<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Kerberos security in Operating System - HP-UX</title>
    <link>https://community.hpe.com/t5/operating-system-hp-ux/kerberos-security/m-p/3459361#M744200</link>
    <description>Hi,&lt;BR /&gt;&lt;BR /&gt;Q1) But there is number of kerberos clients, pam interfaces.... which are used by your applications for kerberos authentications and authorization. Is all these services active/function now? How to check?&lt;BR /&gt; &lt;BR /&gt;Q2) Since there is no kerberos server in my system, can I hash all the related kerberos services (kerberos clients, pam interfaces ...) in /etc/services and /etc/inetd.conf?&lt;BR /&gt;&lt;BR /&gt;regards.</description>
    <pubDate>Tue, 11 Jan 2005 07:20:52 GMT</pubDate>
    <dc:creator>Ngoh Chean Siung</dc:creator>
    <dc:date>2005-01-11T07:20:52Z</dc:date>
    <item>
      <title>Kerberos security</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/kerberos-security/m-p/3459355#M744194</link>
      <description>Hi,&lt;BR /&gt;&lt;BR /&gt;How I know whether the Kerberos security is used in my system?&lt;BR /&gt;&lt;BR /&gt;regards.</description>
      <pubDate>Mon, 10 Jan 2005 07:06:01 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/kerberos-security/m-p/3459355#M744194</guid>
      <dc:creator>Ngoh Chean Siung</dc:creator>
      <dc:date>2005-01-10T07:06:01Z</dc:date>
    </item>
    <item>
      <title>Re: Kerberos security</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/kerberos-security/m-p/3459356#M744195</link>
      <description>Hi,&lt;BR /&gt;&lt;BR /&gt;# swlist -l fileset | grep -i kerberos&lt;BR /&gt;&lt;BR /&gt;check the /etc/pam.conf&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://www.software.hp.com/portal/swdepot/displayInstallInfo.do?productNumber=J5849AA" target="_blank"&gt;http://www.software.hp.com/portal/swdepot/displayInstallInfo.do?productNumber=J5849AA&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;Hope this helps,&lt;BR /&gt;Robert-Jan</description>
      <pubDate>Mon, 10 Jan 2005 07:11:13 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/kerberos-security/m-p/3459356#M744195</guid>
      <dc:creator>Robert-Jan Goossens</dc:creator>
      <dc:date>2005-01-10T07:11:13Z</dc:date>
    </item>
    <item>
      <title>Re: Kerberos security</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/kerberos-security/m-p/3459357#M744196</link>
      <description>Hi,&lt;BR /&gt;&lt;BR /&gt;In the HP-UX 11.11 system,&lt;BR /&gt;&lt;BR /&gt;# swlist -l fileset | grep -i kerberos&lt;BR /&gt;# KRB-Support                           B.11.11        Kerberos Support for HP-UX and DCE&lt;BR /&gt;# KRB5-Client                           B.11.11        Kerberos V5 Client Version 1.0&lt;BR /&gt;# PAM-Kerberos                          B.11.11.12     PAM-Kerberos Version 1.10&lt;BR /&gt;  PAM-Kerberos.PAM-KRB-DEMO             B.11.11.12     PAM-Kerberos Demonstration&lt;BR /&gt;  PAM-Kerberos.PAM-KRB-MAN              B.11.11.12     PAM-Kerberos Man Pages&lt;BR /&gt;  PAM-Kerberos.PAM-KRB-RUN              B.11.11.12     PAM-Kerberos Runtime&lt;BR /&gt;  PAM-Kerberos.PAM-KRB-SHLIB            B.11.11.12     PAM-Kerberos Shared Library&lt;BR /&gt;&lt;BR /&gt;In the HP-UX 11 system,&lt;BR /&gt;&lt;BR /&gt;# swlist -l fileset | grep -i kerberos&lt;BR /&gt;# KRB-Support                           B.11.00        Kerberos Support for HP-UX and DCE&lt;BR /&gt;&lt;BR /&gt;Q1) I think there is Kerberos software installed in both system. How I know whether we are using this software now? Or these software is come together with the server? Because I want to hash all the kerberos services under /etc/services and /etc/inetd.conf.&lt;BR /&gt;&lt;BR /&gt;Example of the kerberos services is as below:&lt;BR /&gt;&lt;BR /&gt;kerberos5     88/udp   kdc           # Kerberos 5 kdc&lt;BR /&gt;klogin       543/tcp                 # Kerberos rlogin -kfall&lt;BR /&gt;kshell       544/tcp  krcmd          # Kerberos remote shell -kfall&lt;BR /&gt;ekshell      545/tcp  krcmd          # Kerberos encrypted remote shell -kfall&lt;BR /&gt;kerberos     750/udp  kdc            # Kerberos (server) udp -kfall&lt;BR /&gt;kerberos     750/tcp  kdc            # Kerberos (server) tcp -kfall&lt;BR /&gt;kerberos_master 751/tcp kadmin       # Kerberos kadmin&lt;BR /&gt;krbupdate    760/tcp  kreg           # Kerberos registration -kfall&lt;BR /&gt;kpasswd      761/tcp  kpwd           # Kerberos "passwd" -kfall&lt;BR /&gt;eklogin     2105/tcp                 # Kerberos encrypted rlogin -kfall&lt;BR /&gt;&lt;BR /&gt;regards.&lt;BR /&gt;</description>
      <pubDate>Tue, 11 Jan 2005 03:46:33 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/kerberos-security/m-p/3459357#M744196</guid>
      <dc:creator>Ngoh Chean Siung</dc:creator>
      <dc:date>2005-01-11T03:46:33Z</dc:date>
    </item>
    <item>
      <title>Re: Kerberos security</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/kerberos-security/m-p/3459358#M744197</link>
      <description>Hello,&lt;BR /&gt;&lt;BR /&gt;Try the following:&lt;BR /&gt;&lt;BR /&gt;1.  swlist | grep T1417AA&lt;BR /&gt;&lt;BR /&gt;If it results with the following &lt;BR /&gt;&lt;BR /&gt;"Kerberos Server Version X.X and its Administration Utilities"&lt;BR /&gt;&lt;BR /&gt;It says HP Kerberos server is available on your host. You can simply remove the server by the following command if needed.&lt;BR /&gt;&lt;BR /&gt;swremove T1417AA &lt;BR /&gt;&lt;BR /&gt;2. A simple check for kerberos deamon is&lt;BR /&gt;&lt;BR /&gt;ps -ef | grep kdcd&lt;BR /&gt;&lt;BR /&gt;which lists kerberos deomons if it is currently running in the system. &lt;BR /&gt;&lt;BR /&gt;Q1) I think there is Kerberos software installed in both system. How I know whether we are using this software now? Or these software is come together with the server? Because I want to hash all the kerberos services under /etc/services and /etc/inetd.conf.&lt;BR /&gt;&lt;BR /&gt;I belive from you message no kerberos server runs on your machine. If you no more need kerberos support for those services you may hast it all.&lt;BR /&gt;&lt;BR /&gt;Releated links:&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://www.ncsa.uiuc.edu/UserInfo/Resources/Software/kerberos/inetd.conf" target="_blank"&gt;http://www.ncsa.uiuc.edu/UserInfo/Resources/Software/kerberos/inetd.conf&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://www.isi.edu/gost/brian/security/kerberos.html" target="_blank"&gt;http://www.isi.edu/gost/brian/security/kerberos.html&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://software.hp.com/portal/swdepot/displayProductInfo.do?productNumber=T1417AA" target="_blank"&gt;http://software.hp.com/portal/swdepot/displayProductInfo.do?productNumber=T1417AA&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Hope this helps&lt;BR /&gt;--&lt;BR /&gt;M&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Tue, 11 Jan 2005 04:21:25 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/kerberos-security/m-p/3459358#M744197</guid>
      <dc:creator>Michael Selvesteen_2</dc:creator>
      <dc:date>2005-01-11T04:21:25Z</dc:date>
    </item>
    <item>
      <title>Re: Kerberos security</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/kerberos-security/m-p/3459359#M744198</link>
      <description>Hi,&lt;BR /&gt;&lt;BR /&gt;Q1) There is no output after running these commands &lt;BR /&gt;# swlist | grep T1417AA&lt;BR /&gt;# ps -ef | grep kdcd&lt;BR /&gt;&lt;BR /&gt;What does it mean? No software installed or ...?&lt;BR /&gt;&lt;BR /&gt;Q2) Where is the location of kdcd? There is also no man for kdcd.&lt;BR /&gt;&lt;BR /&gt;Q3) From which messages that you know my system is not using kerberos?&lt;BR /&gt;&lt;BR /&gt;regards. &lt;BR /&gt;</description>
      <pubDate>Tue, 11 Jan 2005 05:18:12 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/kerberos-security/m-p/3459359#M744198</guid>
      <dc:creator>Ngoh Chean Siung</dc:creator>
      <dc:date>2005-01-11T05:18:12Z</dc:date>
    </item>
    <item>
      <title>Re: Kerberos security</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/kerberos-security/m-p/3459360#M744199</link>
      <description>Hello,&lt;BR /&gt;&lt;BR /&gt;Q1) There is no output after running these commands &lt;BR /&gt;# swlist | grep T1417AA&lt;BR /&gt;# ps -ef | grep kdcd&lt;BR /&gt;&lt;BR /&gt;What does it mean? No software installed or ...?&lt;BR /&gt;&lt;BR /&gt;Yes..It means HP Kerberos server is not installed in your system.&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://docs.hp.com/en/B8725-90078/ch01.html" target="_blank"&gt;http://docs.hp.com/en/B8725-90078/ch01.html&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Q2) Where is the location of kdcd? There is also no man for kdcd.&lt;BR /&gt;&lt;BR /&gt;In my system &lt;BR /&gt;&lt;BR /&gt;# ps -ef | grep kdcd&lt;BR /&gt;    root   658   621  0 12:28:05 ?         0:00 /opt/krb5/sbin/kdcd&lt;BR /&gt;    root 14785  5352  0 19:36:20 pts/td    0:00 grep kdcd&lt;BR /&gt;    root   621     1  0 12:28:04 ?         0:00 /opt/krb5/sbin/kdcd&lt;BR /&gt;&lt;BR /&gt;It resides in /opt/krb5/sbin/kdcd&lt;BR /&gt;&lt;BR /&gt;kdcd is a daemon that provides two services: the authentication service (AS) and the ticket-granting service (TGS).&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://www.cmf.nrl.navy.mil/CCS/people/kenh/kerberos-faq.html" target="_blank"&gt;http://www.cmf.nrl.navy.mil/CCS/people/kenh/kerberos-faq.html&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Q3) From which messages that you know my system is not using kerberos?&lt;BR /&gt;&lt;BR /&gt;I told your system has no HP kerberos server.&lt;BR /&gt;But there is number of kerberos clients, pam interfaces....  which are used by your applications for kerberos authentications and authorization.&lt;BR /&gt;&lt;BR /&gt;FYI:&lt;BR /&gt;&lt;BR /&gt;/etc/services&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://www.faqs.org/docs/securing/chap5sec40.html" target="_blank"&gt;http://www.faqs.org/docs/securing/chap5sec40.html&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;Hope this helps&lt;BR /&gt;&lt;BR /&gt;--&lt;BR /&gt;M&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Tue, 11 Jan 2005 06:45:09 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/kerberos-security/m-p/3459360#M744199</guid>
      <dc:creator>Michael Selvesteen_2</dc:creator>
      <dc:date>2005-01-11T06:45:09Z</dc:date>
    </item>
    <item>
      <title>Re: Kerberos security</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/kerberos-security/m-p/3459361#M744200</link>
      <description>Hi,&lt;BR /&gt;&lt;BR /&gt;Q1) But there is number of kerberos clients, pam interfaces.... which are used by your applications for kerberos authentications and authorization. Is all these services active/function now? How to check?&lt;BR /&gt; &lt;BR /&gt;Q2) Since there is no kerberos server in my system, can I hash all the related kerberos services (kerberos clients, pam interfaces ...) in /etc/services and /etc/inetd.conf?&lt;BR /&gt;&lt;BR /&gt;regards.</description>
      <pubDate>Tue, 11 Jan 2005 07:20:52 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/kerberos-security/m-p/3459361#M744200</guid>
      <dc:creator>Ngoh Chean Siung</dc:creator>
      <dc:date>2005-01-11T07:20:52Z</dc:date>
    </item>
  </channel>
</rss>

