12.07.2015 Views

eTrust CA-Top Secret Security for z/OS and OS ... - SupportConnect

eTrust CA-Top Secret Security for z/OS and OS ... - SupportConnect

eTrust CA-Top Secret Security for z/OS and OS ... - SupportConnect

SHOW MORE
SHOW LESS
  • No tags were found...

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

KerberosThe comm<strong>and</strong> syntax <strong>for</strong> this definition is given by:TSS ADDTO(SDT) REALM(KERBDFLT) REALMNAME(default_realm) KERBPASS(Kerberos-password)REALM—KERBDFLT (required)REALMNAME—Must be identical to configuration file default_realm.etrust <strong>CA</strong>-<strong>Top</strong> <strong>Secret</strong> has simplified the REALMNAME specification. This isinternally exp<strong>and</strong>ed to the following when used <strong>for</strong> run-time security checks:/…/default_realm/krbtgt/default_realmThe REALMNAME is generally specified in the <strong>for</strong>m of a first orderweb-address. It can be a maximum of 117 characters, but cannot include spaces(x’40’) or the at-sign (x’7F’).Note: Because the relationship between the REALMNAME <strong>and</strong> generatingKerberos tickets <strong>for</strong> principal users is based, in part, on the local REALMNAME,care must be taken when choosing a REALMNAME. Renaming the REALMshould be avoided at all costs during Kerberos operations, since trust relations inflight will cause unpredictable effects.MINTKTLF—Specifies the maximum ticket life in seconds, <strong>and</strong> is representedby a numeric value between 1 <strong>and</strong> 2 147 483 647. Note that 0 is not a valid value.This keyword is only applicable when defining the KERBDFLT realm record. IfMAXTKTLF is specified, DEFTKTLF <strong>and</strong> MINTKTLF must also be specified.DEFTKTLF—Specifies the time intervals (in seconds) that a Kerberos generatedticket will remain active in the realm. If any of these intervals is specified, allmust be specified. If no intervals are specified, tickets are not limited. Validvalues <strong>for</strong> these parameters lie in the range 1 through 2**31-1 (2147483647). Asyou would expect, MAXTKTLF >= DEFTKTLF >= MINTKTLF is en<strong>for</strong>ced.KERBPASS—Specifies a 1-8 character password (alphanumeric) <strong>for</strong> the localrealm. When the same realm name is used as a <strong>for</strong>eign realm in a <strong>for</strong>eignKerberos system, the passwords must be identical. Passwords are case-sensitive<strong>and</strong> are maintained in the case in which they are entered. The KERBPASS bearsno relationship to the password of the SKRBKDC region ACID.Example:TSS ADDTO(SDT) REALM(KERBDFLT) REALMNAME(local.ca.com) MINTKTLF(30)MAXTKTLF(86400) DEFTKTLF(36000) KERBPASS(children)In the above example, the realm name is KERBDFLT, which identifies this recordas the default realm record. The Kerberos realm name is local.ca.com. Thiscorresponds to a the following fully qualified Kerberos security name which<strong>eTrust</strong> <strong>CA</strong>-<strong>Top</strong> <strong>Secret</strong> will <strong>for</strong>mat automatically./…/local.ca.com/kerbtgt/local.ca.comImplementing <strong>eTrust</strong> <strong>CA</strong>-<strong>Top</strong> <strong>Secret</strong> in a z/<strong>OS</strong> or <strong>OS</strong>/390 Environment 1–83

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!