Reference8:Configuration/General/Kerberos

From innovaphone wiki
Revision as of 18:23, 27 October 2009 by Msc (talk | contribs) (New page: On this page the Kerberos server of the device is managed. == General settings == === Password === The password is used to encrypt sensitive information in the LDAP database of the server...)
(diff) ← Older revision | Latest revision (diff) | Newer revision → (diff)
Jump to navigation Jump to search
There are also other versions of this article available: Reference8 (this version) | Reference9

On this page the Kerberos server of the device is managed.

General settings

Password

The password is used to encrypt sensitive information in the LDAP database of the server. The password has to be configured before any further settings can be done. In scenarios with LDAP replication the passwords have to be the same on both the master and the slave.

Realm

This is the unique name of the realm of the Kerberos server. The name may contain letters, numbers, points (.) and minus signs (-). Typically names of Kerberos realms don't contain lower-case letters.

LDAP Replication

LDAP replication can be used to setup two redundant Kerberos servers. The replication is configured on the slave device.

Master

The IP address of the master server.

Enable

Turns on/off replication.

Users

Name

May contain letters, numbers and minus signs.

Password

User passwords are limited to a length of 15 characters.

Authorization

Defines the rights the user has on the devices of the realm.

  • Administrator: do anything
  • Viewer: view settings
  • Join Realm: add devices to the realm, no login

Trusted realms / Cross-realm authentication

Defines trust relationships between the realm of the Kerberos server and remote realms. This means that users from the one realm can be authenticated to services/hosts of the other realm. This is called cross-realm authentication. Realms that trust each other have a shared password.

Name

May contain letters, numbers and minus signs.

Password

Passwords are limited to a length of 15 characters.

Authorization

  • keep: Works only with innovaphone realms. Users of the remote realm have the same rights in the local realm.
  • use domain group: Works only with Windows domains. You can specify the RIDs of a windows group of administrators and a windows group of viewers.
  • Administrator: All users of the remote realm have administrator rights in the local realm.
  • Viewer: All users of the remote realm have viewer rights in the local realm.

Admin Group RIP / Viewer Group RID