kdc

kdc

 英

  • 网络密钥分发中心(Key Distribution Center);密钥分配中心;密钥发行中心

例句

The KDC supplies the ME with single-sign-on credentials in the form of a Key Encryption Key (KEK).

KDCME提供密密KEK形式登录证书

The following steps are required on both the KDC machines to set up an inter-realm between the two realms that have been configured so far.

下面步骤领域目前为止已经配置领域之间设置领域配置KDC计算机所需采取步骤

KDC is responsible for key distribution and all the authentication processes which may take place in the network.

KDC负责密钥分发可能网络发生所有身份验证过程

Since the slave KDC is meant for backing up the master KDC in an emergency, the slave KDC might need to use the read-write copy.

因为KDC用于紧急情况替代KDC所以KDC可能需要使用读写拷贝

You've got the valid credentials from KDC for principal name sandeep, so let's try to log in as principal root, as shown in Listing 3.

已经KDC获得主体sandeep有效凭据所以让我们尝试主体root用户进行登录清单3

For a KDC in one realm to authenticate Kerberos users in a different realm, it must share a key with the KDC in the other realm.

如果一个领域KDC另一个领域Kerberos用户进行身份验证必须另一个领域KDC共享密钥

The figure below provides an overview of the communication between the client, application server and the KDC during authentication.

下面一个概览展示客户机应用服务器KDC身份验证期间通信

Please note KDC is configured to support encryption types which are a variant of des-cbc-crc, as it works well with OpenAFS.

注意KDC配置支持des-cbc-crc变体这些加密类型因为des-cbc-crc非常适用OpenAFS

Administrators with a hybrid environment can benefit from a single IBM NAS KDC on AIX for authentication across different platforms.

混合环境可以使用单个AIXIBMNASKDC进行不同平台身份验证管理员可以从中受益

In this type of scenario, users authenticate once to the KDC, and then their authentications are valid for a predetermined time period.

这种情况用户只需一次性通过KDC身份验证然后身份验证信息预定时间有效

As I am not interested in using any of the KDC options, I don't need to do any logical processing to author the kdc-options field.

因为不想使用任何KDC选项所以需要生成kdc-options字段进行任何逻辑处理

This message is directed to the KDC component known as Authentication Server (AS).

这个消息指向称为身份验证服务器(AuthenticationServer,AS)KDC组件

In this article, you have examined all the necessary steps required to set up the IBM NAS KDC and administration discovery using TDS.

本文研究使用TDS进行IBMNASKDC管理服务器发现所有配置步骤

The KDC was unable to generate a referral for the service requested.

KDC无法要求服务生成参照

This makes it very important that the KDC database is not compromised because otherwise it becomes a single point of failure.

因此KDC数据库绝对不能泄漏否则成为一个故障一点非常重要

Fix: Verify whether the server service principal name and client principal name are in the KDC database.

解决方案检查服务器服务主体客户机主体是否存储KDC数据库

The KDC failed to update the trusted domain list. The error is in the data.

KDC无法更新新任列表错误数据

A simple Kerberos configuration is a realm definition, which includes KDC server, kadmind server (optional) and clients.

一种简单Kerberos配置一个定义其中包含KDC服务器kadmind服务器可选客户端

To configure the NAS KDC server to use the legacy database, use the following command, as shown in Listing 3 .

NASKDC服务器配置使用遗留数据库可以使用下面命令清单3所示

Edit the kdc. conf file to reflect the encryption types required by all the clients and relevant principals.

编辑kdc.conf文件反映所有客户端相关主体加密类型

kinit: This utility obtains the name and port of the KDC from the LDAP server.

kinit这个实用工具可以LDAP服务器获得KDC名称口号

On a non-KDC-enabled system (not a domain controller), the KDC service startup type is disabled.

支持KDC系统控制器KDC服务启动类型禁用

Note: There is no "kdc" or "admin_server" entry for this type of configuration under the [realm] stanza, unlike in the default case.

注意缺省情况不同对于这种配置类型[realm]之下没有相应kdc或者“admin_server”条目

The client principal name and client host principal name should be in the KDC database.

客户机主体客户机主机主体必须KDC数据库

The example KDC setup below shows the steps needed to set up an MIT Kerberos authentication system.

下面示例KDC设置展示设置MITKerberos身份验证系统步骤

Receiving the reply from KDC, client then decrypts the message using its own secret key.

客户端接收KDC回复然后使用自己秘密密解密消息

After changing the kdc. conf file, the Kerberos server must be restarted.

修改kdc.conf文件之后必须重新启动Kerberos服务器

Only one conifig. krb5 command on the slave KDC, and that is all.

需要KDC运行一个conifig.krb5命令而已

Therefore, securing the KDC is of paramount importance.

因此保证KDC安全至关重要

Use this utility to setup a realm entry for a Kerberos V5 realm by defining a list of KDC servers and "kpasswd" server for the realm.

使用工具通过领域定义KDC服务器列表kpasswd服务器KerberosV5领域设置领域条目

This article covered the details on how to set up the IBM NAS master KDC on AIX to use the LDAP directory.

本文详细讨论如何AIX通过设置IBMNASKDC使用LDAP目录

Now the master KDC is up and running, but only this master KDC to one LDAP master server.

现在KDC已经开始运行但是这个KDC连接一个LDAP服务器

KDC also has a database of secret keys; each entity (user, host, or an application server) shares a secret key with the KDC.

KDC拥有一个数据库每个实体用户主机应用服务器KDC共享一个

It must be run locally on the KDC as root and modifies the KDC databases directly.

必须用户身份本地运行KDC可以直接更改KDC数据库

The KDC administrator must add a server principal to the KDC database for each SSO-enabled IDS database server.

对于每个启用SSOIDS数据库服务器KDC管理员必须一个服务器主体添加KDC数据库

The admin principals are KDC service principals that handle the administrative tasks.

管理员主体处理管理任务KDC服务主体

The KDC is trusted by all clients and servers in the network and is used to verify user identities.

网络所有客户机服务器信任KDC并且使用KDC验证用户身份

Also, you need to configure clients in such a way that all slave KDCs and the master KDC are optimally exploited.

同样需要客户机进行配置使所有KDCKDC得到充分利用

Now configure the slave KDC with the two LDAP master servers and three LDAP replica servers.

现在两个LDAP服务器三个LDAP副本服务器配置KDC

After Active Directory is installed, ensure that the Kerberos KDC is running.

安装活动目录确保KerberosKDC正在运行