kdc

kdc

 英

  • 網絡密鑰分發中心(Key Distribution Center);密鑰分配中心;密鑰發行中心

例句

The KDC supplies the ME with single-sign-on credentials in the form of a Key Encryption Key (KEK).

KDCME提供密密KEK形式登錄證書

The following steps are required on both the KDC machines to set up an inter-realm between the two realms that have been configured so far.

下面步驟領域目前為止已經配置領域之間設置領域配置KDC計算機所需采取步驟

KDC is responsible for key distribution and all the authentication processes which may take place in the network.

KDC負責密鑰分發可能網絡發生所有身份驗證過程

Since the slave KDC is meant for backing up the master KDC in an emergency, the slave KDC might need to use the read-write copy.

因為KDC用于緊急情況替代KDC所以KDC可能需要使用讀寫拷貝

You've got the valid credentials from KDC for principal name sandeep, so let's try to log in as principal root, as shown in Listing 3.

已經KDC獲得主體sandeep有效憑據所以讓我們嘗試主體root用戶進行登錄清單3

For a KDC in one realm to authenticate Kerberos users in a different realm, it must share a key with the KDC in the other realm.

如果一個領域KDC另一個領域Kerberos用戶進行身份驗證必須另一個領域KDC共享密鑰

The figure below provides an overview of the communication between the client, application server and the KDC during authentication.

下面一個概覽展示客戶機應用服務器KDC身份驗證期間通信

Please note KDC is configured to support encryption types which are a variant of des-cbc-crc, as it works well with OpenAFS.

注意KDC配置支持des-cbc-crc變體這些加密類型因為des-cbc-crc非常適用OpenAFS

Administrators with a hybrid environment can benefit from a single IBM NAS KDC on AIX for authentication across different platforms.

混合環境可以使用單個AIXIBMNASKDC進行不同平臺身份驗證管理員可以從中受益

In this type of scenario, users authenticate once to the KDC, and then their authentications are valid for a predetermined time period.

這種情況用戶只需一次性通過KDC身份驗證然后身份驗證信息預定時間有效

As I am not interested in using any of the KDC options, I don't need to do any logical processing to author the kdc-options field.

因為不想使用任何KDC選項所以需要生成kdc-options字段進行任何邏輯處理

This message is directed to the KDC component known as Authentication Server (AS).

這個消息指向稱為身份驗證服務器(AuthenticationServer,AS)KDC組件

In this article, you have examined all the necessary steps required to set up the IBM NAS KDC and administration discovery using TDS.

本文研究使用TDS進行IBMNASKDC管理服務器發現所有配置步驟

The KDC was unable to generate a referral for the service requested.

KDC無法要求服務生成參照

This makes it very important that the KDC database is not compromised because otherwise it becomes a single point of failure.

因此KDC數據庫絕對不能泄漏否則成為一個故障一點非常重要

Fix: Verify whether the server service principal name and client principal name are in the KDC database.

解決方案檢查服務器服務主體客戶機主體是否存儲KDC數據庫

The KDC failed to update the trusted domain list. The error is in the data.

KDC無法更新新任列表錯誤數據

A simple Kerberos configuration is a realm definition, which includes KDC server, kadmind server (optional) and clients.

一種簡單Kerberos配置一個定義其中包含KDC服務器kadmind服務器可選客戶端

To configure the NAS KDC server to use the legacy database, use the following command, as shown in Listing 3 .

NASKDC服務器配置使用遺留數據庫可以使用下面命令清單3所示

Edit the kdc. conf file to reflect the encryption types required by all the clients and relevant principals.

編輯kdc.conf文件反映所有客戶端相關主體加密類型

kinit: This utility obtains the name and port of the KDC from the LDAP server.

kinit這個實用工具可以LDAP服務器獲得KDC名稱口號

On a non-KDC-enabled system (not a domain controller), the KDC service startup type is disabled.

支持KDC系統控制器KDC服務啟動類型禁用

Note: There is no "kdc" or "admin_server" entry for this type of configuration under the [realm] stanza, unlike in the default case.

注意缺省情況不同對于這種配置類型[realm]之下沒有相應kdc或者“admin_server”條目

The client principal name and client host principal name should be in the KDC database.

客戶機主體客戶機主機主體必須KDC數據庫

The example KDC setup below shows the steps needed to set up an MIT Kerberos authentication system.

下面示例KDC設置展示設置MITKerberos身份驗證系統步驟

Receiving the reply from KDC, client then decrypts the message using its own secret key.

客戶端接收KDC回復然后使用自己秘密密解密消息

After changing the kdc. conf file, the Kerberos server must be restarted.

修改kdc.conf文件之后必須重新啟動Kerberos服務器

Only one conifig. krb5 command on the slave KDC, and that is all.

需要KDC運行一個conifig.krb5命令而已

Therefore, securing the KDC is of paramount importance.

因此保證KDC安全至關重要

Use this utility to setup a realm entry for a Kerberos V5 realm by defining a list of KDC servers and "kpasswd" server for the realm.

使用工具通過領域定義KDC服務器列表kpasswd服務器KerberosV5領域設置領域條目

This article covered the details on how to set up the IBM NAS master KDC on AIX to use the LDAP directory.

本文詳細討論如何AIX通過設置IBMNASKDC使用LDAP目錄

Now the master KDC is up and running, but only this master KDC to one LDAP master server.

現在KDC已經開始運行但是這個KDC連接一個LDAP服務器

KDC also has a database of secret keys; each entity (user, host, or an application server) shares a secret key with the KDC.

KDC擁有一個數據庫每個實體用戶主機應用服務器KDC共享一個

It must be run locally on the KDC as root and modifies the KDC databases directly.

必須用戶身份本地運行KDC可以直接更改KDC數據庫

The KDC administrator must add a server principal to the KDC database for each SSO-enabled IDS database server.

對于每個啟用SSOIDS數據庫服務器KDC管理員必須一個服務器主體添加KDC數據庫

The admin principals are KDC service principals that handle the administrative tasks.

管理員主體處理管理任務KDC服務主體

The KDC is trusted by all clients and servers in the network and is used to verify user identities.

網絡所有客戶機服務器信任KDC并且使用KDC驗證用戶身份

Also, you need to configure clients in such a way that all slave KDCs and the master KDC are optimally exploited.

同樣需要客戶機進行配置使所有KDCKDC得到充分利用

Now configure the slave KDC with the two LDAP master servers and three LDAP replica servers.

現在兩個LDAP服務器三個LDAP副本服務器配置KDC

After Active Directory is installed, ensure that the Kerberos KDC is running.

安裝活動目錄確保KerberosKDC正在運行