Rules and Procedures for Using Special Kerberos Principals
|
Sharing the password for a
Kerberos principal is a policy violation (see Important!
Please Read!). Shared or group
access accounts are usually best handled by a local user account
with .k5login or .k5user files to control
account access (see 9.3 Account
Access by Multiple Users)
from a specific list of Kerberos principals. These Special Principals
are for authenticating automated processes that are not initiated by
the super-user (root) account. Frequently these automated processes run
on remote systems or under other accounts on the local system and can
use the Special Principal in a .k5login or .k5user file to control this access. Requesting a Special Kerberos Principal When the shared access account method discussed above is not adequate, a Special Kerberos Principal may need to be requested. Special Kerberos Principals are named with muliple fields separated by slashes ("/") similar to the per-user /cron principals setup by kcroninit (see 10.3.1 Specific-User Processes (cron jobs) in the Strong Authentication Guide. Some discussion about one type of Special Kerberos Principals can be found in section 10.3.3 Non-root, Non-specific-user Processes in the Strong Authentication Guide. Commonly, Special Principals are used for behind-the-scenes access (like by web servers) to helper accounts or to remote computer systems. Examples of some Special Principals used for these situations: enstore/cd/stkenmvr31a.fnal.gov@FNAL.GOV
postgress/nimisrva.fnal.gov@FNAL.GOV lsf/fsui03.fnal.gov@FNAL.GOV Requests for Special Kerberos Principals should be made to the HelpDesk. The request should include an explanation of how this Principal will be used and the special local user accounts to be using the Principal. In particular, an explanation of why the standard shared access account method is inadequate will speed the approval process. If necessary, the HelpDesk will forward the request on to the Computer Security Team for approval before the Principal is created. |
|
For assistance contact helpdesk@fnal.gov.
Information compiled and maintained by Computer Security Team ; last modified by TR on July 13, 2006. (Address comments about page to the Computer Security Team.) |