DCE and kadmin
Douglas E. Engert
deengert at anl.gov
Fri Jan 10 10:23:40 EST 2003
It has been a long time since I used DCE, but you may want to look at
ftp://achilles.ctd.anl.gov/pub/kerberos.v5/anldce.notes and k5dce.20010824.tar
One of the mods was to run a modified kadmind5 on the DCE security server.
It would then issued dcecp commands. We only did the password change. But
a similiar approach could be used for adding a principal.
You can also use the DCE commands to create the keytab on a DCE manchine,
then copy them using the kerberized rcp for example.
Kenneth Stephen wrote:
>
> Hi,
>
> I am attempting to get MIT Kerberos kerberized servers to work in
> a Kerberos realm defined by (IBM) DCE security servers. DCE doesnt use
> kadmind and so using kadmin to add keytab files and other things are not
> possible. So I need to manually execute the various steps that kadmin
> performs under the covers. As far as I know, these steps are :
>
> 1. Create a host principal for the kerberized server machine in the KDC
> (DCE) registry
> 2. Create a keytab for the host principal on the KDC server
> 3. Copy over same keytab to the machine where the kerberized server will
> run.
>
> Is there anything else that I'm missing out that needs to be done?
>
> Thanks,
> Kenneth
>
> ________________________________________________
> Kerberos mailing list Kerberos at mit.edu
> http://mailman.mit.edu/mailman/listinfo/kerberos
--
Douglas E. Engert <DEEngert at anl.gov>
Argonne National Laboratory
9700 South Cass Avenue
Argonne, Illinois 60439
(630) 252-5444
More information about the Kerberos
mailing list