Table of Contents (exploded view)
Abstract for z/OS Integrated Security Services Network Authentication Service Administration
Summary of changes made in z/OS Version 2 Release 2
z/OS Version 2 Release 1 summary of changes
Guide
Introducing Network Authentication Service
Overview
Supported RFCs
Authentication
Realms
Principals
Registry database types: SAF or NDBM
Encryption types and strong encryption
Application programming interfaces
Configuring Network Authentication Service
Making the program operational
Configuration of Public Key Cryptography for initial authentication (PKINIT)
Configuration of encryption types
Security runtime configuration with LDAP and DNS considerations
LDAP schema definitions
Security server configuration
Configuring the primary security server for the realm
Configuring a secondary security server for the realm
Using a SAF registry database
Using an NDBM registry database
Security runtime environment variables
Security server environment variables
Security runtime configuration profile
Configuration profile file sections
[libdefaults] section
[realms] section
[domain realm] section
[capaths] section
Sample /etc/skrb/krb5.conf configuration file
Administering Network Authentication Service
Adding principals
Local principals
Foreign principals
Principal names
Realm trust relationships
Peer trust
Transitive trust
Passwords
Cache files
Audit
KDC error codes
Security server operator commands
F SKRBKDC,parameters
MODIFY SKRBKDC,parameters
CTRACE debugging utility
P SKRBKDC
STOP SKRBKDC
Kerberos administration server
Administration privileges
Administration RPC functions
Kerberos database propagation
Setting up a secondary KDC
Moving the primary KDC to another system
Interoperability with MIT Kerberos
RACF and z/OS Integrated Security Services Network Authentication Service
Customizing your local environment
Defining your local RRSF node
Defining your local realm
Example of defining the local realm
Defining local principals
Generating keys for local principals
System considerations for key generation
Methods for generating keys
Automatic local principal name mapping
Considerations for local principal names
Customizing your foreign environment
Defining foreign realms
Mapping foreign principal names
Example of mapping foreign principal names
Reference
Commands
kadmin
Format
Options
Usage
Subcommands
kdb5_ndbm
Format
Options
Usage
kdestroy
Format
Options
Usage
Examples
keytab
Format
Options
Usage
Examples
kinit
Format
Options
Usage
Examples
klist
Format
Options
Usage
Examples
kpasswd
Format
Options
Usage
kpropd
Format
Options
Usage
ksetup
Format
Options
Usage
kvno
Format
Options
Status codes
Major status values
Kerberos administration database (numbers 01B79C00 - 01B79CFF)
01B79C01
01B79C02
01B79C03
01B79C04
01B79C05
01B79C06
01B79C07
01B79C08
01B79C09
01B79C0A
01B79C0B
01B79C0C
01B79C0D
GSS-API Kerberos mechanism codes (numbers 025EA100 - 025EA1FF)
025EA100
025EA101
025EA102
025EA104
025EA105
025EA106
025EA107
025EA108
025EA109
025EA10B
025EA140
025EA141
025EA142
025EA143
025EA144
025EA145
025EA146
025EA147
025EA148
025EA149
025EA14A
025EA14B
GSS-API LIPKEY/SPKM mechanism codes (numbers 025EA160-025EA18F)
025EA160
025EA161
025EA162
025EA163
025EA164
025EA165
025EA166
025EA167
025EA168
025EA169
025EA16A
025EA16B
025EA16C
025EA16D
025EA16E
025EA16F
025EA170
025EA171
025EA172
025EA173
025EA174
025EA175
025EA176
025EA177
025EA178
025EA179
025EA17A
025EA17B
025EA17C
025EA17D
025EA17E
025EA17F
Kerberos administration codes (numbers 029C2500 - 029C25FF)
029C2500
029C2501
029C2502
029C2503
029C2504
029C2505
029C2506
029C2507
029C2508
029C2509
029C250A
029C250B
029C250C
029C250D
029C250E
029C250F
029C2510
029C2511
029C2512
029C2513
029C2514
029C2515
029C2516
029C2517
029C2518
029C2519
029C251A
029C251B
029C251C
029C251D
029C251E
029C251F
029C2520
029C2521
029C2522
029C2523
029C2524
029C2525
029C2526
029C2527
029C2528
029C2529
029C252A
029C252B
029C252C
029C252D
029C252E
029C252F
029C2530
029C2531
029C2532
029C2533
029C2535
029C25F0
029C25F1
029C25F2
029C25F3
029C25F4
029C25F5
029C25F6
029C25F7
ASN.1 operations codes (numbers 6EDA3600 - 6EDA36FF)
6EDA3600
6EDA3601
6EDA3602
6EDA3603
6EDA3604
6EDA3605
6EDA3606
6EDA3607
6EDA3608
6EDA3609
6EDA360A
6EDA360B
6EDA360C
GSS-API codes (numbers 861B6D00 - 861B6DFF)
861B6D00
861B6D01
861B6D02
861B6D03
861B6D04
861B6D05
861B6D06
861B6D07
861B6D08
861B6D0A
861B6D0B
861B6D0C
861B6D51
861B6D52
861B6D53
861B6D54
861B6D55
861B6D56
861B6D57
861B6D58
861B6D59
861B6D5A
861B6D5B
861B6D5C
861B6D5D
861B6D5E
861B6D5F
861B6D60
861B6D61
861B6D62
861B6D63
Kerberos database (numbers 95E73A00 - 95E73AFF)
95E73A01
95E73A02
95E73A03
95E73A04
95E73A05
95E73A06
95E73A07
95E73A08
95E73A09
95E73A0A
95E73A0B
95E73A0C
95E73A0D
95E73A0E
95E73A0F
95E73A10
95E73A11
95E73A12
95E73A13
95E73A14
95E73A15
95E73A16
95E73A17
95E73A18
95E73A19
95E73A1A
95E73AF0
95E73AF1
95E73AF2
95E73AF3
95E73AF4
95E73AF5
Kerberos runtime codes (numbers 96C73A00 - 96C73CFF)
96C73A01
96C73A02
96C73A03
96C73A04
96C73A05
96C73A06
96C73A07
96C73A08
96C73A09
96C73A0A
96C73A0B
96C73A0C
96C73A0D
96C73A0E
96C73A0F
96C73A10
96C73A11
96C73A12
96C73A13
96C73A14
96C73A15
96C73A16
96C73A17
96C73A18
96C73A19
96C73A1A
96C73A1B
96C73A1C
96C73A1D
96C73A1F
96C73A20
96C73A21
96C73A22
96C73A23
96C73A24
96C73A25
96C73A26
96C73A27
96C73A28
96C73A29
96C73A2A
96C73A2B
96C73A2C
96C73A2D
96C73A2E
96C73A2F
96C73A30
96C73A31
96C73A32
96C73A33
96C73A34
96C73A3C
96C73A3D
96C73A3E
96C73A3F
96C73A40
96C73A41
96C73A46
96C73A47
96C73A48
96C73A49
96C73A4B
96C73A4C
96C73A4D
96C73A4E
96C73A4F
96C73A50
96C73A51
96C73A81
96C73A82
96C73A83
96C73A84
96C73A85
96C73A86
96C73A87
96C73A88
96C73A89
96C73A8A
96C73A8B
96C73A8C
96C73A8D
96C73A8E
96C73A8F
96C73A90
96C73A91
96C73A92
96C73A93
96C73A94
96C73A95
96C73A96
96C73A97
96C73A98
96C73A99
96C73A9A
96C73A9B
96C73A9C
96C73A9D
96C73A9E
96C73A9F
96C73AA0
96C73AA1
96C73AA2
96C73AA3
96C73AA4
96C73AA7
96C73AA8
96C73AA9
96C73AAA
96C73AAB
96C73AAC
96C73AB2
96C73AB3
96C73AB4
96C73AB5
96C73AB6
96C73AB7
96C73AB8
96C73AB9
96C73ABA
96C73ABB
96C73ABC
96C73ABD
96C73ABE
96C73ABF
96C73AC0
96C73AC1
96C73AC2
96C73AC3
96C73AC4
96C73AC5
96C73AC6
96C73AC7
96C73AC8
96C73AC9
96C73ACA
96C73ACB
96C73ACC
96C73ACD
96C73ACE
96C73ACF
96C73AD0
96C73AD1
96C73AD2
96C73AD3
96C73AD4
96C73AD5
96C73AD6
96C73AD7
96C73AD8
96C73AD9
96C73ADA
96C73ADB
96C73ADC
96C73ADD
96C73ADE
96C73ADF
96C73AE1
96C73C00
96C73C01
96C73C02
96C73C03
96C73C04
96C73C05
96C73C06
96C73C07
96C73C08
96C73C09
96C73C0A
96C73C0B
96C73C0C
96C73C0D
96C73C0E
96C73C0F
96C73C10
96C73C11
96C73C12
96C73C13
96C73C14
96C73C15
96C73C16
96C73C17
96C73C1B
96C73C1C
96C73C1D
96C73C1E
96C73C1F
96C73C20
96C73C21
96C73C22
96C73C23
96C73C24
96C73C25
96C73C26
96C73C27
96C73C28
96C73C29
96C73C2A
96C73C2B
96C73C2C
96C73C2D
Profile operations codes (numbers AACA6000 - AACA60FF)
AACA6002
AACA6003
AACA6004
AACA6005
AACA6009
AACA600A
AACA600B
AACA600C
AACA600D
AACA6013
AACA6014
Messages
Kerberos runtime messages (numbers EUVF02000 - EUVF03999)
EUVF02001E
EUVF02002E
EUVF02003E
EUVF02004E
EUVF02005E
EUVF02006E
EUVF02007E
EUVF02008E
EUVF02009E
EUVF02010E
EUVF02011E
EUVF02012E
EUVF02013E
EUVF02014E
EUVF02015E
EUVF02016E
EUVF02017E
EUVF02018E
EUVF02019E
EUVF02020E
EUVF02021E
EUVF02022I
EUVF02023W
EUVF02024W
EUVF02025W
EUVF02026W
EUVF02027E
EUVF02028E
EUVF02029E
EUVF02030E
EUVF02031E
EUVF02032E
EUVF02033R
EUVF02034E
EUVF02035E
EUVF02036I
EUVF02037I
EUVF02038I
EUVF02039E
EUVF02040E
EUVF02041E
EUVF02042E
EUVF02043E
EUVF02044I
Security server messages (numbers EUVF04000 - EUVF05999)
EUVF04001I
EUVF04002I
EUVF04003A
EUVF04004E
EUVF04005E
EUVF04006I
EUVF04007E
EUVF04008I
EUVF04009E
EUVF04010A
EUVF04011E
EUVF04012E
EUVF04013E
EUVF04014E
EUVF04015E
EUVF04016E
EUVF04017A
EUVF04018I
EUVF04019A
EUVF04020A
EUVF04021A
EUVF04022I
EUVF04023I
EUVF04024E
EUVF04025E
EUVF04026E
EUVF04027E
EUVF04028E
EUVF04029E
EUVF04030E
EUVF04031E
EUVF04032E
EUVF04033E
EUVF04034E
EUVF04035E
EUVF04036E
EUVF04037E
EUVF04038I
EUVF04039W
EUVF04040E
EUVF04041E
EUVF04042E
EUVF04043E
EUVF04044E
EUVF04046E
EUVF04047E
EUVF04048E
EUVF04049E
EUVF04050E
EUVF04051E
EUVF04052E
EUVF04053E
EUVF04054E
EUVF04055E
EUVF04056E
EUVF04057E
EUVF04058I
EUVF04059I
EUVF04060I
EUVF04061E
EUVF04062A
EUVF04063E
EUVF04064I
EUVF04065I
EUVF04066I
EUVF04067I
EUVF04068I
EUVF04069I
EUVF04070I
EUVF04071E
EUVF04072I
EUVF04073I
EUVF04074E
EUVF04075E
EUVF04076E
EUVF04077E
EUVF04078E
EUVF04079E
EUVF04080E
EUVF04081E
EUVF04082E
EUVF04083E
EUVF04084E
EUVF04085I
EUVF04086E
EUVF04087E
EUVF04088E
EUVF04089E
EUVF04090E
EUVF04091R
EUVF04092R
EUVF04093E
EUVF04094E
EUVF04095I
EUVF04096E
EUVF04097E
EUVF04098I
EUVF04099I
EUVF04100E
EUVF04101E
EUVF04102I
EUVF04103E
EUVF04104I
EUVF04105E
EUVF04106R
EUVF04107R
EUVF04108E
EUVF04109E
EUVF04110E
EUVF04111E
EUVF04112E
EUVF04113E
EUVF04114E
EUVF04115W
EUVF04116E
EUVF04117E
EUVF04118E
EUVF04119E
EUVF04120E
EUVF04121E
EUVF04122E
EUVF04123E
EUVF04124E
EUVF04125E
EUVF04126E
EUVF04127E
EUVF04128E
EUVF04129E
EUVF04130E
EUVF04131I
EUVF04132I
EUVF04133E
EUVF04134E
EUVF04135I
EUVF04136E
EUVF04137E
EUVF04138E
EUVF04139E
EUVF04140I
EUVF04141I
EUVF04142I
EUVF04143E
EUVF04144E
EUVF04145I
EUVF04146I
EUVF04147I
EUVF04148I
EUVF04149R
EUVF04150I
EUVF04151I
EUVF04152I
EUVF04153W
EUVF04154E
EUVF04155E
EUVF04156E
EUVF04157E
EUVF04158I
EUVF04159I
EUVF04160E
EUVF04163E
EUVF04164E
EUVF04165E
Messages for Kerberos commands (numbers EUVF06000 - EUVF06999)
EUVF06001E
EUVF06002E
EUVF06003E
EUVF06004I
EUVF06005E
EUVF06006E
EUVF06007E
EUVF06008E
EUVF06009E
EUVF06010E
EUVF06011E
EUVF06012E
EUVF06013E
EUVF06014E
EUVF06015E
EUVF06016E
EUVF06017R
EUVF06018E
EUVF06019E
EUVF06020I
EUVF06021E
EUVF06022E
EUVF06023E
EUVF06024E
EUVF06025E
EUVF06026E
EUVF06027E
EUVF06028E
EUVF06029E
EUVF06030I
EUVF06031E
EUVF06032E
EUVF06033E
EUVF06034I
EUVF06035E
EUVF06036E
EUVF06037E
EUVF06039E
EUVF06041E
EUVF06042E
EUVF06043E
EUVF06044E
EUVF06045E
EUVF06046E
EUVF06047E
EUVF06048R
EUVF06049R
EUVF06050E
EUVF06051E
EUVF06052E
EUVF06053E
EUVF06054E
EUVF06055I
EUVF06056E
EUVF06057I
EUVF06058E
EUVF06059E
EUVF06060E
EUVF06061E
EUVF06062E
EUVF06063E
EUVF06064E
EUVF06065E
EUVF06066E
EUVF06067E
EUVF06068E
EUVF06069E
EUVF06070E
EUVF06071E
EUVF06072E
EUVF06073E
EUVF06074E
EUVF06075E
EUVF06076E
EUVF06077E
EUVF06078E
EUVF06079E
EUVF06080E
EUVF06081E
EUVF06082E
EUVF06083I
EUVF06084R
EUVF06085R
EUVF06086R
EUVF06087E
EUVF06088E
EUVF06089E
EUVF06090E
EUVF06091E
EUVF06092E
EUVF06093I
EUVF06094I
EUVF06095E
EUVF06096I
EUVF06097E
EUVF06098I
EUVF06099I
EUVF06100E
EUVF06101I
EUVF06102E
EUVF06103E
EUVF06104E
EUVF06105E
EUVF06106E
EUVF06107I
EUVF06108E
EUVF06109E
EUVF06110I
EUVF06111E
EUVF06112I
EUVF06113E
EUVF06114E
EUVF06115E
EUVF06116R
EUVF06117R
EUVF06118E
EUVF06119E
EUVF06120I
EUVF06121I
EUVF06122I
EUVF06123I
EUVF06124I
EUVF06125I
EUVF06126I
EUVF06127I
EUVF06128I
EUVF06129E
EUVF06130I
EUVF06131I
EUVF06132I
EUVF06133I
EUVF06134E
EUVF06135I
EUVF06136I
EUVF06137I
EUVF06138I
EUVF06139I
EUVF06140I
EUVF06141I
EUVF06142I
EUVF06143I
EUVF06144I
EUVF06145E
EUVF06146E
EUVF06147I
EUVF06148I
EUVF06149E
EUVF06150E
EUVF06151E
EUVF06152E
EUVF06153E
EUVF06154I
EUVF06155E
EUVF06156E
EUVF06157E
EUVF06158E
EUVF06159E
EUVF06160E
EUVF06161E
EUVF06162E
EUVF06163E
EUVF06164E
EUVF06165E
EUVF06166E
EUVF06167W
EUVF06168E
EUVF06169E
EUVF06170E
Component Trace
Capturing Component Trace Data
Displaying the Trace Data
Sample Kerberos configurations
KRB390.IBM.COM configuration
KRB2003.IBM.COM configuration
MITKRB.IBM.COM configuration