Sun Enterprise Authentication Mechanism 1.0.1 Guide
    
A
 
 -a option to Kerberized commands ( Index Term Link )
 
 access
  getting to server, with SEAM ( Index Term Link )
  granting to your account ( Index Term Link ) ( Index Term Link )
  obtaining for a specific service ( Index Term Link )
  restricting for KDC servers ( Index Term Link )
 
 access, granting to your account ( Index Term Link )
 
 Access Control List
  See ACL
 
 access control list
  See ACL
 
 ACL ( Index Term Link ) ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
 
 adding administration principals ( Index Term Link )
 
 adding service principal to keytab file ( Index Term Link )
 
 admin_server ( Index Term Link )
 
 administering
  adding service principal to keytab file ( Index Term Link )
  allowable operations ( Index Term Link ) ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
  creating new policy ( Index Term Link ) ( Index Term Link )
  creating new principal ( Index Term Link )
  deleting policies ( Index Term Link )
  deleting principal ( Index Term Link )
  keytab file with ktremove command ( Index Term Link )
  keytab file with ktutil command ( Index Term Link )
  keytabs ( Index Term Link )
  modifying a principal ( Index Term Link )
  modifying policies ( Index Term Link )
  policies ( Index Term Link )
  principals ( Index Term Link )
  principals and policies ( Index Term Link )
  removing service principal from keytab file ( Index Term Link )
  setting up principal defaults ( Index Term Link )
  viewing list of policies ( Index Term Link )
  viewing list of principals ( Index Term Link )
  viewing policy attributes ( Index Term Link )
  viewing principal attributes ( Index Term Link )
  viewing sublist of principals ( Index Term Link )
 
 administering keytab files ( Index Term Link )
 
 application server
  configuring ( Index Term Link )
  definition ( Index Term Link ) ( Index Term Link )
 
 authentication ( Index Term Link )
  configuring cross-realm ( Index Term Link )
  definition ( Index Term Link )
  disabling with -X option ( Index Term Link )
  overview of Kerberos ( Index Term Link )
  root ( Index Term Link )
  terminology ( Index Term Link )
 
 authenticator ( Index Term Link )
  definition ( Index Term Link ) ( Index Term Link )
 
 authorization ( Index Term Link )
 
 automatic login ( Index Term Link )
  disabling ( Index Term Link )
 
 automating principal creation ( Index Term Link )
    
B
 
 back-end mechanism ( Index Term Link )
 
 backing up the Kerberos database ( Index Term Link )
 
 backup
  Kerberos database ( Index Term Link )
  slave KDC ( Index Term Link )
    
C
 
 cache, credential ( Index Term Link )
 
 Cerberus
  See Kerberos
 
 changepw principal ( Index Term Link )
 
 changing your password ( Index Term Link )
  with kpasswd command ( Index Term Link )
  with passwd command ( Index Term Link )
 
 choosing your password ( Index Term Link )
 
 clear protection level ( Index Term Link )
 
 client ( Index Term Link )
  configuring ( Index Term Link )
  definition ( Index Term Link )
  planning for names ( Index Term Link )
 
 client principal, definition ( Index Term Link )
 
 clock
  skew ( Index Term Link )
  synchronization ( Index Term Link )
  synchronizing ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
 
 clock skew ( Index Term Link ) ( Index Term Link )
  definition ( Index Term Link )
 
 clock synchronization ( Index Term Link )
 
 command
  ftp ( Index Term Link )
  options to ( Index Term Link )
  overview of ( Index Term Link )
  rcp ( Index Term Link )
  rlogin ( Index Term Link )
  rsh ( Index Term Link )
  table of SEAM ( Index Term Link )
  telnet ( Index Term Link )
 
 command-line equivalents of SEAM Administration Tool ( Index Term Link )
 
 configuration decisions ( Index Term Link )
  client and service principal names ( Index Term Link )
  clock skew ( Index Term Link )
  clock synchronization ( Index Term Link )
  database propagation ( Index Term Link )
  mapping hostnames onto realms ( Index Term Link )
  number of realms ( Index Term Link )
  ports ( Index Term Link )
  realm hierarchy ( Index Term Link )
  realm names ( Index Term Link )
  realms ( Index Term Link )
  slave KDCs ( Index Term Link )
 
 configuring a slave KDC ( Index Term Link )
 
 configuring application servers ( Index Term Link )
 
 configuring cross-realm authentication ( Index Term Link )
 
 configuring master KDC server ( Index Term Link )
 
 configuring NFS servers ( Index Term Link )
 
 configuring SEAM ( Index Term Link )
  adding administration principals ( Index Term Link )
  kdb5_util command ( Index Term Link )
 
 configuring SEAM clients
  See also configuration decisions
 
 context-sensitive help ( Index Term Link )
 
 creating a credential table ( Index Term Link )
 
 creating a keytab file ( Index Term Link )
 
 creating a new policy ( Index Term Link )
 
 creating a new principal ( Index Term Link )
 
 creating new policy ( Index Term Link )
 
 creating stash file ( Index Term Link )
 
 creating tickets ( Index Term Link )
  with kinit ( Index Term Link )
 
 credential ( Index Term Link )
  cache ( Index Term Link )
  definition ( Index Term Link ) ( Index Term Link )
  obtaining for a server ( Index Term Link )
  obtaining for a TGS ( Index Term Link )
  vs. ticket ( Index Term Link )
 
 credential cache ( Index Term Link )
  definition ( Index Term Link )
 
 credential table
  adding single entry to ( Index Term Link )
  changing the back-end mechanism ( Index Term Link )
  creating ( Index Term Link )
 
 cron ( Index Term Link )
  backing up using ( Index Term Link )
 
 cross-realm authentication, configuring ( Index Term Link )
    
D
 
 daemon
  krb5kdc ( Index Term Link )
  table of ( Index Term Link )
 
 database
  backing up and propagating ( Index Term Link )
  backing up and propagating Kerberos ( Index Term Link )
  creating ( Index Term Link )
  planning ( Index Term Link )
  propagation ( Index Term Link )
 
 default_realm ( Index Term Link )
 
 delete_entry command ( Index Term Link )
 
 deleting a host's service with delete_entry ( Index Term Link )
 
 deleting a principal ( Index Term Link )
 
 deleting policies ( Index Term Link )
 
 destroying tickets ( Index Term Link )
 
 dfstab file ( Index Term Link )
  kerberos option ( Index Term Link )
 
 direct realms ( Index Term Link )
 
 disabling service on a host ( Index Term Link )
 
 displaying a sublist of principals ( Index Term Link )
 
 DNS ( Index Term Link ) ( Index Term Link )
 
 domain_realm ( Index Term Link ) ( Index Term Link )
 
 duplicating a principal ( Index Term Link )
    
E
 
 enabling only Kerberized applications ( Index Term Link )
 
 encryption
  privacy service ( Index Term Link )
  with -x option ( Index Term Link )
 
 error message, with kpasswd ( Index Term Link )
 
 /etc/dfs/dfstab file, kerberos option ( Index Term Link )
 
 export restrictions ( Index Term Link )
    
F
 
 -f option to Kerberized commands ( Index Term Link ) ( Index Term Link )
 
 -F option to Kerberized commands ( Index Term Link ) ( Index Term Link )
 
 -F option
  vs. -f ( Index Term Link ) ( Index Term Link )
 
 -f option
  vs. -F option ( Index Term Link ) ( Index Term Link )
 
 file
  kdc.conf ( Index Term Link )
  table of SEAM ( Index Term Link )
 
 flavor, definition ( Index Term Link )
 
 forwardable ticket ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
  definition ( Index Term Link )
  -F option vs. -f ( Index Term Link ) ( Index Term Link )
  with -F ( Index Term Link ) ( Index Term Link )
  with -f ( Index Term Link ) ( Index Term Link )
 
 FQDN (Fully Qualified Domain Name) ( Index Term Link )
 
 ftp command ( Index Term Link ) ( Index Term Link )
  setting protection level in ( Index Term Link )
 
 ftpd daemon ( Index Term Link )
    
G
 
 Generic Security Service API
  See GSS-API
 
 getting a credential for a server ( Index Term Link )
 
 getting a credential for a TGS ( Index Term Link )
 
 getting access to a specific service ( Index Term Link )
 
 gkadmin command
  See also SEAM Administration Tool
 
 .gkadmin file ( Index Term Link ) ( Index Term Link )
 
 granting access to your account ( Index Term Link )
 
 GSS-API ( Index Term Link ) ( Index Term Link )
  definition ( Index Term Link )
 
 gsscred command ( Index Term Link )
 
 gsscred.conf file ( Index Term Link ) ( Index Term Link )
 
 gsscred file, changing backend mechanism ( Index Term Link )
 
 gssd daemon ( Index Term Link )
    
H
 
 help
  context-sensitive ( Index Term Link )
  Help Contents ( Index Term Link )
  SEAM Administration Tool ( Index Term Link )
 
 Help button ( Index Term Link )
 
 hierarchical realms ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
 
 host
  definition ( Index Term Link )
  disabling service on ( Index Term Link )
  mapping names onto realms ( Index Term Link )
 
 host principal
  and DNS ( Index Term Link )
  creating ( Index Term Link )
  definition ( Index Term Link )
 
 hostnames, mapping onto realms ( Index Term Link )
    
I
 
 ID
  principals vs. UNIX IDs ( Index Term Link )
  UNIX ( Index Term Link )
 
 initial ticket ( Index Term Link )
  definition ( Index Term Link )
 
 installation, post-installation ( Index Term Link )
 
 instance ( Index Term Link )
  definition ( Index Term Link )
 
 integrity ( Index Term Link ) ( Index Term Link )
  definition ( Index Term Link )
 
 invalid ticket ( Index Term Link )
  definition ( Index Term Link )
    
K
 
 -k option to Kerberized commands ( Index Term Link )
 
 -K option to Kerberized commands ( Index Term Link )
 
 .k5.REALM file ( Index Term Link )
 
 .k5login file ( Index Term Link ) ( Index Term Link )
  vs. revealing password ( Index Term Link )
 
 kadm5.acl ( Index Term Link ) ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
  format of entries ( Index Term Link )
 
 kadm5.acl file ( Index Term Link ) ( Index Term Link )
 
 kadm5.keytab file ( Index Term Link ) ( Index Term Link )
 
 kadmin command ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
  ktadd command ( Index Term Link )
  ktremove command ( Index Term Link )
  removing principals from keytab with ( Index Term Link )
 
 kadmin.local command ( Index Term Link ) ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
 
 kadmin.log file ( Index Term Link )
 
 kadmind daemon ( Index Term Link ) ( Index Term Link )
 
 kadmind principal ( Index Term Link )
 
 kdb5_util command ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
 
 KDC ( Index Term Link )
  adding entries to propagation file ( Index Term Link )
  adding slave names to cron job ( Index Term Link )
  backing up and propagating ( Index Term Link )
  configuring master ( Index Term Link )
  configuring server ( Index Term Link )
  configuring slave ( Index Term Link )
  copying administration files from slave to master ( Index Term Link )
  creating database ( Index Term Link )
  creating host principal ( Index Term Link )
  creating root principal ( Index Term Link ) ( Index Term Link )
  definition ( Index Term Link )
  master ( Index Term Link )
  planning ( Index Term Link )
  ports ( Index Term Link )
  propagating database with kprop_util ( Index Term Link )
  restricting access to servers ( Index Term Link )
  slave ( Index Term Link ) ( Index Term Link )
  slave vs. master ( Index Term Link ) ( Index Term Link )
  starting daemon ( Index Term Link )
  swapping master and slave ( Index Term Link )
  synchronizing clocks ( Index Term Link ) ( Index Term Link )
 
 kdc.conf file ( Index Term Link ) ( Index Term Link )
 
 kdc file ( Index Term Link )
 
 kdc.log file ( Index Term Link )
 
 kdc.master file ( Index Term Link )
 
 kdc start command ( Index Term Link )
 
 kdestroy command ( Index Term Link ) ( Index Term Link )
 
 KERB authentication, dfstab file option ( Index Term Link )
 
 Kerberos
  and Kerberos V5 ( Index Term Link )
  and SEAM ( Index Term Link ) ( Index Term Link )
  origin of name ( Index Term Link )
  terminology ( Index Term Link )
 
 kerberos, dfstab file option ( Index Term Link )
 
 Kerberos (KERB) authentication ( Index Term Link )
 
 key
  definition ( Index Term Link ) ( Index Term Link )
  private ( Index Term Link )
  service ( Index Term Link )
  service key ( Index Term Link )
  session ( Index Term Link ) ( Index Term Link )
 
 Key Distribution Center
  See KDC
 
 keytab, definition ( Index Term Link )
 
 keytab file
  adding master KDC's host principal to ( Index Term Link )
  adding service principal to ( Index Term Link ) ( Index Term Link )
  administering ( Index Term Link )
  administering with ktutil command ( Index Term Link )
  creating ( Index Term Link )
  disabling a host's service with delete_entry command ( Index Term Link )
  read into keytab buffer with with read_kt command ( Index Term Link )
  read into keytab with read_kt command ( Index Term Link )
  removing principals with ktremove command ( Index Term Link )
  removing service principal from ( Index Term Link )
  viewing contents with ktutil command ( Index Term Link ) ( Index Term Link )
  viewing keylist buffer with list command ( Index Term Link )
  viewing keylist buffer with the list command ( Index Term Link )
 
 kinds of tickets ( Index Term Link )
 
 kinit command ( Index Term Link ) ( Index Term Link )
  -F ( Index Term Link )
  ticket lifetime ( Index Term Link )
 
 klist command ( Index Term Link ) ( Index Term Link )
  -f option ( Index Term Link )
 
 kpasswd command ( Index Term Link ) ( Index Term Link )
  error message ( Index Term Link )
  vs. passwd command ( Index Term Link )
 
 kprop command ( Index Term Link )
 
 kprop_script script ( Index Term Link )
 
 kpropd.acl file ( Index Term Link ) ( Index Term Link )
 
 kpropd daemon ( Index Term Link )
 
 krb5.conf file ( Index Term Link ) ( Index Term Link )
  domain_realm ( Index Term Link )
  editing ( Index Term Link )
  ports ( Index Term Link )
 
 krb5.keytab file ( Index Term Link )
 
 krb5cc_uid file ( Index Term Link )
 
 krb5kdc command ( Index Term Link )
 
 krb5kdc daemon ( Index Term Link ) ( Index Term Link )
 
 ktadd command ( Index Term Link ) ( Index Term Link )
  syntax ( Index Term Link )
 
 ktkt_warnd daemon ( Index Term Link )
 
 ktremove command ( Index Term Link )
 
 ktutil command ( Index Term Link ) ( Index Term Link )
  delete_entry command ( Index Term Link )
  list command ( Index Term Link ) ( Index Term Link )
  read_kt command ( Index Term Link ) ( Index Term Link )
  viewing list of principals ( Index Term Link ) ( Index Term Link )
    
L
 
 lifetime of ticket ( Index Term Link )
 
 list command ( Index Term Link ) ( Index Term Link )
 
 list privileges in SEAM Administration Tool ( Index Term Link )
    
M
 
 -m option to Kerberized commands ( Index Term Link )
 
 managing passwords ( Index Term Link )
 
 mapping hostnames onto realms ( Index Term Link )
 
 master and slave KDCs ( Index Term Link )
 
 master KDC ( Index Term Link )
  configuring ( Index Term Link )
  definition ( Index Term Link )
  swapping with slave KDC ( Index Term Link )
  vs. slave ( Index Term Link )
 
 max_life ( Index Term Link )
 
 max_renewable_life ( Index Term Link )
 
 mech file ( Index Term Link )
 
 mechanism, defnition ( Index Term Link )
 
 modifying a principal ( Index Term Link )
 
 modifying a principal's password ( Index Term Link )
 
 modifying policies ( Index Term Link )
 
 mounting NFS Files systems ( Index Term Link )
    
N
 
 network application server
  See application server
 
 Network Time Protocol
  See NTP
 
 NFS, mounting systems ( Index Term Link )
 
 NFS server ( Index Term Link )
  configuring ( Index Term Link )
 
 non-hierarchical realms ( Index Term Link )
 
 NTP ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
  setting up client ( Index Term Link )
  setting up server ( Index Term Link )
    
O
 
 obtaining a credential for a server ( Index Term Link )
 
 obtaining a credential for a TGS ( Index Term Link )
 
 obtaining access to a specific service ( Index Term Link )
 
 obtaining forwardable tickets ( Index Term Link )
 
 obtaining tickets ( Index Term Link )
  with kinit ( Index Term Link )
 
 online help
  context-sensitive ( Index Term Link )
  Help Contents ( Index Term Link )
  SEAM Administration Tool ( Index Term Link )
 
 options to Kerberized commands ( Index Term Link )
  -f ( Index Term Link ) ( Index Term Link )
  -a ( Index Term Link )
  -F ( Index Term Link ) ( Index Term Link )
  -K ( Index Term Link )
  -m ( Index Term Link )
  -X ( Index Term Link )
  -x ( Index Term Link )
 
 ovsec_adm.xxxxx file ( Index Term Link )
    
P
 
 PAM ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
  configuration file ( Index Term Link )
  try_first_pass ( Index Term Link )
 
 pam.conf file ( Index Term Link ) ( Index Term Link )
 
 panels, table of SEAM Administration Tool ( Index Term Link )
 
 passwd command ( Index Term Link )
  try_first_pass ( Index Term Link )
  vs. kpasswd command ( Index Term Link )
 
 password ( Index Term Link )
  and policies ( Index Term Link )
  changing ( Index Term Link )
  changing with kpasswd command ( Index Term Link )
  changing with passwd command ( Index Term Link )
  granting access without revealing ( Index Term Link )
  management ( Index Term Link )
  modifying a principal's ( Index Term Link )
  suggestions on choosing ( Index Term Link )
  UNIX vs. Kerberos ( Index Term Link )
 
 password management ( Index Term Link )
 
 path ( Index Term Link )
  MANPATH variable ( Index Term Link )
  updating ( Index Term Link )
 
 planning ( Index Term Link )
  client and service principal names ( Index Term Link )
  clock skew ( Index Term Link )
  clock synchronization ( Index Term Link )
  configuration decisions ( Index Term Link )
  database propagation ( Index Term Link )
  number of realms ( Index Term Link )
  ports ( Index Term Link )
  realm hierarchy ( Index Term Link )
  realm names ( Index Term Link )
  realms ( Index Term Link )
  slave KDCs ( Index Term Link )
 
 planning for SEAM
  See planning
 
 Pluggable Authentication Module
  See PAM
 
 policy
  administering ( Index Term Link ) ( Index Term Link )
  and passwords ( Index Term Link )
  creating ( Index Term Link )
  creating new ( Index Term Link )
  definition ( Index Term Link )
  deleting ( Index Term Link )
  modifying ( Index Term Link )
  SEAM Administration Tool panels for ( Index Term Link )
  task map for administering ( Index Term Link )
  viewing attributes ( Index Term Link )
  viewing list of ( Index Term Link )
 
 port
  for KDC and admin services ( Index Term Link )
  KDC administration daemon ( Index Term Link )
 
 post-installation ( Index Term Link )
 
 postdatable ticket ( Index Term Link )
 
 postdated ticket ( Index Term Link )
  definition ( Index Term Link )
 
 primary ( Index Term Link )
  definition ( Index Term Link )
 
 principal ( Index Term Link )
  adding administration ( Index Term Link )
  adding service principal to keytab ( Index Term Link ) ( Index Term Link )
  administering ( Index Term Link ) ( Index Term Link )
  automating creation of ( Index Term Link )
  creating ( Index Term Link )
  creating host ( Index Term Link )
  creating root ( Index Term Link ) ( Index Term Link )
  definition ( Index Term Link )
  deleting ( Index Term Link )
  duplicating ( Index Term Link )
  instance ( Index Term Link )
  modifiying ( Index Term Link )
  name ( Index Term Link )
  primary ( Index Term Link )
  principal name ( Index Term Link )
  realm ( Index Term Link )
  removing from keytab file ( Index Term Link )
  removing service principal from keytab ( Index Term Link )
  root ( Index Term Link )
  SEAM Administration Tool panels for ( Index Term Link )
  service ( Index Term Link )
  setting up defaults ( Index Term Link )
  task map for administering ( Index Term Link )
  user ( Index Term Link )
  viewing attributes ( Index Term Link )
  viewing list of ( Index Term Link )
  viewing sublist of principals ( Index Term Link )
  vs. UNIX ID ( Index Term Link )
 
 principal.db file ( Index Term Link )
 
 principal.kadm5 file ( Index Term Link )
 
 principal.kadm5.lock file ( Index Term Link )
 
 principal name ( Index Term Link )
  definition ( Index Term Link )
 
 principal.ok file ( Index Term Link )
 
 privacy ( Index Term Link ) ( Index Term Link )
  availability ( Index Term Link ) ( Index Term Link )
  definition ( Index Term Link )
 
 private key ( Index Term Link )
  definition ( Index Term Link )
 
 private protection level ( Index Term Link )
 
 privilege ( Index Term Link )
  effects on SEAM Administration Tool ( Index Term Link )
 
 propagating KDC database with kprop_util ( Index Term Link )
 
 propagating the Kerberos database ( Index Term Link )
 
 propagation ( Index Term Link )
  database ( Index Term Link )
  Kerberos database ( Index Term Link )
 
 propagation file, adding entries to ( Index Term Link )
 
 protection level
  clear ( Index Term Link )
  private ( Index Term Link )
  safe ( Index Term Link )
  setting in ftp ( Index Term Link )
 
 proxiable ticket ( Index Term Link )
  definition ( Index Term Link )
 
 proxy ticket ( Index Term Link )
    
Q
 
 qop file ( Index Term Link )
    
R
 
 rcp command ( Index Term Link ) ( Index Term Link )
 
 read into keytab buffer with read_kt command ( Index Term Link )
 
 read into keytab with read_kt command ( Index Term Link )
 
 read_kt command ( Index Term Link ) ( Index Term Link )
 
 realm ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
  and servers ( Index Term Link )
  configuration decisions ( Index Term Link )
  configuring cross-realm authentication ( Index Term Link )
  contents of ( Index Term Link )
  definition ( Index Term Link )
  direct ( Index Term Link )
  hierarchical ( Index Term Link )
  hierarchical vs. non-hierarchical ( Index Term Link )
  hierarchy ( Index Term Link )
  in principal names ( Index Term Link )
  mapping hostnames onto ( Index Term Link )
  names ( Index Term Link )
  number of ( Index Term Link )
  requesting tickets for specific ( Index Term Link )
 
 realms and servers ( Index Term Link )
 
 removing principals with ktremove command ( Index Term Link )
 
 removing service principal from keytab file ( Index Term Link )
 
 renewable ticket ( Index Term Link )
  definition ( Index Term Link )
 
 restricting access for KDC servers ( Index Term Link )
 
 rlogin command ( Index Term Link ) ( Index Term Link )
 
 rlogind daemon ( Index Term Link )
 
 root
  adding principal to host's keytab ( Index Term Link )
  setting up authentication for NFS ( Index Term Link )
 
 root principal
  creating ( Index Term Link ) ( Index Term Link )
 
 RPCSEC_GSS API ( Index Term Link )
 
 rsh command ( Index Term Link ) ( Index Term Link )
 
 rshd daemon ( Index Term Link )
    
S
 
 safe protection level ( Index Term Link )
 
 SEAM
  acronym ( Index Term Link )
  administering ( Index Term Link )
  Administration Tool ( Index Term Link )
  and Kerberos V5 ( Index Term Link ) ( Index Term Link )
  commands ( Index Term Link ) ( Index Term Link )
  components of ( Index Term Link )
  configuration decisions ( Index Term Link )
  configuring ( Index Term Link )
  configuring KDC servers ( Index Term Link )
  daemons ( Index Term Link )
  enabling only kerberized applications ( Index Term Link )
  examples of using Kerberized commands ( Index Term Link )
  files ( Index Term Link )
  files, commands, and daemons ( Index Term Link )
  gaining access to server ( Index Term Link )
  granting access to your account ( Index Term Link )
  options to Kerberized commands ( Index Term Link )
  overview ( Index Term Link )
  overview of authentication ( Index Term Link )
  overview of kerberized commands ( Index Term Link )
  password management ( Index Term Link )
  planning for ( Index Term Link )
  post-installation ( Index Term Link )
  reference ( Index Term Link )
  SEAM-based commands, list of ( Index Term Link )
  table of command options ( Index Term Link )
  table of commands ( Index Term Link )
  table of daemons ( Index Term Link )
  table of files ( Index Term Link )
  terminology ( Index Term Link )
  using ( Index Term Link )
 
 SEAM Administration Tool ( Index Term Link )
  and limited administration privileges ( Index Term Link )
  and list privileges ( Index Term Link )
  and X Window system ( Index Term Link )
  command-line equivalents ( Index Term Link )
  context-sensitive help ( Index Term Link )
  creating a new principal ( Index Term Link )
  creating new policy ( Index Term Link ) ( Index Term Link )
  default values ( Index Term Link )
  deleting a principal ( Index Term Link )
  deleting policies ( Index Term Link )
  displaying sublist of principals ( Index Term Link )
  duplicating a principal ( Index Term Link )
  files modified by ( Index Term Link )
  Filter Pattern field ( Index Term Link )
  gkadmin command ( Index Term Link )
  gkadmin command vs. kadmin ( Index Term Link ) ( Index Term Link )
  .gkadmin file ( Index Term Link )
  help (print) ( Index Term Link )
  Help button ( Index Term Link )
  Help Contents ( Index Term Link )
  how affected by privileges ( Index Term Link )
  kadmin command vs. gkadmin ( Index Term Link ) ( Index Term Link )
  login window ( Index Term Link )
  modifying a principal ( Index Term Link )
  modifying policies ( Index Term Link )
  online help ( Index Term Link )
  panel descriptions ( Index Term Link )
  privileges ( Index Term Link )
  setting up principal defaults ( Index Term Link )
  starting ( Index Term Link )
  table of panels ( Index Term Link )
  viewing a principal's attributes ( Index Term Link )
  viewing list of policies ( Index Term Link )
  viewing list of principals ( Index Term Link )
  viewing policy attributes ( Index Term Link )
  vs. kadmin command ( Index Term Link )
 
 SEAM commands ( Index Term Link ) ( Index Term Link )
  enabling only Kerberized ( Index Term Link )
  examples of ( Index Term Link )
 
 SEAM files ( Index Term Link )
 
 security, KERB authentication ( Index Term Link )
 
 security mechanism, specifying with -m ( Index Term Link )
 
 security mode, setting up environment with multiple ( Index Term Link )
 
 security service ( Index Term Link )
  export restrictions on ( Index Term Link )
  integrity ( Index Term Link )
  privacy ( Index Term Link )
 
 server
  and realms ( Index Term Link )
  definition ( Index Term Link ) ( Index Term Link )
  gaining access with SEAM ( Index Term Link )
  obtaining credential for ( Index Term Link )
 
 server principal, definition ( Index Term Link )
 
 servers and realms ( Index Term Link )
 
 service
  definition ( Index Term Link ) ( Index Term Link )
  disabling on a host ( Index Term Link )
  obtaining access for specific service ( Index Term Link )
 
 service, security
  See security service
 
 service key ( Index Term Link ) ( Index Term Link )
  definition ( Index Term Link )
 
 service principal ( Index Term Link )
  adding to keytab file ( Index Term Link ) ( Index Term Link )
  definition ( Index Term Link )
  planning for names ( Index Term Link )
  removing from keytab file ( Index Term Link )
 
 session key ( Index Term Link ) ( Index Term Link )
  definition ( Index Term Link )
 
 setting up principal defaults ( Index Term Link )
 
 single-sign-on system ( Index Term Link ) ( Index Term Link )
 
 slave and master KDCs ( Index Term Link )
 
 slave_datatrans file ( Index Term Link ) ( Index Term Link )
 
 slave KDC ( Index Term Link )
  adding names to cron job ( Index Term Link )
  configuring ( Index Term Link )
  definition ( Index Term Link )
  planning for ( Index Term Link )
  swapping with master KDC ( Index Term Link )
  vs. master ( Index Term Link )
 
 starting KDC daemon ( Index Term Link )
 
 stash file ( Index Term Link )
  creating ( Index Term Link )
  definition ( Index Term Link )
 
 Sun Enterprise Authentication Manager
  See SEAM
 
 swapping master and slave KDCs ( Index Term Link )
 
 synchronizing clocks ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
    
T
 
 table of SEAM daemons ( Index Term Link )
 
 task map
  administering policies ( Index Term Link )
  administering principals ( Index Term Link )
 
 telnet command ( Index Term Link ) ( Index Term Link )
 
 telnetd daemon ( Index Term Link )
 
 terminology
  authentication-specific ( Index Term Link )
  Kerberos-specific ( Index Term Link )
  SEAM ( Index Term Link )
 
 TGS ( Index Term Link )
  getting credential for ( Index Term Link )
 
 TGT ( Index Term Link ) ( Index Term Link )
 
 ticket ( Index Term Link ) ( Index Term Link )
  -F option vs. -f ( Index Term Link )
  -k option ( Index Term Link )
  creating ( Index Term Link )
  creating with kinit ( Index Term Link )
  definition ( Index Term Link ) ( Index Term Link )
  destroying ( Index Term Link )
  file
   See credential cache
  forwardable ( Index Term Link ) ( Index Term Link ) ( Index Term Link ) ( Index Term Link ) ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
  initial ( Index Term Link )
  invalid ( Index Term Link )
  klist command ( Index Term Link )
  lifetime ( Index Term Link )
  maximum renewable lifetime ( Index Term Link )
  obtaining ( Index Term Link )
  postdatable ( Index Term Link )
  postdated ( Index Term Link )
  proxiable ( Index Term Link )
  proxy ( Index Term Link )
  renewable ( Index Term Link )
  requesting for specific realm ( Index Term Link )
  types of ( Index Term Link )
  viewing ( Index Term Link )
  vs. credential ( Index Term Link )
  warning about expiration ( Index Term Link )
 
 ticket file
  See credential cache
 
 ticket-granting service
  See TGS
 
 Ticket-Granting Ticket
  See TGT
 
 transparency ( Index Term Link )
 
 try_first_pass ( Index Term Link )
 
 types of tickets ( Index Term Link )
    
U
 
 UNIX
  IDs, in NFS services ( Index Term Link )
  IDs, vs. principals ( Index Term Link )
 
 user principal ( Index Term Link )
  definition ( Index Term Link )
    
V
 
 view keylist buffer with list command ( Index Term Link )
 
 viewing a principal's attributes ( Index Term Link )
 
 viewing keylist buffer with list command ( Index Term Link )
 
 viewing list of policies ( Index Term Link )
 
 viewing list of principals ( Index Term Link )
 
 viewing policy attributes ( Index Term Link )
 
 viewing tickets ( Index Term Link )
    
W
 
 warn.conf file ( Index Term Link )
 
 warning about ticket expiration ( Index Term Link )
    
X
 
 -x option to Kerberized commands ( Index Term Link )
 
 -X option to Kerberized commands ( Index Term Link )
 
 X Window system, and SEAM Administration Tool ( Index Term Link )
 
 xfn ( Index Term Link )
 
 xfn_files ( Index Term Link )
 
 xfn_nis ( Index Term Link )
 
 xfn_nisplus ( Index Term Link )