Installing and Administering Internet Services

Chapter 11 355
Secure Internet Services
Configuration and Kerberos Version Interoperability Requirements
The configuration file and realms file are combined into one
configuration file with a new format. The new configuration file is
named /etc/krb5.conf.
The /etc/krb5.conf file specifies (1) defaults for the realm and for
Kerberos applications, (2) mappings of host names onto Kerberos
realms, and (3) the location of KDCs for the Kerberos realms.
For HP DCE clients, the /etc/krb5.conf file must be created and
maintained manually.
For HP P/SS clients, the /etc/krb5.conf file is created
automatically but it must be maintained manually. Also, to ensure
that the file is created correctly, the patch PHSS_7877 must have
been installed before the P/SS client is configured.
If you were using the pre-HP-UX 11.0 Secure Internet Services, and
so the configuration and realms files were previously configured, you
can use a migration tool to combine the two files into the one file used
by HP-UX 11.0. See “Migrating Version 5 Beta 4 Files to Version 5
Release 1.0” on page 361 for instructions on how to use the tool.
Note that, because the kinit, klist, and kdestroy commands still
require the V5 Beta 4 /krb5/krb.conf and /krb5/krb.realms
files, you must still keep these files in the secure environment’s
configuration, and their configuration information must match that of
the V5-1.0 file. If you make any changes to the V5-1.0 file
(/etc/krb5.conf), you must also manually make the same changes
to both of the V5 Beta 4 files.
To ensure interoperability between V5 Beta 4 and V5-1.0, the
checksum and encryption types must be synchronized. So, you need to
ensure that the[libdefaults] section of the /etc/krb5.conf file
is correct, as follows:
If using an HP DCE KDC, the following entries must be in
the[libdefaults] section of the /etc/krb5.conf file:
kdc_req_checksum_type = 2
ccache_type = 2
If using a non-HP DCE V5 Beta 4 KDC, the following entries must
be in the[libdefaults] section of the /etc/krb5.conf file:
checksum_type = 1
default_tgs_enctypes = des-cbc-crc
default_tkt_enctypes = des-cbc-crc
ccache_type = 2