krb5_auth_rules(7) 맨 페이지 - 윈디하나의 솔라나라

개요

섹션
맨 페이지 이름
검색(S)

krb5_auth_rules(7)

krb5_auth_rules(7)    Standards, Environments, and Macros   krb5_auth_rules(7)

NAME
       krb5_auth_rules - overview of Kerberos V5 authorization

DESCRIPTION
       When  kerberized versions of the ftp, rcp, rlogin, rsh, ssh, telnet, or
       ssh clients are used to connect to a server, the identity of the origi‐
       nating user must be authenticated to  the  Kerberos  V5  authentication
       system.  Account  access  can then be authorized if appropriate entries
       exist in the ~/.k5login file, the gsscred  table,  or  if  the  default
       GSS/Kerberos authentication rules successfully map the Kerberos princi‐
       pal name to Unix login name.


       To  avoid  security  problems, the ~/.k5login file must be owned by the
       remote user on the server the client is attempting to access. The  file
       should contain a private authorization list comprised of Kerberos prin‐
       cipal  names of the form principal/instance@ realm. The /instance vari‐
       able is optional in Kerberos principal names.  For  example,  different
       principal  names  such  as  jdb@ENG.EXAMPLE.COM and jdb/happy.eng.exam‐
       ple.com@ENG.EXAMPLE.COM would each be  legal,  though  not  equivalent,
       Kerberos  principals.  The  client  is granted access if the ~/.k5login
       file is located in the login directory of the remote user  account  and
       if  the  originating user can be authenticated to one of the principals
       named in the file. See kadm5.acl(5) for more  information  on  Kerberos
       principal names.


       When  no  ~/.k5login  file is found in the remote user's login account,
       the Kerberos V5 principal name associated with the originating user  is
       checked  against  the  gsscred table. If a gsscred table exists and the
       principal name is matched in the table, access is granted if  the  Unix
       user  ID listed in the table corresponds to the user account the client
       is attempting to access. If the Unix user ID does not match, access  is
       denied. See gsscred(8).


       For  example,  an originating user listed in the gsscred table with the
       principal name jdb@ENG.EXAMPLE.COM and the uid  23154 is granted access
       to the jdb-user account if 23154 is also the uid of jdb-user listed  in
       the user account database. See passwd(5).


       Finally, if there is no ~/.k5login file and the Kerberos V5 identity of
       the originating user is not in the gsscred table, or if the gsscred ta‐
       ble  does  not exist, the client is granted access to the account under
       the following conditions (default GSS/Kerberos auth rules):

           o      The user part of the authenticated  principal  name  is  the
                  same as the Unix account name specified by the client.


           o      The realm part of the client and server are the same, unless
                  the  krb5.conf(5)   auth_to_local_realm parameter is used to
                  create equivalence.


           o      The Unix account name exists on the server.



       For example, if the originating user has the principal name jdb@ENG.EX‐
       AMPLE.COM and if the server is in realm SALES.EXAMPLE.COM,  the  client
       would  be  denied  access  even  if  jdb is a valid account name on the
       server. This is because  the  realms  SALES.EXAMPLE.COM  and  ENG.EXAM‐
       PLE.COM differ.


       The krb5.conf(5)  auth_to_local_realm parameter also affects authoriza‐
       tion.  Non-default realms can be equated with the default realm for au‐
       thenticated name-to-local name mapping.

FILES
       ~/.k5login     Per user-account authorization file.


       /etc/passwd    System account file. This information may also be  in  a
                      directory service. See passwd(5).



ATTRIBUTES
       See attributes(7) for descriptions of the following attributes:

       box; cbp-1 | cbp-1 l | l .  ATTRIBUTE TYPE ATTRIBUTE VALUE = Availabil‐
       ity   security/kerberos-5 = Stability Pass-through committed

SEE ALSO
       ftp(1),   rcp(1),   rsh(1),   telnet(1)   kadm5.acl(5),   krb5.conf(5),
       passwd(5), attributes(7), gss_auth_rules(7), gsscred(8),



NOTES
       Source code for open source software components in Oracle  Solaris  can
       be found at https://www.oracle.com/downloads/opensource/solaris-source-
       code-downloads.html.

       This software was built from source available at:
       https://github.com/oracle/solaris-userland

       The original community source was downloaded from:
       http://web.mit.edu/kerberos/dist/krb5/1.20/krb5-1.20.2.tar.gz

       Further information about this software can be found on the open source
       community website at http://web.mit.edu/kerberos/.

Solaris 11.4                      21 Jun 2021               krb5_auth_rules(7)
맨 페이지 내용의 저작권은 맨 페이지 작성자에게 있습니다.
RSS ATOM XHTML 5 CSS3