Aller au contenu

ADDKRBTKT

Ajouter ticket Kerberos

Add Kerberos Ticket

En bref

La commande Ajouter un ticket Kerberos (ADDKRBTKT) permet d'obtenir et de mettre en cache des tickets d'octroi de tickets Kerberos. The Add Kerberos Ticket (ADDKRBTKT) command is used to obtain and cache Kerberos ticket-granting tickets.

ADDKRBTKT se lit ADD (Ajouter) + KRBTKT. Sur IBM i, le nom d'une commande associe presque toujours un verbe et un objet.

Syntaxe minimale

ADDKRBTKT PRINCIPAL(…)

Paramètres

  • PRINCIPAL Principal obligatoire
  • PASSWORD Mot de passe
  • KEYTABFILE Fichier de table de clés Keytab file
  • CCF Fichier de cache des données d'identification Credentials cache file
  • ALWFWD Autoriser le transfert Allow forwarding
  • ALWPRX Autoriser le proxy Allow proxy

Astuce : dans une session 5250, tapez ADDKRBTKT puis F4 pour l'invite de saisie, et F1 sur un paramètre pour son aide.

Aide IBM i de la commande

Texte du F1, IBM i 7.5 en français (bibliothèque QSYS)

Où s'exécute : Tous les environnements (*ALL)
Compatible multitâche : Non

La commande Ajouter un ticket Kerberos (ADDKRBTKT) permet d'obtenir et de mettre en cache des tickets d'octroi de tickets Kerberos. Cette commande est similaire à l'outil kinit que l'on trouve couramment dans d'autres implémentations du protocole Kerberos, telles que les implémentations de référence SEAM et MIT. The Add Kerberos Ticket (ADDKRBTKT) command is used to obtain and cache Kerberos ticket-granting tickets. This command is similar to the kinit tool that is commonly found in other implementations of the Kerberos protocol, such as the SEAM and MIT Reference implementations.

Restrictions:

  • The user must be registered as a principal with the Key Distribution Center (KDC) prior to running this command.

    Les commandes et API du service d'authentification réseau prennent en charge les environnements de travail pour la plupart des CCSID EBCDIC. Les CCSID 290 et 5026 ne sont pas pris en charge en raison de la variance des lettres minuscules a à z. The Network Authentication Service Commands and APIs support job environments for most EBCDIC CCSIDs. CCSID 290 and 5026 are not supported because of the variance of lower-case letters a to z.

Paramètres

Mot-clé Description Valeurs possibles Remarques
PRINCIPAL Principal Liste d'éléments Obligatoire, positionnel 1
Élément 1: Nom Valeur caractère
Élément 2: Realm Valeur caractère, *DFT
PASSWORD Mot de passe Valeur caractère Facultatif, positionnel 2
KEYTABFILE Fichier de table de clésKeytab file Chemin d'accès, *DFT Facultatif
CCF Fichier de cache des données d'identificationCredentials cache file Chemin d'accès, *DFT Facultatif
ALWFWD Autoriser le transfertAllow forwarding *NO, *YES Facultatif
ALWPRX Autoriser le proxyAllow proxy *NO, *YES Facultatif

Principal (PRINCIPAL)

Indique le nom de principal d'un utilisateur ou d'un principal de service sur un nom d'hôte dans un réseau Kerberos. Les paires principal/clé du fichier de table de clés permettent aux services s'exécutant sur l'hôte d'être authentifiés par un centre de distribution de clés (KDC). Tous les principaux sont ajoutés au serveur Kerberos, qui gère une base de données de tous les utilisateurs et services d'un domaine Kerberos. Specifies the principal name of a user or service principal on a host name in a Kerberos network. The principal and key pairs in the keytab file allow services running on the host to be authenticated by a Key Distribution Center (KDC). All the principals are added to the Kerberos server which maintains a database of all users and services within a Kerberos realm.

Ce paramètre est obligatoire. This is a required parameter.

Élément 1: Nom

Indique le nom de principal ou le principal de service sur un nom d'hôte donné. Specifies the principal name or service principal on a specified host name.

valeur-caractère
Specify the user name of the Kerberos principal.

Le principal Kerberos comporte de 1 à 256 caractères. Les caractères valides sont sensibles à la casse et comprennent tous les caractères alphanumériques (a-z, A-Z, 0-9) et tout caractère ASCII imprimable. Le format du nom de principal est tiré du mécanisme Kerberos 5 GSS-API (RFC 1964). The Kerberos principal has a minimum length of 1 character and a maximum length of 256 characters. Valid characters are case sensitive and include all alpha-numeric characters (a-z, A-Z, 0-9) and any printable ASCII character. The principal name format is taken from the Kerberos 5 GSS-API mechanism (RFC 1964).

Caractères spéciaux autorisés : Special characters allowed:

/ - delimit name components.

Élément 2: Realm

Indique le domaine (realm) dans lequel l'utilisateur Kerberos est enregistré et dans lequel l'authentification initiale a eu lieu. Specifies the realm in which the Kerberos user is registered and in which initial authentication took place.

*DFT
Le domaine par défaut du système local est utilisé. En général, le domaine par défaut et le KDC de ce domaine sont indiqués dans le fichier de configuration Kerberos krb5.conf. Si le domaine par défaut n'a pas été défini, il est obtenu à partir de l'entrée default_realm de la section [libdefaults] du fichier de configuration Kerberos. The default realm for the local system will be used. Typically, the default realm and the KDC for that realm are indicated in the Kerberos krb5.conf configuration file. If the default realm has not been set, it is obtained from the default_realm entry in the ¬libdefaults| section of the Kerberos configuration file.
valeur-caractère
Specify the name of the Kerberos realm where the user specified for the first element of this parameter is registered.

Le nom comporte de 1 à 256 caractères. Les caractères valides sont sensibles à la casse et comprennent tous les caractères alphanumériques (a-z, A-Z, 0-9) et tout caractère ASCII imprimable. Le format du nom de principal est tiré du mécanisme Kerberos 5 GSS-API (RFC 1964). The name has a minimum length of 1 character and a maximum length of 256 characters. Valid characters are case sensitive and include all alpha-numeric characters (a-z, A-Z, 0-9) and any printable ASCII character. The principal name format is taken from the Kerberos 5 GSS-API mechanism (RFC 1964).

Caractères spéciaux autorisés : Special characters allowed:

à - start realm.

Mot de passe (PASSWORD)

Indique le mot de passe qui permet au principal de s'authentifier auprès du centre de distribution de clés (KDC). Specifies the password that allows the principal to authenticate in the Key Distribution Center (KDC).

Ce paramètre est obligatoire si le nom du fichier de table de clés n'est pas défini. This is a required parameter if the keytab file name is not defined.

valeur-caractère
Indiquez la valeur du mot de passe. Le mot de passe peut comporter jusqu'à 255 caractères. Specify the password value. The password can be up to 255 characters long.

Fichier de table de clés (KEYTABFILE)Keytab file (KEYTABFILE)

Indique le fichier de table de clés (keytab) Kerberos dans lequel sont stockés le groupe de principaux et leurs clés. Specifies the Kerberos keytab file where the group of principals and its keys are stored.

*DFT
Le fichier de table de clés par défaut de l'utilisateur en cours est utilisé. Si la variable d'environnement KRB5_KTNAME est définie, il s'agit du nom du fichier de table de clés par défaut. Sinon, le nom du fichier de table de clés est obtenu à partir de l'entrée default_keytab_name de la section [libdefaults] du fichier de configuration Kerberos. Si cette entrée n'est pas définie, le nom du fichier de table de clés par défaut est /QIBM/UserData/OS400/NetworkAuthentication/keytab/krb5.keytab. The default keytab file for the current user will be used. If the KRB5_KTNAME environment variable is set, this is the name of the default keytab file. Otherwise, the keytab file name is obtained from the default_keytab_name entry in the ¬libdefaults| section of the Kerberos configuration file. If this entry is not defined, the default keytab file name is /QIBM/UserData/OS400/NetworkAuthentication/keytab/krb5.keytab.
chemin-d'accès
Indiquez le chemin d'accès du fichier STREAM qui contient le fichier de table de clés Kerberos à utiliser. Specify the path name of the stream file which contains the Kerberos keytab file to use.

Fichier de cache des données d'identification (CCF)Credentials cache file (CCF)

Indique le fichier de cache des données d'identification que cette commande utilise. Ce cache sert à stocker chacun des nouveaux tickets, la clé de session et d'autres informations de la séquence KrbCredInfo correspondante issue de la partie chiffrée du message KRB_CRED. Specifies the credentials cache file that this command will use. This cache is used to store each of the new tickets, the session key and other information in the corresponding KrbCredInfo sequence from the encrypted part of the KRB_CRED message.

*DFT
Le fichier de cache des données d'identification par défaut de l'utilisateur en cours est utilisé. Si la variable d'environnement KRB5CCNAME est définie, il s'agit du nom du cache par défaut. Sinon, le nom est obtenu à partir du fichier indiqué par la variable d'environnement _EUV_SEC_KRB5CCNAME_FILE. Si cette variable d'environnement n'est pas définie, le nom est obtenu à partir de krb5ccname dans le répertoire HOME. Si ce fichier n'existe pas ou si aucun nom de cache par défaut n'est défini dans le fichier, un nouveau fichier de cache des données d'identification est créé. The default credentials cache file for the current user is used. If the KRB5CCNAME environment variable is set, this is the name of the default cache. Otherwise, the name is obtained from the file specified by the _EUV_SEC_KRB5CCNAME_FILE environment variable. If this environment variable is not set, the name is obtained from the krb5ccname in the HOME directory. If this file does not exist or if there is no default credentials cache name set in the file, a new credentials cache file is created.
chemin-d'accès
Indiquez le chemin d'accès du fichier de cache des données d'identification à utiliser. Specify the path name of the credentials cache file to use.

Autoriser le transfert (ALWFWD)Allow forwarding (ALWFWD)

Indique si le ticket Kerberos peut être transféré. Specifies whether the Kerberos ticket will be forwardable.

L'indicateur FORWARDABLE d'un ticket n'est normalement interprété que par le service d'octroi de tickets. Il peut être ignoré par le serveur d'applications. The FORWARDABLE flag in a ticket is normally only interpreted by the ticket-granting service. It can be ignored by the application server.

L'indicateur FORWARDABLE a une interprétation similaire à celle de l'indicateur PROXIABLE, sauf que des tickets d'octroi de tickets peuvent également être émis avec des adresses réseau différentes. The FORWARDABLE flag has an interpretation similar to that of the PROXIABLE flag, except ticket-granting tickets may also be issued with different network addresses.

Cet indicateur permet le transfert d'authentification sans que l'utilisateur ait à saisir à nouveau un mot de passe. Si l'indicateur n'est pas activé, le transfert d'authentification n'est pas autorisé, mais le même résultat peut être obtenu si l'utilisateur effectue l'échange avec le serveur d'authentification avec les adresses réseau demandées et fournit un mot de passe. This flag allows for authentication forwarding without requiring the user to enter a password again. If the flag is not set, then authentication forwarding is not permitted, but the same end result can still be achieved if the user engages in the authentication server exchange with the requested network addresses and supplies a password.

*NO
Le ticket ne peut pas être transféré. The ticket will not be forwardable.
*YES
Le ticket peut être transféré. The ticket will be forwardable.

Autoriser le proxy (ALWPRX)Allow proxy (ALWPRX)

Indique si le ticket Kerberos est un ticket proxy (proxiable). Specifies whether the Kerberos ticket will be a proxiable ticket.

L'indicateur PROXIABLE d'un ticket n'est normalement interprété que par le service d'octroi de services. Il peut être ignoré par les serveurs d'applications. Lorsque ce paramètre a pour valeur *YES, le serveur d'octroi de tickets peut émettre, à partir de ce ticket, un nouveau ticket (mais pas un ticket d'octroi de tickets) avec une adresse réseau différente. The PROXIABLE flag in a ticket is normally only interpreted by the service-granting service. It can be ignored by application servers. When this parameter is set to *YES, the ticket-granting server can issue a new ticket (but not a ticket-granting ticket) with a different network address based on this ticket.

*NO
Le ticket n'est pas un ticket proxy. The ticket is not proxiable.
*YES
Le ticket est un ticket proxy. The ticket is proxiable.

Exemples

Exemple 1 : Ajout d'un ticket transférable Example 1: Adding a Forwardable Ticket

ADDKRBTKT   PRINCIPAL('krbsrv400/guada.lajara.com')
            PASSWORD('my1pwd')  ALWFWD(*YES)

Cette commande ajoute un ticket transférable à l'aide du principal 'krbsrv400/guada.lajara.com' et du domaine par défaut. This command adds a forwardable ticket using the 'krbsrv400/guada.lajara.com' principal and the default realm.

Exemple 2 : Ajout d'un ticket proxy Example 2: Adding a Proxiable Ticket

ADDKRBTKT   PRINCIPAL('krbsrv400/guada.lajara.com')
            PASSWORD('my1pwd')  ALWPRX(*YES)

Cette commande ajoute un ticket proxy à l'aide du principal 'krbsrv400/guada.lajara.com' et du domaine par défaut. This command adds a proxiable ticket using the :'krbsrv400/guada.lajara.com' principal and the default realm.

Exemple 3 : Ajout d'un ticket pour un domaine autre que le domaine par défaut Example 3: Adding a Ticket for Non-default Realm

ADDKRBTKT   PRINCIPAL('krbsrv400/guada.lajara.com'
                      'MEX.ICO.COM')
            PASSWORD('my1pwd')  ALWFWD(*YES)

Cette commande ajoute un ticket transférable à l'aide du principal de nom d'utilisateur 'krbsrv400/guada.lajara.com' et du domaine 'MEX.ICO.COM'. This command adds a forwardable ticket using the principal with user name 'krbsrv400/guada.lajara.com' and realm 'MEX.ICO.COM'.

Messages d'erreur

Messages *ESCAPE *ESCAPE Messages

CPFC602
Fichier de table de clés &3 introuvable. Keytab file &3 not found.
CPFC608
Le nom du fichier de cache des données d'identification par défaut ne peut pas être déterminé. The default credential cache file name cannot be determined.
CPFC609
Le principal du fichier de cache des données d'identification &1 ne peut pas être extrait. The principal from credential cache file &1 cannot be retrieved.
CPFC60A
Aucun ticket d'octroi de tickets (TGT) initial n'est disponible. No initial ticket granting ticket (TGT) available.
CPFC60B
Les données d'identification initiales ne peuvent pas être obtenues. The initial credentials cannot be obtained.
CPFC60C
Le ticket du cache des données d'identification &1 ne peut pas être extrait. The ticket from credentials cache &1 cannot be retrieved.
CPFC60E
Le mot de passe n'est pas correct pour le principal. Password is not correct for principal.
CPFC60F
Les données d'identification initiales ne peuvent pas être stockées dans le cache &1. Initial credential cannot be stored in credentials cache &1.
CPFC610
Aucun cache de données d'identification par défaut n'a été trouvé. No default credentials cache found.
CPFC611
L'opération sur le fichier de cache des données d'identification a échoué. Credentials cache file operation failed.
CPFC613
Le répertoire du cache des données d'identification ne peut pas être lu. The credentials cache directory cannot be read.
CPFC615
Le mot de passe ne peut pas être lu. The password cannot be read.
CPFC61B
Le nom de principal &3 ne peut pas être analysé. The principal name &3 cannot be parsed.

© Copyright IBM Corp. Texte d'aide reproduit à des fins de formation.