xref: /netbsd-src/crypto/external/bsd/heimdal/dist/lib/krb5/kerberos.8 (revision d3273b5b76f5afaafe308cead5511dbb8df8c5e9)
1*d3273b5bSchristos.\"	$NetBSD: kerberos.8,v 1.2 2017/01/28 21:31:49 christos Exp $
2ca1c9b0cSelric.\"
3ca1c9b0cSelric.\" Copyright (c) 2000 Kungliga Tekniska Högskolan
4ca1c9b0cSelric.\" (Royal Institute of Technology, Stockholm, Sweden).
5ca1c9b0cSelric.\" All rights reserved.
6ca1c9b0cSelric.\"
7ca1c9b0cSelric.\" Redistribution and use in source and binary forms, with or without
8ca1c9b0cSelric.\" modification, are permitted provided that the following conditions
9ca1c9b0cSelric.\" are met:
10ca1c9b0cSelric.\"
11ca1c9b0cSelric.\" 1. Redistributions of source code must retain the above copyright
12ca1c9b0cSelric.\"    notice, this list of conditions and the following disclaimer.
13ca1c9b0cSelric.\"
14ca1c9b0cSelric.\" 2. Redistributions in binary form must reproduce the above copyright
15ca1c9b0cSelric.\"    notice, this list of conditions and the following disclaimer in the
16ca1c9b0cSelric.\"    documentation and/or other materials provided with the distribution.
17ca1c9b0cSelric.\"
18ca1c9b0cSelric.\" 3. Neither the name of the Institute nor the names of its contributors
19ca1c9b0cSelric.\"    may be used to endorse or promote products derived from this software
20ca1c9b0cSelric.\"    without specific prior written permission.
21ca1c9b0cSelric.\"
22ca1c9b0cSelric.\" THIS SOFTWARE IS PROVIDED BY THE INSTITUTE AND CONTRIBUTORS ``AS IS'' AND
23ca1c9b0cSelric.\" ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
24ca1c9b0cSelric.\" IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
25ca1c9b0cSelric.\" ARE DISCLAIMED.  IN NO EVENT SHALL THE INSTITUTE OR CONTRIBUTORS BE LIABLE
26ca1c9b0cSelric.\" FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
27ca1c9b0cSelric.\" DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
28ca1c9b0cSelric.\" OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
29ca1c9b0cSelric.\" HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
30ca1c9b0cSelric.\" LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
31ca1c9b0cSelric.\" OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
32ca1c9b0cSelric.\" SUCH DAMAGE.
33ca1c9b0cSelric.\"
34b40995a4Selric.\" Id
35ca1c9b0cSelric.\"
36b9d004c6Schristos.Dd Jun 27, 2013
37ca1c9b0cSelric.Dt KERBEROS 8
38ca1c9b0cSelric.Os
39ca1c9b0cSelric.Sh NAME
40ca1c9b0cSelric.Nm kerberos
41ca1c9b0cSelric.Nd introduction to the Kerberos system
42ca1c9b0cSelric.Sh DESCRIPTION
43ca1c9b0cSelricKerberos is a network authentication system. Its purpose is to
44ca1c9b0cSelricsecurely authenticate users and services in an insecure network
45ca1c9b0cSelricenvironment.
46ca1c9b0cSelric.Pp
47ca1c9b0cSelricThis is done with a Kerberos server acting as a trusted third party,
48ca1c9b0cSelrickeeping a database with secret keys for all users and services
49ca1c9b0cSelric(collectively called
50ca1c9b0cSelric.Em principals ) .
51ca1c9b0cSelric.Pp
52ca1c9b0cSelricEach principal belongs to exactly one
53ca1c9b0cSelric.Em realm ,
54ca1c9b0cSelricwhich is the administrative domain in Kerberos. A realm usually
55ca1c9b0cSelriccorresponds to an organisation, and the realm should normally be
56ca1c9b0cSelricderived from that organisation's domain name. A realm is served by one
57ca1c9b0cSelricor more Kerberos servers.
58ca1c9b0cSelric.Pp
59ca1c9b0cSelricThe authentication process involves exchange of
60ca1c9b0cSelric.Sq tickets
61ca1c9b0cSelricand
62ca1c9b0cSelric.Sq authenticators
63ca1c9b0cSelricwhich together prove the principal's identity.
64ca1c9b0cSelric.Pp
65ca1c9b0cSelricWhen you login to the Kerberos system, either through the normal
66ca1c9b0cSelricsystem login or with the
67ca1c9b0cSelric.Xr kinit 1
68ca1c9b0cSelricprogram, you acquire a
69ca1c9b0cSelric.Em ticket granting ticket
70ca1c9b0cSelricwhich allows you to get new tickets for other services, such as
71ca1c9b0cSelric.Ic telnet
72ca1c9b0cSelricor
73ca1c9b0cSelric.Ic ftp ,
74ca1c9b0cSelricwithout giving your password.
75ca1c9b0cSelric.Pp
76ca1c9b0cSelricFor more information on how Kerberos works, and other general Kerberos
77ca1c9b0cSelricquestions see the Kerberos FAQ at
78b9d004c6Schristos.Lk http://www.cmf.nrl.navy.mil/krb/kerberos-faq.html .
79ca1c9b0cSelric.Pp
80ca1c9b0cSelricFor setup instructions see the Heimdal Texinfo manual.
81ca1c9b0cSelric.Sh SEE ALSO
82ca1c9b0cSelric.Xr ftp 1 ,
83ca1c9b0cSelric.Xr kdestroy 1 ,
84ca1c9b0cSelric.Xr kinit 1 ,
85ca1c9b0cSelric.Xr klist 1 ,
86ca1c9b0cSelric.Xr kpasswd 1 ,
87b9d004c6Schristos.Xr telnet 1 ,
88b9d004c6Schristos.Xr krb5 3 ,
89b9d004c6Schristos.Xr krb5.conf 5 ,
90b9d004c6Schristos.Xr kadmin 1 ,
91b9d004c6Schristos.Xr kdc 8 ,
92b9d004c6Schristos.Xr ktutil 1
93ca1c9b0cSelric.Sh HISTORY
94ca1c9b0cSelricThe Kerberos authentication system was developed in the late 1980's as
95ca1c9b0cSelricpart of the Athena Project at the Massachusetts Institute of
96ca1c9b0cSelricTechnology. Versions one through three never reached outside MIT, but
97ca1c9b0cSelricversion 4 was (and still is) quite popular, especially in the academic
98ca1c9b0cSelriccommunity, but is also used in commercial products like the AFS
99ca1c9b0cSelricfilesystem.
100ca1c9b0cSelric.Pp
101ca1c9b0cSelricThe problems with version 4 are that it has many limitations, the code
102ca1c9b0cSelricwas not too well written (since it had been developed over a long
103ca1c9b0cSelrictime), and it has a number of known security problems. To resolve many
104ca1c9b0cSelricof these issues work on version five started, and resulted in IETF RFC
105ca1c9b0cSelric1510 in 1993. IETF RFC 1510 was obsoleted in 2005 with IETF RFC 4120,
106ca1c9b0cSelricalso known as Kerberos clarifications. With the arrival of IETF RFC
107ca1c9b0cSelric4120, the work on adding extensibility and internationalization have
108ca1c9b0cSelricstarted (Kerberos extensions), and a new RFC will hopefully appear
109ca1c9b0cSelricsoon.
110ca1c9b0cSelric.Pp
111ca1c9b0cSelricThis manual page is part of the
112ca1c9b0cSelric.Nm Heimdal
113ca1c9b0cSelricKerberos 5 distribution, which has been in development at the Royal
114ca1c9b0cSelricInstitute of Technology in Stockholm, Sweden, since about 1997.
115