12.07.2015 Views

eTrust CA-Top Secret Security for z/OS and OS ... - SupportConnect

eTrust CA-Top Secret Security for z/OS and OS ... - SupportConnect

eTrust CA-Top Secret Security for z/OS and OS ... - SupportConnect

SHOW MORE
SHOW LESS
  • No tags were found...

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

KerberosYou will also want to be able to write to the STDOUT <strong>and</strong> STDERR files specifiedin your file. In the Kerberos configuration file, the variablesEUV_SVC_STDOUT_FILENAMEEUV_SVC_STDERR_FILENAMEwill contain the file names required. The following permissions will allow allaccess to the STDERR <strong>and</strong> STDOUT files suppled by default:TSS PER(SKRBKDC) HFSSEC(/VAR.SKRB.LOGS.) ACC(ALL)To allow the server to read <strong>and</strong> write credentials, use the following comm<strong>and</strong>s:TSS PER(SKRBKDC) HFSSEC(/VAR.SKRB.CREDS) ACC(ALL)After you have defined the ACID <strong>and</strong> provided proper access, you may add theprocedure to the STC using the following comm<strong>and</strong>:TSS ADD(STC) PROCNAME(SKRBKDC) ACID(SKRBKDC)Customizing your Local EnvironmentThe default_realm specification is also known as the “local” realm. The otherrealms defined in the configuration are known as “<strong>for</strong>eign” realms. Realms aredefined in the SDT.Users defined to Kerberos are not defined in the configuration file, but must bedefined entirely through the <strong>Security</strong> File. Users defined in the local realm areknown as “local” principals. Only local principals are allowed to initiateKerberos comm<strong>and</strong>s from the local Unix Systems Services. Users defined in a<strong>for</strong>eign realm are mapped in the SDT with a surrogate user in the local realm.We will see how the security environment must be customized to interact withKerberos.Defining Your Local RealmYou must define to the <strong>Security</strong> File the REALMs defined to your Kerberosconfiguration file./etc/skrb/krb5.confThe local realm is specified in your default_realm parameter. The local REALMis always named KERBDFLT <strong>and</strong> must be defined be<strong>for</strong>e the local principals aredefined.1–82 Cookbook

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!