HP Visualize J5000 hp enterprise file system: planning and configuring hp DCE/ - Page 157

Authenticating to DCE from an NFS Client

Page 157 highlights

The DFS/NFS Secure Gateway Configuring Gateway Server Machines Note that if you configure multiple Gateway Server machines, each server machine houses its own authentication table. The dfs_login and dfs_logout commands affect entries only in the authentication table maintained on the Gateway Server machine they contact; commands in the dfsgw suite affect entries only in the authentication table on the machine on which they are issued. Authenticating to DCE from an NFS Client The dfs_login command authenticates a user to DCE from an NFS client. The command contacts the DCE Security Service to obtain a TGT and a service ticket for the Gateway Server (dfsgwd) process for the user. It encrypts the user's TGT with the service ticket and sends these to the Gateway Server process. It also sends the UID of the user who issues the command and the network address of the NFS client from which the command is issued. The Gateway Server process uses this information to create a valid login context, including a PAG, and an entry in the authentication table for the user. The syntax of the dfs_login command follows: dfs_login [-h hostname] [-l hh[:mm]] [dce_principal] [dce_password] The command includes the following options and arguments: -h hostname Specifies the hostname of the Gateway Server machine. By default, the command uses the hostname of the machine that exports /.... to the NFS client. Use this option to contact a different Gateway Server. -l hh[:mm] Specifies the lifetime to be assigned to the service ticket obtained with the command. Enter the lifetime as a number of hours and, optionally, minutes. A value specified with this option is subject to the policies in effect in the registry database of the DCE cell. By default, the ticket is assigned the default lifetime assigned to tickets in the DCE cell. dce_principal Specifies the DCE principal name of the user who is to be logged into DCE. By default, the command uses the name of the issuer of the command. 157

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164

157
The DFS/NFS Secure Gateway
Configuring Gateway Server Machines
Note that if you configure multiple Gateway Server machines, each server
machine houses its own authentication table. The
dfs_login
and
dfs_logout
commands affect entries only in the authentication table maintained on the
Gateway Server machine they contact; commands in the
dfsgw
suite affect
entries only in the authentication table on the machine on which they are
issued.
Authenticating to DCE from an NFS Client
The
dfs_login
command authenticates a user to DCE from an NFS client.
The command contacts the DCE Security Service to obtain a TGT and a
service ticket for the Gateway Server (
dfsgwd
) process for the user. It
encrypts the user’s TGT with the service ticket and sends these to the
Gateway Server process. It also sends the UID of the user who issues the
command and the network address of the NFS client from which the
command is issued. The Gateway Server process uses this information to
create a valid login context, including a PAG, and an entry in the
authentication table for the user.
The syntax of the
dfs_login
command follows:
dfs_login
[
-h
hostname
] [
-l
hh[:mm]
] [
dce_principal
] [
dce_password
]
The command includes the following options and arguments:
-h
hostname
Specifies the hostname of the Gateway Server machine. By default, the
command uses the hostname of the machine that exports
/...
. to the NFS
client. Use this option to contact a different Gateway Server.
-l
hh[:mm]
Specifies the lifetime to be assigned to the service ticket obtained with the
command. Enter the lifetime as a number of hours and, optionally, minutes.
A value specified with this option is subject to the policies in effect in the
registry database of the DCE cell. By default, the ticket is assigned the
default lifetime assigned to tickets in the DCE cell.
dce_principal
Specifies the DCE principal name of the user who is to be logged into DCE.
By default, the command uses the name of the issuer of the command.