12.07.2015 Views

eTrust CA-Top Secret Security for z/OS and OS ... - SupportConnect

eTrust CA-Top Secret Security for z/OS and OS ... - SupportConnect

eTrust CA-Top Secret Security for z/OS and OS ... - SupportConnect

SHOW MORE
SHOW LESS
  • No tags were found...

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Mapping of Foreign EnvironmentsREALMNAME—a fully qualified Kerberos trust relationship of the following<strong>for</strong>m:/…/local_realm/krbtgt/<strong>for</strong>eign_realm/…/<strong>for</strong>eign_realm/krbtgt/local_realmwhere the values:local_realm—represents the web-address of the local default realm in theKerberos configuration file<strong>for</strong>eign_realm—represents the web-address of the <strong>for</strong>eign realm in the Kerberosconfiguration file.KERBPASS—a password used to validate the trust relationship.Let us suppose that we wish to establish a trust relationship betweenTRUSTWORTHY.<strong>CA</strong>.COM with MAJESTERIAL.CLIENT.COM <strong>for</strong> which wewill employ the label MAJESTY in the SDT. Locally, we would define thefollowing:TSS ADD(SDT) REALM(majesty)REALMNAME(‘/…/trustworthy.ca.com/krbtgt/majesterial.client.com’)PASSWORD(xylofone)<strong>and</strong>,TSS ADD(SDT) REALM(trustyca)REALMNAME(‘/…/majesterial.client.com/krbtgt/trustworthy.ca.com’)PASSWORD(marimba)In the <strong>for</strong>eign system, a set of parallel definitions is required so that eachconnection in the conversation maintains identical passwords:TSS ADD(SDT) REALM(kingart)REALMNAME(‘/…/trustworthy.ca.com/krbtgt/majesterial.client.com’)PASSWORD(xylofone)<strong>and</strong>,TSS ADD(SDT) REALM(troubador)REALMNAME(‘/…/majesterial.client.com/krbtgt/trustworthy.ca.com’)PASSWORD(marimba)Notice that the REALM oper<strong>and</strong>s are merely labels of convenience, <strong>and</strong> do nothave to match between the two systems. However, the password <strong>for</strong> each trustrelationship must be identical <strong>for</strong> identical REALMNAME specifications.1–88 Cookbook

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!