2.4 Kerberos Service Objects

Each service of Novell Kerberos KDC (KDC server, Administration server, and Password server) uses a representative object in eDirectory. This has two purposes:

When each service comes up, it makes an LDAP bind to eDirectory as the corresponding service object, using the stashed password or stored certificate on the local system. All subsequent operations happen based on the rights provided to that object.

2.4.1 Kerberos Service Attributes

The following table describes the Kerberos service attributes:

Table 2-8 Kerberos Service Attributes

Attribute

Description

Service Name

Name of the Kerberos server.

Host server

This attribute holds the host name, transport protocol and port for a Kerberos service.

2.4.2 Kerberos Service Associations

The following table describes the object you can associate a Kerberos service to:

Table 2-9 Kerberos Service Associations

Associate To

Description

Realm references

List of references to the realm objects.