guide
Security Commands
208
DiagnosticTips:
• UsethenamecommandinthenetworkmenutosettheFQDNfor
DSX.
• DisableHTTPredirectfromtheservicesmenu.
• Synchronizethetimeoftheclientmachine.DSXmachine,KDCand
kadmindmachinesusingtimemenuandntpoption.
• Theabove3machinesshouldbepi
ngablebyFQD
N.Getthehostsfile
usinggethostnamefilefromtheKerberosmenu.
• Useklisttochecktheticketexpiration.
Mostofthekadminerrormessagesareassociatedwithticket
expiration
• Kadmin:‐Listprincipalandaddmissingprincipalifitdoesnʹt
alreadyexistintheKDCdatabase.
• Browserrule:Donotincl
u
detheREALMpartwhenthebrowser
promptsforprincipal.
• Telnetaccess:Use‐x‐land‐koptionappropriately.Telnetwill
initiallyprintthatauthentication
KeyandDefinitions:
1. ForKDC,Kadmind,theapplicationserverandclientmachine,refer
to:theMITKe
rberosFAQ
[http://www.cmf.nrl.nav
y.mil/CCS/people/kenh/kerberos‐faq.html]
2. FQDN:FullyQualifiedDomainName
Note:InformationaboutsettingupKDCkadmindisnotinthescopeof
thisdocument.Usethereferencesmentionedinthissectionforthis
information.
Kerberos Command Example
1. admin>Security>Kerberos>getkrbconfigip192.168.52.197login
vijaypasswordvijayvpath/home/vijay/krb5.conf
Success
2. kadmin:addprinchost/dsx‐182.domain.com@REALM
kadmin:addprincHTTP/dsx‐182.raritan.com@RARITAN.COM
Loginsettings Commands
Theloginsettingscommandmenuprovidesaccesstothecommandsused
toconfigurethesystemwideloginsettings.Theloginsettingscommands
arelistedinthetablebelow.