mirror of
https://git.hardenedbsd.org/hardenedbsd/HardenedBSD.git
synced 2025-01-11 17:04:19 +01:00
1130b656e5
This will make a number of things easier in the future, as well as (finally!) avoiding the Id-smashing problem which has plagued developers for so long. Boy, I'm glad we're not using sup anymore. This update would have been insane otherwise.
59 lines
1.8 KiB
Groff
59 lines
1.8 KiB
Groff
.\" from: kdb_edit.8,v 4.1 89/01/23 11:08:55 jtkohl Exp $
|
|
.\" $FreeBSD$
|
|
.\" Copyright 1989 by the Massachusetts Institute of Technology.
|
|
.\"
|
|
.\" For copying and distribution information,
|
|
.\" please see the file <Copyright.MIT>.
|
|
.\"
|
|
.TH KDB_EDIT 8 "Kerberos Version 4.0" "MIT Project Athena"
|
|
.SH NAME
|
|
kdb_edit \- Kerberos key distribution center database editing utility
|
|
.SH SYNOPSIS
|
|
kdb_edit [
|
|
.B \-n
|
|
]
|
|
.SH DESCRIPTION
|
|
.I kdb_edit
|
|
is used to create or change principals stored in the Kerberos key
|
|
distribution center (KDC) database.
|
|
.PP
|
|
When executed,
|
|
.I kdb_edit
|
|
prompts for the master key string and verifies that it matches the
|
|
master key stored in the database.
|
|
If the
|
|
.B \-n
|
|
option is specified, the master key is instead fetched from the master
|
|
key cache file.
|
|
.PP
|
|
Once the master key has been verified,
|
|
.I kdb_edit
|
|
begins a prompt loop. The user is prompted for the principal and
|
|
instance to be modified. If the entry is not found the user may create
|
|
it.
|
|
Once an entry is found or created, the user may set the password,
|
|
expiration date, maximum ticket lifetime, and attributes.
|
|
Default expiration dates, maximum ticket lifetimes, and attributes are
|
|
presented in brackets; if the user presses return the default is selected.
|
|
There is no default password.
|
|
The password "RANDOM" and an empty password are interpreted specially,
|
|
if entered the user may have the program select a random DES key for the
|
|
principal.
|
|
.PP
|
|
Upon successfully creating or changing the entry, ``Edit O.K.'' is
|
|
printed.
|
|
.SH DIAGNOSTICS
|
|
.TP 20n
|
|
"verify_master_key: Invalid master key, does not match database."
|
|
The master key string entered was incorrect.
|
|
.SH FILES
|
|
.TP 20n
|
|
/etc/kerberosIV/principal.db
|
|
DBM file containing database
|
|
.TP
|
|
/etc/kerberosIV/principal.ok
|
|
Semaphore indicating that the DBM database is not being modified.
|
|
.TP
|
|
/etc/kerberosIV/master_key
|
|
Master key cache file.
|