1*d3273b5bSchristos.\" $NetBSD: kerberos.8,v 1.2 2017/01/28 21:31:49 christos Exp $ 2ca1c9b0cSelric.\" 3ca1c9b0cSelric.\" Copyright (c) 2000 Kungliga Tekniska Högskolan 4ca1c9b0cSelric.\" (Royal Institute of Technology, Stockholm, Sweden). 5ca1c9b0cSelric.\" All rights reserved. 6ca1c9b0cSelric.\" 7ca1c9b0cSelric.\" Redistribution and use in source and binary forms, with or without 8ca1c9b0cSelric.\" modification, are permitted provided that the following conditions 9ca1c9b0cSelric.\" are met: 10ca1c9b0cSelric.\" 11ca1c9b0cSelric.\" 1. Redistributions of source code must retain the above copyright 12ca1c9b0cSelric.\" notice, this list of conditions and the following disclaimer. 13ca1c9b0cSelric.\" 14ca1c9b0cSelric.\" 2. Redistributions in binary form must reproduce the above copyright 15ca1c9b0cSelric.\" notice, this list of conditions and the following disclaimer in the 16ca1c9b0cSelric.\" documentation and/or other materials provided with the distribution. 17ca1c9b0cSelric.\" 18ca1c9b0cSelric.\" 3. Neither the name of the Institute nor the names of its contributors 19ca1c9b0cSelric.\" may be used to endorse or promote products derived from this software 20ca1c9b0cSelric.\" without specific prior written permission. 21ca1c9b0cSelric.\" 22ca1c9b0cSelric.\" THIS SOFTWARE IS PROVIDED BY THE INSTITUTE AND CONTRIBUTORS ``AS IS'' AND 23ca1c9b0cSelric.\" ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE 24ca1c9b0cSelric.\" IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE 25ca1c9b0cSelric.\" ARE DISCLAIMED. IN NO EVENT SHALL THE INSTITUTE OR CONTRIBUTORS BE LIABLE 26ca1c9b0cSelric.\" FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL 27ca1c9b0cSelric.\" DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS 28ca1c9b0cSelric.\" OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) 29ca1c9b0cSelric.\" HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT 30ca1c9b0cSelric.\" LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY 31ca1c9b0cSelric.\" OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF 32ca1c9b0cSelric.\" SUCH DAMAGE. 33ca1c9b0cSelric.\" 34b40995a4Selric.\" Id 35ca1c9b0cSelric.\" 36b9d004c6Schristos.Dd Jun 27, 2013 37ca1c9b0cSelric.Dt KERBEROS 8 38ca1c9b0cSelric.Os 39ca1c9b0cSelric.Sh NAME 40ca1c9b0cSelric.Nm kerberos 41ca1c9b0cSelric.Nd introduction to the Kerberos system 42ca1c9b0cSelric.Sh DESCRIPTION 43ca1c9b0cSelricKerberos is a network authentication system. Its purpose is to 44ca1c9b0cSelricsecurely authenticate users and services in an insecure network 45ca1c9b0cSelricenvironment. 46ca1c9b0cSelric.Pp 47ca1c9b0cSelricThis is done with a Kerberos server acting as a trusted third party, 48ca1c9b0cSelrickeeping a database with secret keys for all users and services 49ca1c9b0cSelric(collectively called 50ca1c9b0cSelric.Em principals ) . 51ca1c9b0cSelric.Pp 52ca1c9b0cSelricEach principal belongs to exactly one 53ca1c9b0cSelric.Em realm , 54ca1c9b0cSelricwhich is the administrative domain in Kerberos. A realm usually 55ca1c9b0cSelriccorresponds to an organisation, and the realm should normally be 56ca1c9b0cSelricderived from that organisation's domain name. A realm is served by one 57ca1c9b0cSelricor more Kerberos servers. 58ca1c9b0cSelric.Pp 59ca1c9b0cSelricThe authentication process involves exchange of 60ca1c9b0cSelric.Sq tickets 61ca1c9b0cSelricand 62ca1c9b0cSelric.Sq authenticators 63ca1c9b0cSelricwhich together prove the principal's identity. 64ca1c9b0cSelric.Pp 65ca1c9b0cSelricWhen you login to the Kerberos system, either through the normal 66ca1c9b0cSelricsystem login or with the 67ca1c9b0cSelric.Xr kinit 1 68ca1c9b0cSelricprogram, you acquire a 69ca1c9b0cSelric.Em ticket granting ticket 70ca1c9b0cSelricwhich allows you to get new tickets for other services, such as 71ca1c9b0cSelric.Ic telnet 72ca1c9b0cSelricor 73ca1c9b0cSelric.Ic ftp , 74ca1c9b0cSelricwithout giving your password. 75ca1c9b0cSelric.Pp 76ca1c9b0cSelricFor more information on how Kerberos works, and other general Kerberos 77ca1c9b0cSelricquestions see the Kerberos FAQ at 78b9d004c6Schristos.Lk http://www.cmf.nrl.navy.mil/krb/kerberos-faq.html . 79ca1c9b0cSelric.Pp 80ca1c9b0cSelricFor setup instructions see the Heimdal Texinfo manual. 81ca1c9b0cSelric.Sh SEE ALSO 82ca1c9b0cSelric.Xr ftp 1 , 83ca1c9b0cSelric.Xr kdestroy 1 , 84ca1c9b0cSelric.Xr kinit 1 , 85ca1c9b0cSelric.Xr klist 1 , 86ca1c9b0cSelric.Xr kpasswd 1 , 87b9d004c6Schristos.Xr telnet 1 , 88b9d004c6Schristos.Xr krb5 3 , 89b9d004c6Schristos.Xr krb5.conf 5 , 90b9d004c6Schristos.Xr kadmin 1 , 91b9d004c6Schristos.Xr kdc 8 , 92b9d004c6Schristos.Xr ktutil 1 93ca1c9b0cSelric.Sh HISTORY 94ca1c9b0cSelricThe Kerberos authentication system was developed in the late 1980's as 95ca1c9b0cSelricpart of the Athena Project at the Massachusetts Institute of 96ca1c9b0cSelricTechnology. Versions one through three never reached outside MIT, but 97ca1c9b0cSelricversion 4 was (and still is) quite popular, especially in the academic 98ca1c9b0cSelriccommunity, but is also used in commercial products like the AFS 99ca1c9b0cSelricfilesystem. 100ca1c9b0cSelric.Pp 101ca1c9b0cSelricThe problems with version 4 are that it has many limitations, the code 102ca1c9b0cSelricwas not too well written (since it had been developed over a long 103ca1c9b0cSelrictime), and it has a number of known security problems. To resolve many 104ca1c9b0cSelricof these issues work on version five started, and resulted in IETF RFC 105ca1c9b0cSelric1510 in 1993. IETF RFC 1510 was obsoleted in 2005 with IETF RFC 4120, 106ca1c9b0cSelricalso known as Kerberos clarifications. With the arrival of IETF RFC 107ca1c9b0cSelric4120, the work on adding extensibility and internationalization have 108ca1c9b0cSelricstarted (Kerberos extensions), and a new RFC will hopefully appear 109ca1c9b0cSelricsoon. 110ca1c9b0cSelric.Pp 111ca1c9b0cSelricThis manual page is part of the 112ca1c9b0cSelric.Nm Heimdal 113ca1c9b0cSelricKerberos 5 distribution, which has been in development at the Royal 114ca1c9b0cSelricInstitute of Technology in Stockholm, Sweden, since about 1997. 115