Managing the Kerberos Realm Object

This section discusses the following:


Creating a New Realm Object

  1. In iManager, click Kerberos Management > New Realm to open the New Realm page.

  2. Specify a name for the Kerberos realm that is to be created.

    The realm name must be the same as the one with which you want to configure this Login Method and must conform to the RFC 1510 conventions.

  3. Specify a master password for the realm and confirm the password.

  4. Select the key type that is to be used for generating the master key for this realm.

    The available key types are DES-CBC-CRC, DES-CBC-MD5, and DES3-CBC-MD5.

    The default is DES3-CBC-MD5.

  5. Select the encryption types for this realm:

    1. Select the supported encryption types.

    2. Select the default encryption type.

    The available encryption types are DES-CBC-CRC, DES-CBC-MD5, and DES3-CBC-MD5.

    The default value is DES-CBC-CRC.

    NOTE:  The selected default encryption type must be present in the Supported Encryption type list.

  6. Specify the subtree you want the Kerberos realm to be configured with or use the Object Selector icon to select it.

    This is the FDN of the subtree or the container that contains the eDirectory service principals of this realm. This subtree is not applicable to user principals (Foreign Principal names).

    If you do not select a subtree or a container, the root of the tree is used as the default.

  7. Specify the scope of the subtree search:

  8. Specify the KDC service that serves this realm or use the Object Selector icon to select it.

    NOTE:  If you have not created a KDC Service Object, leave this field blank. You can create one using Creating a New KDC Service Object and associate it with this realm. This will automatically update the KDC service entry for this realm.

  9. Click OK.


Editing a Realm Object

This task helps you modify the attribute values of the existing Realm object.

  1. In iManager, click Kerberos Management > Edit Realm to open the Edit Realm page.

  2. Specify a name for the Kerberos realm that is to be edited.

  3. Click OK.

  4. Select the encryption types for this realm:

    1. Select the supported encryption types.

    2. Select the default encryption type.

    The available encryption types are DES-CBC-CRC, DES-CBC-MD5, and DES3-CBC-MD5.

    The default value is DES-CBC-CRC.

    NOTE:  The selected default encryption type must be present in the Supported Encryption type list.

  5. Specify the subtree you want the Kerberos realm to be configured with or use the Object Selector icon to select it.

    This is the FDN of the subtree or the container that contains the eDirectory service principals of this realm. This subtree is not applicable to user principals (Foreign Principal names).

    If you do not select a subtree or a container, the root of the tree is used as the default.

  6. Specify the scope of the subtree search.

  7. Specify the KDC service that serves this realm or use the Object Selector icon to select it.

    NOTE:   If you have not created a KDC Service Object, you can create using Creating a New KDC Service Object and associate with this realm. This will automatically update the KDC service entry for this realm.

  8. Click OK.

  9. (Optional) To edit another realm, click Repeat Task.


Deleting a Realm Object

This task helps you delete existing Kerberos realms.

  1. In iManager, click Kerberos Management > Delete Realm to open the Delete Realm page.

  2. Select the realms that are to be deleted.

    To select multiple realms, press Shift and select the realms or press Shift + Arrow keys.

  3. Click OK.

  4. Click OK again to confirm the delete operation or click Cancel to cancel the delete operation.