
84 MergePoint 5224/5240 Service Processor Manager Installer and Administrator Guide
When the administrative user configures an authentication server on this page, the server is
available to perform authentication checking for logins to the following:
• Any target devices that are configured to use that authentication method. See Configuring
Target Devices on page 79 for how devices are assigned an authentication method.
• The SP manager, if the SP manager is subsequently configured to use that authentication
method. See Configuring an Authentication Method for the MergePoint 5224/5240 SP
Manager on page 90 for how the SP manager is assigned an authentication method.
Configuring a Kerberos authentication server
By selecting the Config - Authentication menu option and selecting Kerberos from the
Authentication Type pull
-down menu, the administrative user can configure a Kerberos
authentication server. Configure an authentication server when the SP manager or any of its target
devices is configured to use the Kerberos authentication method or any of its variations (Kerberos,
Local ⁄ Kerberos, Kerberos/Local or Kerberos Down/Local).
If the Kerberos authentication server (which is also referred to as a Key Distribution Center, or
KDC) has previously been configured in either of the authentication configuration screens, the
fields are filled in with the previously configured values.
Before configuring a Kerberos server, the administrative user must obtain from the server’s
administrator the Kerberos Realm Domain Name and the Kerberos Server IP address.
CAUTION: The Kerberos KDC rejects tickets when the timestamp on an authentication request from a host is
not within the maximum clock skew time specified in the KDC’s hdc.conf file. Therefore, it is essential for the time
on the SP manager to be synchronized with the time on the KDC.
Also, work with the Kerberos server’s administrator to ensure that following types of accounts are
set up on the Kerberos server and that the administrators of the SP manager and target devices
know the passwords assigned to the accounts:
• An account for admin or other administrative user
• If Kerberos authentication is specified for the SP manager, accounts for all users who need to
log into the SP manager to administer target devices
• If Kerberos authentication is specified for devices, accounts for users who need access to
target devices
To configure a Kerberos authentication server:
1. Make sure entries for the appliance and the Kerberos server exist in the SP manager’s
/etc/hosts file.
a. Select the Network
- Host Table menu option. The Host Table form appears.
b. Add an entry for appliance (if needed) and add an entry for the Kerberos server.
2. Make sure that timezone and time and date settings are synchronized between the SP manager
and on the Kerberos server.
Komentáře k této Příručce