Lines Matching +full:non +full:- +full:secure +full:- +full:otp

81 \label{\detokenize{admin/install:installation-guide}}\label{\detokenize{admin/install::doc}}
87 \label{\detokenize{admin/install_kdc:installing-kdcs}}\label{\detokenize{admin/install_kdc::doc}}
101 {\hyperref[\detokenize{admin/install_kdc:switch-primary-replica}]{\sphinxcrossref{\DUrole{std,std-r…
125 \label{\detokenize{admin/install_kdc:install-and-configure-the-primary-kdc}}
128 source (See \DUrole{xref,std,std-ref}{do\_build}).
144 See {\hyperref[\detokenize{mitK5defaults:mitk5defaults}]{\sphinxcrossref{\DUrole{std,std-ref}{MIT K…
151 \label{\detokenize{admin/install_kdc:edit-kdc-configuration-files}}
153 … {\hyperref[\detokenize{admin/conf_files/krb5_conf:krb5-conf-5}]{\sphinxcrossref{\DUrole{std,std-r…
154 {\hyperref[\detokenize{admin/conf_files/kdc_conf:kdc-conf-5}]{\sphinxcrossref{\DUrole{std,std-ref}{…
156 (See {\hyperref[\detokenize{mitK5defaults:mitk5defaults}]{\sphinxcrossref{\DUrole{std,std-ref}{MIT …
162 {\hyperref[\detokenize{admin/conf_files/krb5_conf:krb5-conf-5}]{\sphinxcrossref{\DUrole{std,std-ref…
178 \label{\detokenize{admin/install_kdc:krb5-conf}}
180 …(see {\hyperref[\detokenize{admin/realm_config:mapping-hostnames}]{\sphinxcrossref{\DUrole{std,std
181 …ize{admin/conf_files/krb5_conf:libdefaults}]{\sphinxcrossref{\DUrole{std,std-ref}{{[}libdefaults{]…
183-hostnames}]{\sphinxcrossref{\DUrole{std,std-ref}{Hostnames for KDCs}}}} and {\hyperref[\detokeniz…
184 …tokenize{admin/conf_files/krb5_conf:realms}]{\sphinxcrossref{\DUrole{std,std-ref}{{[}realms{]}}}}}…
187 {\hyperref[\detokenize{admin/conf_files/krb5_conf:realms}]{\sphinxcrossref{\DUrole{std,std-ref}{{[}…
206 \label{\detokenize{admin/install_kdc:kdc-conf}}
255 \label{\detokenize{admin/install_kdc:create-the-kdc-database}}\label{\detokenize{admin/install_kdc:…
257 …yperref[\detokenize{admin/admin_commands/kdb5_util:kdb5-util-8}]{\sphinxcrossref{\DUrole{std,std-r…
258 create the Kerberos database and the optional \DUrole{xref,std,std-ref}{stash\_definition}.
269 …yperref[\detokenize{admin/admin_commands/kdb5_util:kdb5-util-8}]{\sphinxcrossref{\DUrole{std,std-r…
284 …yperref[\detokenize{admin/admin_commands/kdb5_util:kdb5-util-8}]{\sphinxcrossref{\DUrole{std,std-r…
300 …{\hyperref[\detokenize{mitK5defaults:paths}]{\sphinxcrossref{\DUrole{std,std-ref}{LOCALSTATEDIR}}}…
301 in {\hyperref[\detokenize{admin/conf_files/kdc_conf:kdc-conf-5}]{\sphinxcrossref{\DUrole{std,std-re…
325 {\hyperref[\detokenize{admin/database:db-operations}]{\sphinxcrossref{\DUrole{std,std-ref}{Operatio…
329 …abel{\detokenize{admin/install_kdc:add-administrators-to-the-acl-file}}\label{\detokenize{admin/in…
333 …\hyperref[\detokenize{admin/admin_commands/kadmind:kadmind-8}]{\sphinxcrossref{\DUrole{std,std-ref…
336-conf-5}]{\sphinxcrossref{\DUrole{std,std-ref}{kdc.conf}}}}; the default is {\hyperref[\detokenize…
339 … {\hyperref[\detokenize{admin/conf_files/kadm5_acl:kadm5-acl-5}]{\sphinxcrossref{\DUrole{std,std-r…
343 …detokenize{admin/install_kdc:add-administrators-to-the-kerberos-database}}\label{\detokenize{admin…
357 … file (see {\hyperref[\detokenize{admin/install_kdc:admin-acl}]{\sphinxcrossref{\DUrole{std,std-re…
378 …tokenize{admin/install_kdc:start-the-kerberos-daemons-on-the-primary-kdc}}\label{\detokenize{admin…
381 ({\hyperref[\detokenize{admin/admin_commands/krb5kdc:krb5kdc-8}]{\sphinxcrossref{\DUrole{std,std-re…
397 \DUrole{xref,std,std-ref}{stash\_definition} in order to do this.
403-conf-5}]{\sphinxcrossref{\DUrole{std,std-ref}{krb5.conf}}}} (see {\hyperref[\detokenize{admin/con…
417 As an additional verification, check if \DUrole{xref,std,std-ref}{kinit(1)} succeeds
419 ({\hyperref[\detokenize{admin/install_kdc:addadmin-kdb}]{\sphinxcrossref{\DUrole{std,std-ref}{Add a…
427 \label{\detokenize{admin/install_kdc:install-the-replica-kdcs}}
442 …detokenize{admin/install_kdc:create-host-keytabs-for-replica-kdcs}}\label{\detokenize{admin/instal…
510 \label{\detokenize{admin/install_kdc:configure-replica-kdcs}}
515 (see {\hyperref[\detokenize{mitK5defaults:mitk5defaults}]{\sphinxcrossref{\DUrole{std,std-ref}{MIT …
542 … {\hyperref[\detokenize{admin/admin_commands/kpropd:kpropd-8}]{\sphinxcrossref{\DUrole{std,std-ref…
584 … {\hyperref[\detokenize{admin/admin_commands/kpropd:kpropd-8}]{\sphinxcrossref{\DUrole{std,std-ref…
597 …tokenize{admin/install_kdc:propagate-the-database-to-each-replica-kdc}}\label{\detokenize{admin/in…
641 …arlier (see {\hyperref[\detokenize{admin/realm_config:db-prop}]{\sphinxcrossref{\DUrole{std,std-re…
658 \label{\detokenize{admin/install_kdc:propagation-failed}}
662 …detokenize{admin/troubleshoot:troubleshoot}]{\sphinxcrossref{\DUrole{std,std-ref}{Troubleshooting}…
667 {\hyperref[\detokenize{admin/troubleshoot:kprop-no-route}]{\sphinxcrossref{\DUrole{std,std-ref}{kpr…
671 {\hyperref[\detokenize{admin/troubleshoot:kprop-con-refused}]{\sphinxcrossref{\DUrole{std,std-ref}{…
675 {\hyperref[\detokenize{admin/troubleshoot:kprop-sendauth-exchange}]{\sphinxcrossref{\DUrole{std,std
681 \label{\detokenize{admin/install_kdc:add-kerberos-principals-to-the-database}}
684 …erref[\detokenize{admin/admin_commands/kadmin_local:kadmin-1}]{\sphinxcrossref{\DUrole{std,std-ref…
686 fully in {\hyperref[\detokenize{admin/database:principals}]{\sphinxcrossref{\DUrole{std,std-ref}{Pr…
696 …etokenize{admin/install_kdc:switching-primary-and-replica-kdcs}}\label{\detokenize{admin/install_k…
724 {\hyperref[\detokenize{admin/install_kdc:kprop-to-replicas}]{\sphinxcrossref{\DUrole{std,std-ref}{P…
734-8}]{\sphinxcrossref{\DUrole{std,std-ref}{kadmind}}}} daemon (see {\hyperref[\detokenize{admin/ins…
739 {\hyperref[\detokenize{admin/install_kdc:kprop-to-replicas}]{\sphinxcrossref{\DUrole{std,std-ref}{P…
744 … {\hyperref[\detokenize{admin/conf_files/krb5_conf:krb5-conf-5}]{\sphinxcrossref{\DUrole{std,std-r…
751 \label{\detokenize{admin/install_kdc:incremental-database-propagation}}
755 {\hyperref[\detokenize{admin/database:incr-db-prop}]{\sphinxcrossref{\DUrole{std,std-ref}{Increment…
759 \label{\detokenize{admin/install_clients:installing-and-configuring-unix-client-machines}}\label{\d…
761 The Kerberized client programs include \DUrole{xref,std,std-ref}{kinit(1)},
762 \DUrole{xref,std,std-ref}{klist(1)}, \DUrole{xref,std,std-ref}{kdestroy(1)}, and \DUrole{xref,std,s…
763 …ctory {\hyperref[\detokenize{mitK5defaults:paths}]{\sphinxcrossref{\DUrole{std,std-ref}{BINDIR}}}}.
777 in place of its non\sphinxhyphen{}Kerberos counterparts passwd.
781 \label{\detokenize{admin/install_clients:client-machine-configuration-files}}
783 … {\hyperref[\detokenize{admin/conf_files/krb5_conf:krb5-conf-5}]{\sphinxcrossref{\DUrole{std,std-r…
785 {\hyperref[\detokenize{admin/conf_files/krb5_conf:libdefaults}]{\sphinxcrossref{\DUrole{std,std-ref…
786-hostnames}]{\sphinxcrossref{\DUrole{std,std-ref}{Hostnames for KDCs}}}}) or URI records ({\hyperr…
787 …tokenize{admin/conf_files/krb5_conf:realms}]{\sphinxcrossref{\DUrole{std,std-ref}{{[}realms{]}}}}}…
817 …{\hyperref[\detokenize{admin/conf_files/krb5_conf:domain-realm}]{\sphinxcrossref{\DUrole{std,std-r…
825 \label{\detokenize{admin/install_appl_srv:unix-application-servers}}\label{\detokenize{admin/instal…
828 over the network. Application servers can be “secure” or “insecure.”
829 A “secure” host is set up to require authentication from every client
836 recommends that you make your hosts secure, to take advantage of the
844 \label{\detokenize{admin/install_appl_srv:the-keytab-file}}\label{\detokenize{admin/install_appl_sr…
847 …ed {\hyperref[\detokenize{mitK5defaults:paths}]{\sphinxcrossref{\DUrole{std,std-ref}{DEFKTNAME}}}}.
859 …rref[\detokenize{admin/database:principals}]{\sphinxcrossref{\DUrole{std,std-ref}{Principals}}}}. …
860 {\hyperref[\detokenize{admin/install_kdc:replica-host-key}]{\sphinxcrossref{\DUrole{std,std-ref}{Cr…
861-1}]{\sphinxcrossref{\DUrole{std,std-ref}{kadmin}}}} and issuing the {\hyperref[\detokenize{admin/…
888 \subsubsection{Some advice about secure hosts}
889 \label{\detokenize{admin/install_appl_srv:some-advice-about-secure-hosts}}
899 We recommend that backups of secure machines exclude the keytab file
900 ({\hyperref[\detokenize{mitK5defaults:paths}]{\sphinxcrossref{\DUrole{std,std-ref}{DEFKTNAME}}}}). …
911 \label{\detokenize{admin/install:additional-references}}\begin{enumerate}
919 Solaris: \sphinxhref{https://docs.oracle.com/cd/E19253-01/816-4557/6maosrjv2/index.html}{Configurin…
925 \label{\detokenize{admin/conf_files/index:configuration-files}}\label{\detokenize{admin/conf_files/…
928 … {\hyperref[\detokenize{admin/conf_files/krb5_conf:krb5-conf-5}]{\sphinxcrossref{\DUrole{std,std-r…
931 {\hyperref[\detokenize{admin/conf_files/kdc_conf:kdc-conf-5}]{\sphinxcrossref{\DUrole{std,std-ref}{…
932 … {\hyperref[\detokenize{admin/conf_files/kadm5_acl:kadm5-acl-5}]{\sphinxcrossref{\DUrole{std,std-r…
941 …l{\detokenize{admin/conf_files/krb5_conf:krb5-conf}}\label{\detokenize{admin/conf_files/krb5_conf:…
1022 …e, {\hyperref[\detokenize{admin/conf_files/kdc_conf:kdc-conf-5}]{\sphinxcrossref{\DUrole{std,std-r…
1037 {\hyperref[\detokenize{admin/conf_files/krb5_conf:libdefaults}]{\sphinxcrossref{\DUrole{std,std-ref…
1044 {\hyperref[\detokenize{admin/conf_files/krb5_conf:realms}]{\sphinxcrossref{\DUrole{std,std-ref}{{[}…
1051 {\hyperref[\detokenize{admin/conf_files/krb5_conf:domain-realm}]{\sphinxcrossref{\DUrole{std,std-re…
1058 {\hyperref[\detokenize{admin/conf_files/krb5_conf:capaths}]{\sphinxcrossref{\DUrole{std,std-ref}{{[…
1061 Authentication paths for non\sphinxhyphen{}hierarchical cross\sphinxhyphen{}realm
1065 {\hyperref[\detokenize{admin/conf_files/krb5_conf:appdefaults}]{\sphinxcrossref{\DUrole{std,std-ref…
1072 {\hyperref[\detokenize{admin/conf_files/krb5_conf:plugins}]{\sphinxcrossref{\DUrole{std,std-ref}{{[…
1084 {\hyperref[\detokenize{admin/conf_files/kdc_conf:kdc-conf-5}]{\sphinxcrossref{\DUrole{std,std-ref}{…
1109-types}]{\sphinxcrossref{\DUrole{std,std-ref}{Encryption types}}}} in {\hyperref[\detokenize{admin…
1124 created by \DUrole{xref,std,std-ref}{kinit(1)} or other programs. The default value
1145 The default is {\hyperref[\detokenize{mitK5defaults:paths}]{\sphinxcrossref{\DUrole{std,std-ref}{DE…
1151 …{\hyperref[\detokenize{mitK5defaults:paths}]{\sphinxcrossref{\DUrole{std,std-ref}{DEFCKTNAME}}}}. …
1158 …{\hyperref[\detokenize{mitK5defaults:paths}]{\sphinxcrossref{\DUrole{std,std-ref}{DEFKTNAME}}}}. …
1172 invoking programs such as \DUrole{xref,std,std-ref}{kinit(1)}.
1179 …yperref[\detokenize{admin/conf_files/kdc_conf:encryption-types}]{\sphinxcrossref{\DUrole{std,std-r…
1180 {\hyperref[\detokenize{admin/conf_files/kdc_conf:kdc-conf-5}]{\sphinxcrossref{\DUrole{std,std-ref}{…
1286 k5login file to be granted login access, if a \DUrole{xref,std,std-ref}{.k5login(5)}
1396 (\DUrole{xref,std,std-ref}{duration} string.) Sets the default renewable lifetime
1449 (\DUrole{xref,std,std-ref}{duration} string.) Sets the default lifetime for initial
1471 channel bindings when operating over a secure channel. The
1489 …\hyperref[\detokenize{admin/admin_commands/kadmind:kadmind-8}]{\sphinxcrossref{\DUrole{std,std-ref…
1658 \label{\detokenize{admin/conf_files/krb5_conf:domain-realm}}\label{\detokenize{admin/conf_files/krb…
1696 In order to perform direct (non\sphinxhyphen{}hierarchical) cross\sphinxhyphen{}realm
1836 {\hyperref[\detokenize{admin/conf_files/krb5_conf:kadm5-hook}]{\sphinxcrossref{kadm5\_hook}}} inter…
1876 …ize{admin/conf_files/krb5_conf:libdefaults}]{\sphinxcrossref{\DUrole{std,std-ref}{{[}libdefaults{]…
1893 \label{\detokenize{admin/conf_files/krb5_conf:ccselect-interface}}\label{\detokenize{admin/conf_fil…
1919 \label{\detokenize{admin/conf_files/krb5_conf:pwqual-interface}}\label{\detokenize{admin/conf_files…
1946 …etokenize{admin/conf_files/krb5_conf:kadm5-hook-interface}}\label{\detokenize{admin/conf_files/krb…
1956 …etokenize{admin/conf_files/krb5_conf:kadm5-auth-interface}}\label{\detokenize{admin/conf_files/krb…
1965 … {\hyperref[\detokenize{admin/conf_files/kadm5_acl:kadm5-acl-5}]{\sphinxcrossref{\DUrole{std,std-r…
1979 \label{\detokenize{admin/conf_files/krb5_conf:clpreauth-and-kdcpreauth-interfaces}}\label{\detokeni…
2001 \label{\detokenize{admin/conf_files/krb5_conf:hostrealm-interface}}\label{\detokenize{admin/conf_fi…
2031 \label{\detokenize{admin/conf_files/krb5_conf:localauth-interface}}\label{\detokenize{admin/conf_fi…
2062 the account’s \DUrole{xref,std,std-ref}{.k5login(5)} file.
2073 \label{\detokenize{admin/conf_files/krb5_conf:certauth-interface}}\label{\detokenize{admin/conf_fil…
2103 \label{\detokenize{admin/conf_files/krb5_conf:pkinit-options}}
2150 …min/conf_files/krb5_conf:specifying-pkinit-identity-information}}\label{\detokenize{admin/conf_fil…
2207 …{\hyperref[\detokenize{mitK5defaults:paths}]{\sphinxcrossref{\DUrole{std,std-ref}{PKCS11\_MODNAME}…
2226 \label{\detokenize{admin/conf_files/krb5_conf:pkinit-krb5-conf-options}}\begin{description}
2420 \label{\detokenize{admin/conf_files/krb5_conf:parameter-expansion}}\label{\detokenize{admin/conf_fi…
2552 \label{\detokenize{admin/conf_files/krb5_conf:sample-krb5-conf-file}}
2596 \label{\detokenize{admin/conf_files/krb5_conf:see-also}}
2602 …abel{\detokenize{admin/conf_files/kdc_conf:kdc-conf}}\label{\detokenize{admin/conf_files/kdc_conf:…
2604 … {\hyperref[\detokenize{admin/conf_files/krb5_conf:krb5-conf-5}]{\sphinxcrossref{\DUrole{std,std-r…
2605 …\hyperref[\detokenize{admin/admin_commands/krb5kdc:krb5kdc-8}]{\sphinxcrossref{\DUrole{std,std-ref…
2606-8}]{\sphinxcrossref{\DUrole{std,std-ref}{kadmind}}}} daemons and the {\hyperref[\detokenize{admin…
2613 {\hyperref[\detokenize{mitK5defaults:paths}]{\sphinxcrossref{\DUrole{std,std-ref}{LOCALSTATEDIR}}}}…
2625 {\hyperref[\detokenize{admin/conf_files/krb5_conf:krb5-conf-5}]{\sphinxcrossref{\DUrole{std,std-ref…
2640 {\hyperref[\detokenize{admin/conf_files/kdc_conf:kdcdefaults}]{\sphinxcrossref{\DUrole{std,std-ref}…
2647 {\hyperref[\detokenize{admin/conf_files/kdc_conf:kdc-realms}]{\sphinxcrossref{\DUrole{std,std-ref}{…
2654 {\hyperref[\detokenize{admin/conf_files/kdc_conf:dbdefaults}]{\sphinxcrossref{\DUrole{std,std-ref}{…
2661 {\hyperref[\detokenize{admin/conf_files/kdc_conf:dbmodules}]{\sphinxcrossref{\DUrole{std,std-ref}{{…
2668 {\hyperref[\detokenize{admin/conf_files/kdc_conf:logging}]{\sphinxcrossref{\DUrole{std,std-ref}{{[}…
2684 …he {\hyperref[\detokenize{admin/conf_files/kdc_conf:kdc-realms}]{\sphinxcrossref{\DUrole{std,std-r…
2734 …ize{admin/conf_files/krb5_conf:libdefaults}]{\sphinxcrossref{\DUrole{std,std-ref}{{[}libdefaults{]…
2742 …okenize{admin/conf_files/kdc_conf:realms}}\label{\detokenize{admin/conf_files/kdc_conf:kdc-realms}}
2762 {\hyperref[\detokenize{admin/admin_commands/kadmind:kadmind-8}]{\sphinxcrossref{\DUrole{std,std-ref…
2765 …{\hyperref[\detokenize{mitK5defaults:paths}]{\sphinxcrossref{\DUrole{std,std-ref}{LOCALSTATEDIR}}}…
2766 … {\hyperref[\detokenize{admin/conf_files/kadm5_acl:kadm5-acl-5}]{\sphinxcrossref{\DUrole{std,std-r…
2771 …kenize{admin/conf_files/kdc_conf:dbmodules}]{\sphinxcrossref{\DUrole{std,std-ref}{{[}dbmodules{]}}…
2780 …kenize{admin/conf_files/kdc_conf:dbmodules}]{\sphinxcrossref{\DUrole{std,std-ref}{{[}dbmodules{]}}…
2781 …{\hyperref[\detokenize{mitK5defaults:paths}]{\sphinxcrossref{\DUrole{std,std-ref}{LOCALSTATEDIR}}}…
2785 (\DUrole{xref,std,std-ref}{abstime} string.) Specifies the default expiration date of
2951 …\hyperref[\detokenize{admin/admin_commands/kadmind:kadmind-8}]{\sphinxcrossref{\DUrole{std,std-ref…
2969 …\hyperref[\detokenize{admin/admin_commands/kadmind:kadmind-8}]{\sphinxcrossref{\DUrole{std,std-ref…
2993 …\hyperref[\detokenize{admin/admin_commands/kadmind:kadmind-8}]{\sphinxcrossref{\DUrole{std,std-ref…
3005 …\hyperref[\detokenize{admin/admin_commands/kadmind:kadmind-8}]{\sphinxcrossref{\DUrole{std,std-ref…
3013 …{\hyperref[\detokenize{mitK5defaults:paths}]{\sphinxcrossref{\DUrole{std,std-ref}{LOCALSTATEDIR}}}…
3018 …\hyperref[\detokenize{admin/admin_commands/krb5kdc:krb5kdc-8}]{\sphinxcrossref{\DUrole{std,std-ref…
3032 {\hyperref[\detokenize{admin/admin_commands/krb5kdc:krb5kdc-8}]{\sphinxcrossref{\DUrole{std,std-ref…
3039 …\hyperref[\detokenize{admin/admin_commands/krb5kdc:krb5kdc-8}]{\sphinxcrossref{\DUrole{std,std-ref…
3054 {\hyperref[\detokenize{admin/admin_commands/krb5kdc:krb5kdc-8}]{\sphinxcrossref{\DUrole{std,std-ref…
3061 …\hyperref[\detokenize{admin/admin_commands/kadmind:kadmind-8}]{\sphinxcrossref{\DUrole{std,std-ref…
3072 …\hyperref[\detokenize{admin/admin_commands/kadmind:kadmind-8}]{\sphinxcrossref{\DUrole{std,std-ref…
3087 …yperref[\detokenize{admin/conf_files/kdc_conf:encryption-types}]{\sphinxcrossref{\DUrole{std,std-r…
3091 (\DUrole{xref,std,std-ref}{duration} string.) Specifies the maximum time period for
3097 (\DUrole{xref,std,std-ref}{duration} string.) Specifies the maximum time period
3114 {\hyperref[\detokenize{admin/conf_files/krb5_conf:krb5-conf-5}]{\sphinxcrossref{\DUrole{std,std-ref…
3154 …erref[\detokenize{admin/admin_commands/kadmin_local:kadmin-1}]{\sphinxcrossref{\DUrole{std,std-ref…
3156 …{\hyperref[\detokenize{admin/conf_files/kdc_conf:keysalt-lists}]{\sphinxcrossref{\DUrole{std,std-r…
3166 …kenize{admin/conf_files/kdc_conf:dbmodules}]{\sphinxcrossref{\DUrole{std,std-ref}{{[}dbmodules{]}}…
3246 …{\hyperref[\detokenize{mitK5defaults:paths}]{\sphinxcrossref{\DUrole{std,std-ref}{LOCALSTATEDIR}}}…
3279 …\hyperref[\detokenize{admin/admin_commands/krb5kdc:krb5kdc-8}]{\sphinxcrossref{\DUrole{std,std-ref…
3280 …\hyperref[\detokenize{admin/admin_commands/kadmind:kadmind-8}]{\sphinxcrossref{\DUrole{std,std-ref…
3336 for SASL authentication. This file must be kept secure.
3384 …\hyperref[\detokenize{admin/admin_commands/krb5kdc:krb5kdc-8}]{\sphinxcrossref{\DUrole{std,std-ref…
3385 {\hyperref[\detokenize{admin/admin_commands/kadmind:kadmind-8}]{\sphinxcrossref{\DUrole{std,std-ref…
3390 …\hyperref[\detokenize{admin/admin_commands/kadmind:kadmind-8}]{\sphinxcrossref{\DUrole{std,std-ref…
3394 …\hyperref[\detokenize{admin/admin_commands/krb5kdc:krb5kdc-8}]{\sphinxcrossref{\DUrole{std,std-ref…
3474 \paragraph{{[}otp{]}}
3475 \label{\detokenize{admin/conf_files/kdc_conf:otp}}\label{\detokenize{admin/conf_files/kdc_conf:id5}}
3477 Each subsection of {[}otp{]} is the name of an OTP token type. The tags
3489 {\hyperref[\detokenize{mitK5defaults:paths}]{\sphinxcrossref{\DUrole{std,std-ref}{LOCALSTATEDIR}}}}…
3493 …{\hyperref[\detokenize{mitK5defaults:paths}]{\sphinxcrossref{\DUrole{std,std-ref}{LOCALSTATEDIR}}}…
3506 which an OTP value remains valid for. The default is 5 seconds.
3531 [otp]
3548 \PYG{p}{[}\PYG{n}{otp}\PYG{p}{]}
3556 \label{\detokenize{admin/conf_files/kdc_conf:pkinit-options}}
3591 …hyperref[\detokenize{admin/conf_files/krb5_conf:pkinit-identity}]{\sphinxcrossref{\DUrole{std,std-
3592 {\hyperref[\detokenize{admin/conf_files/krb5_conf:krb5-conf-5}]{\sphinxcrossref{\DUrole{std,std-ref…
3698 \label{\detokenize{admin/conf_files/kdc_conf:encryption-types}}\label{\detokenize{admin/conf_files/…
3839 \label{\detokenize{admin/conf_files/kdc_conf:keysalt-lists}}\label{\detokenize{admin/conf_files/kdc…
3903 \label{\detokenize{admin/conf_files/kdc_conf:sample-kdc-conf-file}}
3948 {\hyperref[\detokenize{mitK5defaults:paths}]{\sphinxcrossref{\DUrole{std,std-ref}{LOCALSTATEDIR}}}}…
3952 \label{\detokenize{admin/conf_files/kdc_conf:see-also}}
3954-conf-5}]{\sphinxcrossref{\DUrole{std,std-ref}{krb5.conf}}}}, {\hyperref[\detokenize{admin/admin_c…
3958 …{\detokenize{admin/conf_files/kadm5_acl:kadm5-acl}}\label{\detokenize{admin/conf_files/kadm5_acl:k…
3963 …\hyperref[\detokenize{admin/admin_commands/kadmind:kadmind-8}]{\sphinxcrossref{\DUrole{std,std-ref…
3970 {\hyperref[\detokenize{mitK5defaults:paths}]{\sphinxcrossref{\DUrole{std,std-ref}{LOCALSTATEDIR}}}}…
3971 …in {\hyperref[\detokenize{admin/conf_files/kdc_conf:kdc-conf-5}]{\sphinxcrossref{\DUrole{std,std-r…
4067 …ase (used in {\hyperref[\detokenize{admin/database:incr-db-prop}]{\sphinxcrossref{\DUrole{std,std-
4130 …in {\hyperref[\detokenize{admin/conf_files/kdc_conf:kdc-conf-5}]{\sphinxcrossref{\DUrole{std,std-r…
4142 (\DUrole{xref,std,std-ref}{getdate} string) associated value will be forced to
4185 …His \sphinxcode{\sphinxupquote{root}} and other non\sphinxhyphen{}\sphinxcode{\sphinxupquote{admin…
4210 \label{\detokenize{admin/conf_files/kadm5_acl:module-behavior}}
4213 … {\hyperref[\detokenize{admin/conf_files/krb5_conf:kadm5-auth}]{\sphinxcrossref{\DUrole{std,std-re…
4214 {\hyperref[\detokenize{admin/conf_files/krb5_conf:krb5-conf-5}]{\sphinxcrossref{\DUrole{std,std-ref…
4221 {\hyperref[\detokenize{admin/conf_files/kdc_conf:kdc-conf-5}]{\sphinxcrossref{\DUrole{std,std-ref}{…
4225 \label{\detokenize{admin/conf_files/kadm5_acl:see-also}}
4227-conf-5}]{\sphinxcrossref{\DUrole{std,std-ref}{kdc.conf}}}}, {\hyperref[\detokenize{admin/admin_co…
4231 \label{\detokenize{admin/realm_config:realm-configuration-decisions}}\label{\detokenize{admin/realm…
4267 \label{\detokenize{admin/realm_config:realm-name}}
4291 …detokenize{admin/realm_config:mapping-hostnames-onto-kerberos-realms}}\label{\detokenize{admin/rea…
4297-realm}]{\sphinxcrossref{\DUrole{std,std-ref}{{[}domain\_realm{]}}}}} section of {\hyperref[\detok…
4315-realms}]{\sphinxcrossref{\DUrole{std,std-ref}{{[}realms{]}}}}} section of {\hyperref[\detokenize{…
4320 … {\hyperref[\detokenize{admin/conf_files/krb5_conf:krb5-conf-5}]{\sphinxcrossref{\DUrole{std,std-r…
4346 \label{\detokenize{admin/realm_config:ports-for-the-kdc-and-admin-services}}
4351 {\hyperref[\detokenize{admin/conf_files/krb5_conf:krb5-conf-5}]{\sphinxcrossref{\DUrole{std,std-ref…
4352 {\hyperref[\detokenize{admin/conf_files/kdc_conf:kdc-conf-5}]{\sphinxcrossref{\DUrole{std,std-ref}{…
4354 {\hyperref[\detokenize{admin/appl_servers:conf-firewall}]{\sphinxcrossref{\DUrole{std,std-ref}{Conf…
4358 \label{\detokenize{admin/realm_config:replica-kdcs}}
4396 \label{\detokenize{admin/realm_config:hostnames-for-kdcs}}\label{\detokenize{admin/realm_config:kdc
4442 …erref[\detokenize{admin/admin_commands/kadmin_local:kadmin-1}]{\sphinxcrossref{\DUrole{std,std-ref…
4443 … {\hyperref[\detokenize{admin/conf_files/krb5_conf:krb5-conf-5}]{\sphinxcrossref{\DUrole{std,std-r…
4485 …tokenize{admin/conf_files/krb5_conf:realms}]{\sphinxcrossref{\DUrole{std,std-ref}{{[}realms{]}}}}}…
4486 {\hyperref[\detokenize{admin/conf_files/krb5_conf:krb5-conf-5}]{\sphinxcrossref{\DUrole{std,std-ref…
4492 \label{\detokenize{admin/realm_config:kdc-discovery}}\label{\detokenize{admin/realm_config:id1}}
4560 …ize{admin/conf_files/krb5_conf:libdefaults}]{\sphinxcrossref{\DUrole{std,std-ref}{{[}libdefaults{]…
4561 {\hyperref[\detokenize{admin/conf_files/krb5_conf:krb5-conf-5}]{\sphinxcrossref{\DUrole{std,std-ref…
4567 \label{\detokenize{admin/realm_config:database-propagation}}\label{\detokenize{admin/realm_config:d…
4586 See also {\hyperref[\detokenize{admin/database:incr-db-prop}]{\sphinxcrossref{\DUrole{std,std-ref}{…
4590 \label{\detokenize{admin/database:database-administration}}\label{\detokenize{admin/database::doc}}
4594 …yperref[\detokenize{admin/admin_commands/kdb5_util:kdb5-util-8}]{\sphinxcrossref{\DUrole{std,std-r…
4596 …erref[\detokenize{admin/admin_commands/kadmin_local:kadmin-1}]{\sphinxcrossref{\DUrole{std,std-ref…
4598 \DUrole{xref,std,std-ref}{kpasswd(1)} program to change their own passwords.) The kadmin
4603 …yperref[\detokenize{admin/admin_commands/kdb5_util:kdb5-util-8}]{\sphinxcrossref{\DUrole{std,std-r…
4606-8}]{\sphinxcrossref{\DUrole{std,std-ref}{kadmind}}}} and {\hyperref[\detokenize{admin/admin_comma…
4610 …erref[\detokenize{admin/admin_commands/kadmin_local:kadmin-1}]{\sphinxcrossref{\DUrole{std,std-ref…
4613 …\hyperref[\detokenize{admin/admin_commands/kadmind:kadmind-8}]{\sphinxcrossref{\DUrole{std,std-ref…
4630 …erref[\detokenize{admin/admin_commands/kadmin_local:kadmin-1}]{\sphinxcrossref{\DUrole{std,std-ref…
4641 …erref[\detokenize{admin/admin_commands/kadmin_local:kadmin-1}]{\sphinxcrossref{\DUrole{std,std-ref…
4644 …ef[\detokenize{admin/dictionary:dictionary}]{\sphinxcrossref{\DUrole{std,std-ref}{Addressing dicti…
4653 …{\hyperref[\detokenize{admin/pkinit:pkinit}]{\sphinxcrossref{\DUrole{std,std-ref}{PKINIT configura…
4695 \DUrole{xref,std,std-ref}{kpasswd(1)}.
4715 …erref[\detokenize{admin/admin_commands/kadmin_local:kadmin-1}]{\sphinxcrossref{\DUrole{std,std-ref…
4745 \label{\detokenize{admin/database:updating-the-history-key}}\label{\detokenize{admin/database:updat…
4776 … {\hyperref[\detokenize{admin/conf_files/kadm5_acl:kadm5-acl-5}]{\sphinxcrossref{\DUrole{std,std-r…
4791 \label{\detokenize{admin/database:operations-on-the-kerberos-database}}\label{\detokenize{admin/dat…
4793 …yperref[\detokenize{admin/admin_commands/kdb5_util:kdb5-util-8}]{\sphinxcrossref{\DUrole{std,std-r…
4795 {\hyperref[\detokenize{admin/dbtypes:dbtypes}]{\sphinxcrossref{\DUrole{std,std-ref}{Database types}…
4796 {\hyperref[\detokenize{admin/install_kdc:create-db}]{\sphinxcrossref{\DUrole{std,std-ref}{Create th…
4824 …l{\detokenize{admin/database:dumping-and-loading-a-kerberos-database}}\label{\detokenize{admin/dat…
4827 …yperref[\detokenize{admin/admin_commands/kdb5_util:kdb5-util-8}]{\sphinxcrossref{\DUrole{std,std-r…
4853 …yperref[\detokenize{admin/admin_commands/kdb5_util:kdb5-util-8}]{\sphinxcrossref{\DUrole{std,std-r…
4875 \label{\detokenize{admin/database:updating-the-master-key}}\label{\detokenize{admin/database:updati…
4877 …yperref[\detokenize{admin/admin_commands/kdb5_util:kdb5-util-8}]{\sphinxcrossref{\DUrole{std,std-r…
4904 master key and write it to the stash file. Enter a secure password
4927 …\hyperref[\detokenize{admin/admin_commands/kadmind:kadmind-8}]{\sphinxcrossref{\DUrole{std,std-ref…
4957 \label{\detokenize{admin/database:operations-on-the-ldap-database}}\label{\detokenize{admin/databas…
4959 …[\detokenize{admin/admin_commands/kdb5_ldap_util:kdb5-ldap-util-8}]{\sphinxcrossref{\DUrole{std,st…
4961 … describe in {\hyperref[\detokenize{admin/conf_ldap:conf-ldap}]{\sphinxcrossref{\DUrole{std,std-re…
5005 \label{\detokenize{admin/database:ticket-policy-operations}}
5021 …erref[\detokenize{admin/admin_commands/kadmin_local:kadmin-1}]{\sphinxcrossref{\DUrole{std,std-ref…
5077 \label{\detokenize{admin/database:cross-realm-authentication}}\label{\detokenize{admin/database:xre…
5124 \label{\detokenize{admin/database:changing-the-krbtgt-key}}\label{\detokenize{admin/database:changi…
5134 …erref[\detokenize{admin/admin_commands/kadmin_local:kadmin-1}]{\sphinxcrossref{\DUrole{std,std-ref…
5159 …kenize{admin/enctypes:session-key-selection}]{\sphinxcrossref{\DUrole{std,std-ref}{Session key sel…
5166 …erref[\detokenize{admin/admin_commands/kadmin_local:set-string}]{\sphinxcrossref{\DUrole{std,std-r…
5176 …label{\detokenize{admin/database:incremental-database-propagation}}\label{\detokenize{admin/databa…
5191 …\hyperref[\detokenize{admin/admin_commands/kadmind:kadmind-8}]{\sphinxcrossref{\DUrole{std,std-ref…
5197 …ee {\hyperref[\detokenize{admin/conf_files/kdc_conf:kdc-conf-5}]{\sphinxcrossref{\DUrole{std,std-r…
5262 …le {\hyperref[\detokenize{admin/conf_files/kdc_conf:kdc-conf-5}]{\sphinxcrossref{\DUrole{std,std-r…
5274 default keytab file ({\hyperref[\detokenize{mitK5defaults:paths}]{\sphinxcrossref{\DUrole{std,std-r…
5280 … {\hyperref[\detokenize{admin/conf_files/kadm5_acl:kadm5-acl-5}]{\sphinxcrossref{\DUrole{std,std-r…
5281 …erref[\detokenize{admin/database:privileges}]{\sphinxcrossref{\DUrole{std,std-ref}{Privileges}}}}).
5284 … {\hyperref[\detokenize{admin/admin_commands/kpropd:kpropd-8}]{\sphinxcrossref{\DUrole{std,std-ref…
5331 \label{\detokenize{admin/database:sun-mit-incremental-propagation-differences}}
5357 {\hyperref[\detokenize{mitK5defaults:paths}]{\sphinxcrossref{\DUrole{std,std-ref}{LOCALSTATEDIR}}}}…
5361 \label{\detokenize{admin/dbtypes:database-types}}\label{\detokenize{admin/dbtypes:dbtypes}}\label{\…
5371 …kenize{admin/conf_files/kdc_conf:dbmodules}]{\sphinxcrossref{\DUrole{std,std-ref}{{[}dbmodules{]}}…
5387 {\hyperref[\detokenize{admin/admin_commands/kadmind:kadmind-8}]{\sphinxcrossref{\DUrole{std,std-ref…
5393-8}]{\sphinxcrossref{\DUrole{std,std-ref}{krb5kdc}}}} and {\hyperref[\detokenize{admin/admin_comma…
5397 \label{\detokenize{admin/dbtypes:berkeley-database-module-db2}}
5423 …yperref[\detokenize{admin/admin_commands/kdb5_util:kdb5-util-8}]{\sphinxcrossref{\DUrole{std,std-r…
5424-8}]{\sphinxcrossref{\DUrole{std,std-ref}{kprop}}}} or by {\hyperref[\detokenize{admin/admin_comma…
5425 …\hyperref[\detokenize{admin/admin_commands/krb5kdc:krb5kdc-8}]{\sphinxcrossref{\DUrole{std,std-ref…
5428 …rites (see {\hyperref[\detokenize{admin/lockout:disable-lockout}]{\sphinxcrossref{\DUrole{std,std-
5453 \label{\detokenize{admin/dbtypes:lightning-memory-mapped-database-module-klmdb}}
5486 {\hyperref[\detokenize{admin/lockout:disable-lockout}]{\sphinxcrossref{\DUrole{std,std-ref}{KDC per…
5529 …erref[\detokenize{admin/admin_commands/kadmin_local:kadmin-1}]{\sphinxcrossref{\DUrole{std,std-ref…
5533 \label{\detokenize{admin/dbtypes:ldap-module-kldap}}
5537 …schema. See {\hyperref[\detokenize{admin/conf_ldap:conf-ldap}]{\sphinxcrossref{\DUrole{std,std-re…
5540 …\hyperref[\detokenize{admin/admin_commands/krb5kdc:krb5kdc-8}]{\sphinxcrossref{\DUrole{std,std-ref…
5545 {\hyperref[\detokenize{admin/admin_commands/krb5kdc:krb5kdc-8}]{\sphinxcrossref{\DUrole{std,std-ref…
5550 …erref[\detokenize{admin/admin_commands/kadmin_local:kadmin-1}]{\sphinxcrossref{\DUrole{std,std-ref…
5554 \label{\detokenize{admin/lockout:account-lockout}}\label{\detokenize{admin/lockout:lockout}}\label{…
5564 \label{\detokenize{admin/lockout:configuring-account-lockout}}
5572 …erref[\detokenize{admin/admin_commands/kadmin_local:kadmin-1}]{\sphinxcrossref{\DUrole{std,std-ref…
5579 …perref[\detokenize{admin/database:policies}]{\sphinxcrossref{\DUrole{std,std-ref}{policy objects}}…
5588 …[\detokenize{admin/admin_commands/kadmin_local:policy-maxfailure}]{\sphinxcrossref{\DUrole{std,std
5593 …okenize{admin/admin_commands/kadmin_local:policy-failurecountinterval}]{\sphinxcrossref{\DUrole{st…
5598 …detokenize{admin/admin_commands/kadmin_local:policy-lockoutduration}]{\sphinxcrossref{\DUrole{std,…
5615 \label{\detokenize{admin/lockout:testing-account-lockout}}
5635 \label{\detokenize{admin/lockout:account-lockout-principal-state}}
5683 \label{\detokenize{admin/lockout:kdc-replication-and-account-lockout}}
5686 …al {\hyperref[\detokenize{admin/admin_commands/kprop:kprop-8}]{\sphinxcrossref{\DUrole{std,std-ref…
5708 \label{\detokenize{admin/lockout:kdc-performance-and-account-lockout}}\label{\detokenize{admin/lock…
5717 …of {\hyperref[\detokenize{admin/conf_files/kdc_conf:kdc-conf-5}]{\sphinxcrossref{\DUrole{std,std-r…
5736 \label{\detokenize{admin/lockout:kdc-setup-and-account-lockout}}
5746 …\detokenize{admin/conf_ldap:configuring-kerberos-with-openldap-back-end}}\label{\detokenize{admin/…
5768-8}]{\sphinxcrossref{\DUrole{std,std-ref}{krb5kdc}}}} and {\hyperref[\detokenize{admin/admin_comma…
5771 …in {\hyperref[\detokenize{admin/conf_files/kdc_conf:kdc-conf-5}]{\sphinxcrossref{\DUrole{std,std-r…
5772 …yperref[\detokenize{admin/admin_commands/kdb5_util:kdb5-util-8}]{\sphinxcrossref{\DUrole{std,std-r…
5776 …kenize{admin/conf_files/kdc_conf:dbmodules}]{\sphinxcrossref{\DUrole{std,std-ref}{{[}dbmodules{]}}…
5798 …in {\hyperref[\detokenize{admin/conf_files/kdc_conf:kdc-conf-5}]{\sphinxcrossref{\DUrole{std,std-r…
5809 …kenize{admin/conf_files/kdc_conf:dbmodules}]{\sphinxcrossref{\DUrole{std,std-ref}{{[}dbmodules{]}}…
5845 In {\hyperref[\detokenize{admin/conf_files/kdc_conf:kdc-conf-5}]{\sphinxcrossref{\DUrole{std,std-re…
5846 …kenize{admin/conf_files/kdc_conf:dbmodules}]{\sphinxcrossref{\DUrole{std,std-ref}{{[}dbmodules{]}}…
5859 …[\detokenize{admin/admin_commands/kdb5_ldap_util:kdb5-ldap-util-8}]{\sphinxcrossref{\DUrole{std,st…
5875 …o the section {\hyperref[\detokenize{admin/database:ops-on-ldap}]{\sphinxcrossref{\DUrole{std,std-
5918 \label{\detokenize{admin/appl_servers:application-servers}}\label{\detokenize{admin/appl_servers::d…
5923 database (see {\hyperref[\detokenize{admin/database:principals}]{\sphinxcrossref{\DUrole{std,std-re…
5938 …erref[\detokenize{admin/admin_commands/kadmin_local:kadmin-1}]{\sphinxcrossref{\DUrole{std,std-ref…
5944 …el{\detokenize{admin/appl_servers:adding-principals-to-keytabs}}\label{\detokenize{admin/appl_serv…
5958 \label{\detokenize{admin/appl_servers:removing-principals-from-keytabs}}
5971 \label{\detokenize{admin/appl_servers:using-a-keytab-to-acquire-client-credentials}}
5978 To manually obtain credentials using a keytab, use the \DUrole{xref,std,std-ref}{kinit(1)}
5998 …ize{admin/conf_files/krb5_conf:libdefaults}]{\sphinxcrossref{\DUrole{std,std-ref}{{[}libdefaults{]…
5999 {\hyperref[\detokenize{mitK5defaults:paths}]{\sphinxcrossref{\DUrole{std,std-ref}{DEFCKTNAME}}}}.
6008 service runs as a long\sphinxhyphen{}lived process. See \DUrole{xref,std,std-ref}{ccache\_definiti…
6021 \label{\detokenize{admin/appl_servers:clock-skew}}
6032 …ize{admin/conf_files/krb5_conf:libdefaults}]{\sphinxcrossref{\DUrole{std,std-ref}{{[}libdefaults{]…
6036 \label{\detokenize{admin/appl_servers:getting-dns-information-correct}}
6079 file), and then \DUrole{xref,std,std-ref}{klist(1)}, the output should list a service
6084 …ize{admin/appl_servers:configuring-your-firewall-to-work-with-kerberos-v5}}\label{\detokenize{admi…
6091 …’s {\hyperref[\detokenize{admin/conf_files/kdc_conf:kdc-conf-5}]{\sphinxcrossref{\DUrole{std,std-r…
6109 …. {\hyperref[\detokenize{admin/admin_commands/kprop:kprop-8}]{\sphinxcrossref{\DUrole{std,std-ref…
6118 \label{\detokenize{admin/host_config:host-configuration}}\label{\detokenize{admin/host_config::doc}}
6122 {\hyperref[\detokenize{admin/conf_files/krb5_conf:krb5-conf-5}]{\sphinxcrossref{\DUrole{std,std-ref…
6127 \label{\detokenize{admin/host_config:default-realm}}
6129 …ize{admin/conf_files/krb5_conf:libdefaults}]{\sphinxcrossref{\DUrole{std,std-ref}{{[}libdefaults{]…
6158 in a {\hyperref[\detokenize{admin/install_appl_srv:keytab-file}]{\sphinxcrossref{\DUrole{std,std-re…
6159 …{\hyperref[\detokenize{admin/conf_files/krb5_conf:domain-realm}]{\sphinxcrossref{\DUrole{std,std-r…
6164 If \DUrole{xref,std,std-ref}{kinit(1)} is passed the \sphinxstylestrong{\sphinxhyphen{}n} flag, it …
6179 \label{\detokenize{admin/host_config:login-authorization}}\label{\detokenize{admin/host_config:id1}}
6195 The simplest way to control local access is using \DUrole{xref,std,std-ref}{.k5login(5)}
6200 …ize{admin/conf_files/krb5_conf:libdefaults}]{\sphinxcrossref{\DUrole{std,std-ref}{{[}libdefaults{]…
6209 {\hyperref[\detokenize{admin/conf_files/krb5_conf:libdefaults}]{\sphinxcrossref{\DUrole{std,std-ref…
6213 …tokenize{admin/conf_files/krb5_conf:realms}]{\sphinxcrossref{\DUrole{std,std-ref}{{[}realms{]}}}}}…
6240 …tokenize{admin/conf_files/krb5_conf:realms}]{\sphinxcrossref{\DUrole{std,std-ref}{{[}realms{]}}}}}…
6260 modules; see \DUrole{xref,std,std-ref}{hostrealm\_plugin} for details.
6264 \label{\detokenize{admin/host_config:plugin-module-configuration}}\label{\detokenize{admin/host_con…
6268 …okenize{admin/conf_files/krb5_conf:plugins}]{\sphinxcrossref{\DUrole{std,std-ref}{{[}plugins{]}}}}}
6314 …\hyperref[\detokenize{admin/admin_commands/kadmind:kadmind-8}]{\sphinxcrossref{\DUrole{std,std-ref…
6336 \label{\detokenize{admin/host_config:kdc-location-modules}}
6341 {\hyperref[\detokenize{mitK5defaults:paths}]{\sphinxcrossref{\DUrole{std,std-ref}{LIBDIR}}}}\sphinx…
6343 {\hyperref[\detokenize{mitK5defaults:paths}]{\sphinxcrossref{\DUrole{std,std-ref}{LIBDIR}}}}\sphinx…
6347 …abel{\detokenize{admin/host_config:gssapi-mechanism-modules}}\label{\detokenize{admin/host_config:…
6350 {\hyperref[\detokenize{mitK5defaults:paths}]{\sphinxcrossref{\DUrole{std,std-ref}{SYSCONFDIR}}}}\sp…
6351 {\hyperref[\detokenize{mitK5defaults:paths}]{\sphinxcrossref{\DUrole{std,std-ref}{SYSCONFDIR}}}}\sp…
6375 …etokenize{admin/host_config:configuration-profile-modules}}\label{\detokenize{admin/host_config:pr…
6378 {\hyperref[\detokenize{admin/conf_files/krb5_conf:krb5-conf-5}]{\sphinxcrossref{\DUrole{std,std-ref…
6391 \chapter{Backups of secure hosts}
6392 \label{\detokenize{admin/backup_host:backups-of-secure-hosts}}\label{\detokenize{admin/backup_host:…
6394 When you back up a secure host, you should exclude the host’s keytab
6401 …e. (See {\hyperref[\detokenize{admin/appl_servers:add-princ-kt}]{\sphinxcrossref{\DUrole{std,std-
6403 ensure that the backups are kept as secure as the host’s root
6408 \label{\detokenize{admin/backup_host:backing-up-the-kerberos-database}}
6419 job periodically copy the dump file to a secure machine elsewhere on
6421 these backups are stored as secure as your KDCs, and to encrypt its
6424 (See {\hyperref[\detokenize{admin/database:restore-from-dump}]{\sphinxcrossref{\DUrole{std,std-ref}…
6428 \label{\detokenize{admin/pkinit:pkinit-configuration}}\label{\detokenize{admin/pkinit:pkinit}}\labe…
6438 \label{\detokenize{admin/pkinit:creating-certificates}}
6455 \label{\detokenize{admin/pkinit:generating-a-certificate-authority-certificate}}
6484 \label{\detokenize{admin/pkinit:generating-a-kdc-certificate}}
6548 \label{\detokenize{admin/pkinit:generating-client-certificates}}
6633 \label{\detokenize{admin/pkinit:configuring-the-kdc}}
6637 …’s {\hyperref[\detokenize{admin/conf_files/kdc_conf:kdc-conf-5}]{\sphinxcrossref{\DUrole{std,std-r…
6638 …std,std-ref}{{[}kdcdefaults{]}}}}} section or in a {\hyperref[\detokenize{admin/conf_files/kdc_con…
6664 …\hyperref[\detokenize{admin/admin_commands/krb5kdc:krb5kdc-8}]{\sphinxcrossref{\DUrole{std,std-ref…
6708 … {\hyperref[\detokenize{admin/conf_files/krb5_conf:krb5-conf-5}]{\sphinxcrossref{\DUrole{std,std-r…
6709 use of non\sphinxhyphen{}PKINIT client certificates, it will also be necessary to
6720 \label{\detokenize{admin/pkinit:configuring-the-clients}}
6725 … {\hyperref[\detokenize{admin/conf_files/krb5_conf:krb5-conf-5}]{\sphinxcrossref{\DUrole{std,std-r…
6726 …tokenize{admin/conf_files/krb5_conf:realms}]{\sphinxcrossref{\DUrole{std,std-ref}{{[}realms{]}}}}}…
6764-conf-5}]{\sphinxcrossref{\DUrole{std,std-ref}{krb5.conf}}}} file in the appropriate {\hyperref[\d…
6777 \label{\detokenize{admin/pkinit:anonymous-pkinit}}\label{\detokenize{admin/pkinit:id1}}
6812 …te {\hyperref[\detokenize{admin/conf_files/kdc_conf:kdc-realms}]{\sphinxcrossref{\DUrole{std,std-r…
6813 {\hyperref[\detokenize{admin/conf_files/kdc_conf:kdc-conf-5}]{\sphinxcrossref{\DUrole{std,std-ref}{…
6822 \label{\detokenize{admin/pkinit:freshness-tokens}}
6845-realms}]{\sphinxcrossref{\DUrole{std,std-ref}{{[}realms{]}}}}} subsection of the KDC’s {\hyperref…
6850 \chapter{OTP Preauthentication}
6851 \label{\detokenize{admin/otp:otp-preauthentication}}\label{\detokenize{admin/otp:otp-preauth}}\labe…
6853 OTP is a preauthentication mechanism for Kerberos 5 which uses One
6854 Time Passwords (OTP) to authenticate the client to the KDC. The OTP
6862 Additionally, our implementation of the OTP system allows for the
6869 \label{\detokenize{admin/otp:defining-token-types}}
6871 … {\hyperref[\detokenize{admin/conf_files/krb5_conf:krb5-conf-5}]{\sphinxcrossref{\DUrole{std,std-r…
6872 {\hyperref[\detokenize{admin/conf_files/kdc_conf:kdc-conf-5}]{\sphinxcrossref{\DUrole{std,std-ref}{…
6875 \PYG{p}{[}\PYG{n}{otp}\PYG{p}{]}
6891 …{\hyperref[\detokenize{mitK5defaults:paths}]{\sphinxcrossref{\DUrole{std,std-ref}{RUNSTATEDIR}}}}\…
6902 {\hyperref[\detokenize{admin/auth_indicator:auth-indicator}]{\sphinxcrossref{\DUrole{std,std-ref}{A…
6907 \label{\detokenize{admin/otp:the-default-token-type}}
6913 \PYG{p}{[}\PYG{n}{otp}\PYG{p}{]}
6925 \label{\detokenize{admin/otp:token-instance-configuration}}
6927 To enable OTP for a client principal, the administrator must define
6928 the \sphinxstylestrong{otp} string attribute for that principal. (See
6929 …dmin_commands/kadmin_local:set-string}]{\sphinxcrossref{\DUrole{std,std-ref}{set\_string}}}}.) Th…
6956 \label{\detokenize{admin/otp:other-considerations}}\begin{enumerate}
6960 FAST is required for OTP to work.
6966 \label{\detokenize{admin/spake:spake-preauthentication}}\label{\detokenize{admin/spake:spake}}\labe…
6969 …ef[\detokenize{admin/dictionary:dictionary}]{\sphinxcrossref{\DUrole{std,std-ref}{password diction…
6970 attacks}}}}. Unlike {\hyperref[\detokenize{admin/pkinit:pkinit}]{\sphinxcrossref{\DUrole{std,std-r…
6984 …ize{admin/conf_files/krb5_conf:libdefaults}]{\sphinxcrossref{\DUrole{std,std-ref}{{[}libdefaults{]…
7011 {\hyperref[\detokenize{admin/conf_files/krb5_conf:realms}]{\sphinxcrossref{\DUrole{std,std-ref}{{[}…
7019 …nize{admin/conf_files/kdc_conf:kdcdefaults}]{\sphinxcrossref{\DUrole{std,std-ref}{{[}kdcdefaults{]…
7035 \label{\detokenize{admin/dictionary:addressing-dictionary-attack-risks}}\label{\detokenize{admin/di…
7042 …hyperref[\detokenize{admin/database:policies}]{\sphinxcrossref{\DUrole{std,std-ref}{password policy
7054 {\hyperref[\detokenize{admin/lockout:lockout}]{\sphinxcrossref{\DUrole{std,std-ref}{account lockout…
7095 Enabling {\hyperref[\detokenize{admin/spake:spake}]{\sphinxcrossref{\DUrole{std,std-ref}{SPAKE prea…
7101 Using an {\hyperref[\detokenize{admin/https:https}]{\sphinxcrossref{\DUrole{std,std-ref}{HTTPS prox…
7108 …) or with {\hyperref[\detokenize{admin/pkinit:anonymous-pkinit}]{\sphinxcrossref{\DUrole{std,std-r…
7123 {\hyperref[\detokenize{admin/conf_files/krb5_conf:realms}]{\sphinxcrossref{\DUrole{std,std-ref}{{[}…
7128 …ion. If {\hyperref[\detokenize{admin/realm_config:kdc-discovery}]{\sphinxcrossref{\DUrole{std,std
7139 …rossref{\DUrole{std,std-ref}{PKINIT}}}} or {\hyperref[\detokenize{admin/otp:otp-preauth}]{\sphinxc…
7145 \label{\detokenize{admin/princ_dns:principal-names-and-dns}}\label{\detokenize{admin/princ_dns::doc…
7154 \label{\detokenize{admin/princ_dns:service-principal-names}}
7176 \label{\detokenize{admin/princ_dns:service-principal-canonicalization}}
7180 …ize{admin/conf_files/krb5_conf:libdefaults}]{\sphinxcrossref{\DUrole{std,std-ref}{{[}libdefaults{]…
7213 \label{\detokenize{admin/princ_dns:reverse-dns-mismatches}}
7225 \label{\detokenize{admin/princ_dns:overriding-application-behavior}}
7230 … {\hyperref[\detokenize{admin/conf_files/krb5_conf:krb5-conf-5}]{\sphinxcrossref{\DUrole{std,std-r…
7246 \label{\detokenize{admin/princ_dns:provisioning-keytabs}}
7257 \label{\detokenize{admin/princ_dns:specific-application-advice}}
7259 \subsection{Secure shell (ssh)}
7260 \label{\detokenize{admin/princ_dns:secure-shell-ssh}}
7271 \label{\detokenize{admin/princ_dns:openldap-ldapsearch-etc}}
7281 \label{\detokenize{admin/enctypes:encryption-types}}\label{\detokenize{admin/enctypes:enctypes}}\la…
7290 \label{\detokenize{admin/enctypes:enctypes-in-requests}}
7332 \label{\detokenize{admin/enctypes:session-key-selection}}\label{\detokenize{admin/enctypes:id1}}
7346-string}]{\sphinxcrossref{\DUrole{std,std-ref}{set\_string}}}} in {\hyperref[\detokenize{admin/adm…
7350 \label{\detokenize{admin/enctypes:choosing-enctypes-for-a-service}}
7368 \label{\detokenize{admin/enctypes:configuration-variables}}
7370 … {\hyperref[\detokenize{admin/conf_files/krb5_conf:krb5-conf-5}]{\sphinxcrossref{\DUrole{std,std-r…
7403 keys of non\sphinxhyphen{}permitted enctypes. Starting in release 1.18, this
7426 …in {\hyperref[\detokenize{admin/conf_files/kdc_conf:kdc-conf-5}]{\sphinxcrossref{\DUrole{std,std-r…
7431 …\hyperref[\detokenize{admin/admin_commands/kadmind:kadmind-8}]{\sphinxcrossref{\DUrole{std,std-ref…
7439 \label{\detokenize{admin/enctypes:enctype-compatibility}}
7441 …yperref[\detokenize{admin/conf_files/kdc_conf:encryption-types}]{\sphinxcrossref{\DUrole{std,std-r…
7620 \label{\detokenize{admin/enctypes:migrating-away-from-older-encryption-types}}
7629 …in {\hyperref[\detokenize{admin/conf_files/kdc_conf:kdc-conf-5}]{\sphinxcrossref{\DUrole{std,std-r…
7635 …erref[\detokenize{admin/admin_commands/kadmin_local:kadmin-1}]{\sphinxcrossref{\DUrole{std,std-ref…
7638 {\hyperref[\detokenize{admin/database:changing-krbtgt-key}]{\sphinxcrossref{\DUrole{std,std-ref}{Ch…
7643 …tes in {\hyperref[\detokenize{admin/database:updating-history-key}]{\sphinxcrossref{\DUrole{std,st…
7653 {\hyperref[\detokenize{admin/database:updating-master-key}]{\sphinxcrossref{\DUrole{std,std-ref}{Up…
7657 …yperref[\detokenize{admin/admin_commands/kdb5_util:kdb5-util-8}]{\sphinxcrossref{\DUrole{std,std-r…
7661 …erref[\detokenize{admin/admin_commands/k5srvutil:k5srvutil-1}]{\sphinxcrossref{\DUrole{std,std-ref…
7668 …erref[\detokenize{admin/admin_commands/kadmin_local:kadmin-1}]{\sphinxcrossref{\DUrole{std,std-ref…
7681 \label{\detokenize{admin/https:https-proxy-configuration}}\label{\detokenize{admin/https:https}}\la…
7705 \label{\detokenize{admin/https:configuring-the-clients}}
7710 … {\hyperref[\detokenize{admin/conf_files/krb5_conf:krb5-conf-5}]{\sphinxcrossref{\DUrole{std,std-r…
7711 …tokenize{admin/conf_files/krb5_conf:realms}]{\sphinxcrossref{\DUrole{std,std-ref}{{[}realms{]}}}}}…
7720 … {\hyperref[\detokenize{admin/conf_files/krb5_conf:krb5-conf-5}]{\sphinxcrossref{\DUrole{std,std-r…
7724 … {\hyperref[\detokenize{admin/conf_files/krb5_conf:krb5-conf-5}]{\sphinxcrossref{\DUrole{std,std-r…
7738 …\detokenize{admin/auth_indicator:authentication-indicators}}\label{\detokenize{admin/auth_indicato…
7742 …rossref{\DUrole{std,std-ref}{PKINIT}}}} or {\hyperref[\detokenize{admin/otp:otp-preauth}]{\sphinxc…
7750 To use authentication indicators with PKINIT or OTP, first configure
7753 …[\detokenize{admin/conf_files/kdc_conf:kdc-conf-5}]{\sphinxcrossref{\DUrole{std,std-ref}{kdc.conf}…
7754 token type definition, or specify the indicators in the \sphinxstylestrong{otp} user
7755 …g as described in {\hyperref[\detokenize{admin/otp:otp-preauth}]{\sphinxcrossref{\DUrole{std,std-r…
7767 …he {\hyperref[\detokenize{admin/conf_files/kdc_conf:kdc-realms}]{\sphinxcrossref{\DUrole{std,std-r…
7805 through the \DUrole{xref,std,std-ref}{auth\sphinxhyphen{}indicators} name
7810 \label{\detokenize{admin/admin_commands/index:administration-programs}}\label{\detokenize{admin/adm…
7813 …in_local:kadmin}}\label{\detokenize{admin/admin_commands/kadmin_local:kadmin-1}}\label{\detokenize…
7816 …cal:synopsis}}\phantomsection\label{\detokenize{admin/admin_commands/kadmin_local:kadmin-synopsis}}
7846 …\hyperref[\detokenize{admin/admin_commands/kadmind:kadmind-8}]{\sphinxcrossref{\DUrole{std,std-ref…
7872 …}}\phantomsection\label{\detokenize{admin/admin_commands/kadmin_local:kadmin-options}}\begin{descr…
7901 {\hyperref[\detokenize{admin/conf_files/krb5_conf:krb5-conf-5}]{\sphinxcrossref{\DUrole{std,std-ref…
7918 \DUrole{xref,std,std-ref}{kinit(1)} program. If this option is not specified, kadmin
7949-lists}]{\sphinxcrossref{\DUrole{std,std-ref}{Keysalt lists}}}} in {\hyperref[\detokenize{admin/co…
7990 The exit status will be non\sphinxhyphen{}zero if the query fails.
8002 \label{\detokenize{admin/admin_commands/kadmin_local:database-options}}\label{\detokenize{admin/adm…
8048 …[\detokenize{admin/admin_commands/kdb5_ldap_util:kdb5-ldap-util-8}]{\sphinxcrossref{\DUrole{std,st…
8087 … {\hyperref[\detokenize{admin/conf_files/kadm5_acl:kadm5-acl-5}]{\sphinxcrossref{\DUrole{std,std-r…
8092 \label{\detokenize{admin/admin_commands/kadmin_local:add-principal}}\label{\detokenize{admin/admin_…
8117 (\DUrole{xref,std,std-ref}{getdate} string) The expiration date of the principal.
8121 (\DUrole{xref,std,std-ref}{getdate} string) The password expiration date.
8125 (\DUrole{xref,std,std-ref}{duration} or \DUrole{xref,std,std-ref}{getdate} string) The maximum tick…
8130 (\DUrole{xref,std,std-ref}{duration} or \DUrole{xref,std,std-ref}{getdate} string) The maximum rene…
8272-lists}]{\sphinxcrossref{\DUrole{std,std-ref}{Keysalt lists}}}} in {\hyperref[\detokenize{admin/co…
8339 \label{\detokenize{admin/admin_commands/kadmin_local:modify-principal}}\label{\detokenize{admin/adm…
8370 \label{\detokenize{admin/admin_commands/kadmin_local:rename-principal}}\label{\detokenize{admin/adm…
8389 \label{\detokenize{admin/admin_commands/kadmin_local:delete-principal}}\label{\detokenize{admin/adm…
8407 \label{\detokenize{admin/admin_commands/kadmin_local:change-password}}\label{\detokenize{admin/admi…
8441-lists}]{\sphinxcrossref{\DUrole{std,std-ref}{Keysalt lists}}}} in {\hyperref[\detokenize{admin/co…
8482 \label{\detokenize{admin/admin_commands/kadmin_local:get-principal}}\label{\detokenize{admin/admin_…
8529 \label{\detokenize{admin/admin_commands/kadmin_local:list-principals}}\label{\detokenize{admin/admi…
8555 \PYG{n}{test3}\PYG{n+nd}{@SECURE}\PYG{o}{\PYGZhy{}}\PYG{n}{TEST}\PYG{o}{.}\PYG{n}{OV}\PYG{o}{.}\PYG…
8556 \PYG{n}{test2}\PYG{n+nd}{@SECURE}\PYG{o}{\PYGZhy{}}\PYG{n}{TEST}\PYG{o}{.}\PYG{n}{OV}\PYG{o}{.}\PYG…
8557 \PYG{n}{test1}\PYG{n+nd}{@SECURE}\PYG{o}{\PYGZhy{}}\PYG{n}{TEST}\PYG{o}{.}\PYG{n}{OV}\PYG{o}{.}\PYG…
8558 \PYG{n}{testuser}\PYG{n+nd}{@SECURE}\PYG{o}{\PYGZhy{}}\PYG{n}{TEST}\PYG{o}{.}\PYG{n}{OV}\PYG{o}{.}\…
8564 \label{\detokenize{admin/admin_commands/kadmin_local:get-strings}}\label{\detokenize{admin/admin_co…
8581 \label{\detokenize{admin/admin_commands/kadmin_local:set-string}}\label{\detokenize{admin/admin_com…
8604-types}]{\sphinxcrossref{\DUrole{std,std-ref}{Encryption types}}}} in {\hyperref[\detokenize{admin…
8607 \item[{\sphinxstylestrong{otp}}] \leavevmode
8609 Enables One Time Passwords (OTP) preauthentication for a client
8619 … {\hyperref[\detokenize{admin/conf_files/krb5_conf:krb5-conf-5}]{\sphinxcrossref{\DUrole{std,std-r…
8644 \PYG{n}{set\PYGZus{}string} \PYG{n}{user}\PYG{n+nd}{@FOO}\PYG{o}{.}\PYG{n}{COM} \PYG{n}{otp} \PYG{l…
8649 \label{\detokenize{admin/admin_commands/kadmin_local:del-string}}\label{\detokenize{admin/admin_com…
8666 \label{\detokenize{admin/admin_commands/kadmin_local:add-policy}}\label{\detokenize{admin/admin_com…
8686 (\DUrole{xref,std,std-ref}{duration} or \DUrole{xref,std,std-ref}{getdate} string) Sets the maximum
8691 (\DUrole{xref,std,std-ref}{duration} or \DUrole{xref,std,std-ref}{getdate} string) Sets the minimum
8710 \phantomsection\label{\detokenize{admin/admin_commands/kadmin_local:policy-maxfailure}}\begin{descr…
8720 \phantomsection\label{\detokenize{admin/admin_commands/kadmin_local:policy-failurecountinterval}}\b…
8723 (\DUrole{xref,std,std-ref}{duration} or \DUrole{xref,std,std-ref}{getdate} string) Sets the allowab…
8730 \phantomsection\label{\detokenize{admin/admin_commands/kadmin_local:policy-lockoutduration}}\begin{…
8733 (\DUrole{xref,std,std-ref}{duration} or \DUrole{xref,std,std-ref}{getdate} string) Sets the duratio…
8744-lists}]{\sphinxcrossref{\DUrole{std,std-ref}{Keysalt lists}}}} in {\hyperref[\detokenize{admin/co…
8761 \label{\detokenize{admin/admin_commands/kadmin_local:modify-policy}}\label{\detokenize{admin/admin_…
8779 \label{\detokenize{admin/admin_commands/kadmin_local:delete-policy}}\label{\detokenize{admin/admin_…
8808 \label{\detokenize{admin/admin_commands/kadmin_local:get-policy}}\label{\detokenize{admin/admin_com…
8850 \label{\detokenize{admin/admin_commands/kadmin_local:list-policies}}\label{\detokenize{admin/admin_…
8916-lists}]{\sphinxcrossref{\DUrole{std,std-ref}{Keysalt lists}}}} in {\hyperref[\detokenize{admin/co…
9011 \label{\detokenize{admin/admin_commands/kadmin_local:list-requests}}
9038 See \DUrole{xref,std,std-ref}{kerberos(7)} for a description of Kerberos environment
9043 \label{\detokenize{admin/admin_commands/kadmin_local:see-also}}
9045-ref}{kpasswd(1)}, {\hyperref[\detokenize{admin/admin_commands/kadmind:kadmind-8}]{\sphinxcrossref…
9049 …nds/kadmind:kadmind}}\label{\detokenize{admin/admin_commands/kadmind:kadmind-8}}\label{\detokenize…
9075 …erref[\detokenize{admin/admin_commands/kadmin_local:kadmin-1}]{\sphinxcrossref{\DUrole{std,std-ref…
9076 \DUrole{xref,std,std-ref}{kpasswd(1)} to administer the information in these database.
9082 …m[{{\hyperref[\detokenize{admin/conf_files/kdc_conf:kdc-conf-5}]{\sphinxcrossref{\DUrole{std,std-r…
9090 …{{\hyperref[\detokenize{admin/conf_files/kadm5_acl:kadm5-acl-5}]{\sphinxcrossref{\DUrole{std,std-r…
9094 …e} {\hyperref[\detokenize{admin/conf_files/kdc_conf:kdc-conf-5}]{\sphinxcrossref{\DUrole{std,std-r…
9095 …{\hyperref[\detokenize{mitK5defaults:paths}]{\sphinxcrossref{\DUrole{std,std-ref}{LOCALSTATEDIR}}}…
9108 {\hyperref[\detokenize{admin/conf_files/kdc_conf:kdc-conf-5}]{\sphinxcrossref{\DUrole{std,std-ref}{…
9145 …in {\hyperref[\detokenize{admin/conf_files/kdc_conf:kdc-conf-5}]{\sphinxcrossref{\DUrole{std,std-r…
9177 …ole{std,std-ref}{Database Options}}}} in {\hyperref[\detokenize{admin/admin_commands/kadmin_local:…
9185 See \DUrole{xref,std,std-ref}{kerberos(7)} for a description of Kerberos environment
9190 \label{\detokenize{admin/admin_commands/kadmind:see-also}}
9192-ref}{kpasswd(1)}, {\hyperref[\detokenize{admin/admin_commands/kadmin_local:kadmin-1}]{\sphinxcros…
9193-ldap-util-8}]{\sphinxcrossref{\DUrole{std,std-ref}{kdb5\_ldap\_util}}}}, {\hyperref[\detokenize{a…
9197 …okenize{admin/admin_commands/kdb5_util:kdb5-util}}\label{\detokenize{admin/admin_commands/kdb5_uti…
9200 …til:synopsis}}\phantomsection\label{\detokenize{admin/admin_commands/kdb5_util:kdb5-util-synopsis}}
9216 …s/kdb5_util:description}}\label{\detokenize{admin/admin_commands/kdb5_util:kdb5-util-synopsis-end}}
9235 …dmin_commands/kdb5_util:command-line-options}}\phantomsection\label{\detokenize{admin/admin_comman…
9243 …in {\hyperref[\detokenize{admin/conf_files/kdc_conf:kdc-conf-5}]{\sphinxcrossref{\DUrole{std,std-r…
9251 {\hyperref[\detokenize{admin/conf_files/kdc_conf:kdc-conf-5}]{\sphinxcrossref{\DUrole{std,std-ref}{…
9262 …in {\hyperref[\detokenize{admin/conf_files/kdc_conf:kdc-conf-5}]{\sphinxcrossref{\DUrole{std,std-r…
9273 …in {\hyperref[\detokenize{admin/conf_files/kdc_conf:kdc-conf-5}]{\sphinxcrossref{\DUrole{std,std-r…
9283 …erref[\detokenize{admin/admin_commands/kadmin_local:kadmin-1}]{\sphinxcrossref{\DUrole{std,std-ref…
9290 …mands/kdb5_util:commands}}\label{\detokenize{admin/admin_commands/kdb5_util:kdb5-util-options-end}}
9293 …te}}\phantomsection\label{\detokenize{admin/admin_commands/kdb5_util:kdb5-util-create}}\begin{quot…
9307 …/admin_commands/kdb5_util:kdb5-util-create-end}}\phantomsection\label{\detokenize{admin/admin_comm…
9320 …admin_commands/kdb5_util:kdb5-util-destroy-end}}\phantomsection\label{\detokenize{admin/admin_comm…
9329 {\hyperref[\detokenize{admin/conf_files/kdc_conf:kdc-conf-5}]{\sphinxcrossref{\DUrole{std,std-ref}{…
9333 …/admin_commands/kdb5_util:kdb5-util-stash-end}}\phantomsection\label{\detokenize{admin/admin_comma…
9408 …n/admin_commands/kdb5_util:kdb5-util-dump-end}}\phantomsection\label{\detokenize{admin/admin_comma…
9469 …s/kdb5_util:ark}}\label{\detokenize{admin/admin_commands/kdb5_util:kdb5-util-load-end}}\begin{quot…
9483 \label{\detokenize{admin/admin_commands/kdb5_util:add-mkey}}\begin{quote}
9493-types}]{\sphinxcrossref{\DUrole{std,std-ref}{Encryption types}}}} in {\hyperref[\detokenize{admin…
9499 …of {\hyperref[\detokenize{admin/admin_commands/kprop:kprop-8}]{\sphinxcrossref{\DUrole{std,std-ref…
9506 \label{\detokenize{admin/admin_commands/kdb5_util:use-mkey}}\begin{quote}
9517 active immediately. The format for \sphinxstyleemphasis{time} is \DUrole{xref,std,std-ref}{getdate…
9526 \label{\detokenize{admin/admin_commands/kdb5_util:list-mkeys}}\begin{quote}
9535 …erref[\detokenize{admin/admin_commands/kadmin_local:kadmin-1}]{\sphinxcrossref{\DUrole{std,std-ref…
9540 \label{\detokenize{admin/admin_commands/kdb5_util:purge-mkeys}}\begin{quote}
9568 \label{\detokenize{admin/admin_commands/kdb5_util:update-princ-encryption}}\begin{quote}
9832 See \DUrole{xref,std,std-ref}{kerberos(7)} for a description of Kerberos environment
9837 \label{\detokenize{admin/admin_commands/kdb5_util:see-also}}
9839 …dmin/admin_commands/kadmin_local:kadmin-1}]{\sphinxcrossref{\DUrole{std,std-ref}{kadmin}}}}, \DUro…
9843 …/admin_commands/kdb5_ldap_util:kdb5-ldap-util}}\label{\detokenize{admin/admin_commands/kdb5_ldap_u…
9846 …is}}\phantomsection\label{\detokenize{admin/admin_commands/kdb5_ldap_util:kdb5-ldap-util-synopsis}}
9856 …l:description}}\label{\detokenize{admin/admin_commands/kdb5_ldap_util:kdb5-ldap-util-synopsis-end}}
9863 …nds/kdb5_ldap_util:command-line-options}}\phantomsection\label{\detokenize{admin/admin_commands/kd…
9886 in {\hyperref[\detokenize{admin/conf_files/krb5_conf:krb5-conf-5}]{\sphinxcrossref{\DUrole{std,std-
9888 …DUrole{std,std-ref}{{[}dbdefaults{]}}}}} in {\hyperref[\detokenize{admin/conf_files/kdc_conf:kdc-c…
9892 …_util:commands}}\label{\detokenize{admin/admin_commands/kdb5_ldap_util:kdb5-ldap-util-options-end}}
9895 …antomsection\label{\detokenize{admin/admin_commands/kdb5_ldap_util:kdb5-ldap-util-create}}\begin{q…
9938 {\hyperref[\detokenize{admin/conf_files/kdc_conf:kdc-conf-5}]{\sphinxcrossref{\DUrole{std,std-ref}{…
9949 …in {\hyperref[\detokenize{admin/conf_files/kdc_conf:kdc-conf-5}]{\sphinxcrossref{\DUrole{std,std-r…
9971 (\DUrole{xref,std,std-ref}{getdate} string) Specifies maximum ticket life for
9976 (\DUrole{xref,std,std-ref}{getdate} string) Specifies maximum renewable life of
9983 …erref[\detokenize{admin/admin_commands/kadmin_local:kadmin-1}]{\sphinxcrossref{\DUrole{std,std-ref…
10003 …ds/kdb5_ldap_util:kdb5-ldap-util-create-end}}\phantomsection\label{\detokenize{admin/admin_command…
10037 (\DUrole{xref,std,std-ref}{getdate} string) Specifies maximum ticket life for
10042 (\DUrole{xref,std,std-ref}{getdate} string) Specifies maximum renewable life of
10049 …erref[\detokenize{admin/admin_commands/kadmin_local:kadmin-1}]{\sphinxcrossref{\DUrole{std,std-ref…
10065 …ds/kdb5_ldap_util:kdb5-ldap-util-modify-end}}\phantomsection\label{\detokenize{admin/admin_command…
10092 …nds/kdb5_ldap_util:kdb5-ldap-util-view-end}}\phantomsection\label{\detokenize{admin/admin_commands…
10122 …ds/kdb5_ldap_util:kdb5-ldap-util-destroy-end}}\phantomsection\label{\detokenize{admin/admin_comman…
10146 …nds/kdb5_ldap_util:kdb5-ldap-util-list-end}}\phantomsection\label{\detokenize{admin/admin_commands…
10167-8}]{\sphinxcrossref{\DUrole{std,std-ref}{krb5kdc}}}} or {\hyperref[\detokenize{admin/admin_comman…
10170 …in {\hyperref[\detokenize{admin/conf_files/kdc_conf:kdc-conf-5}]{\sphinxcrossref{\DUrole{std,std-r…
10189-policy}}\label{\detokenize{admin/admin_commands/kdb5_ldap_util:kdb5-ldap-util-stashsrvpw-end}}\ph…
10204 (\DUrole{xref,std,std-ref}{getdate} string) Specifies maximum ticket life for
10209 (\DUrole{xref,std,std-ref}{getdate} string) Specifies maximum renewable life of
10217 …erref[\detokenize{admin/admin_commands/kadmin_local:kadmin-1}]{\sphinxcrossref{\DUrole{std,std-ref…
10238-policy}}\label{\detokenize{admin/admin_commands/kdb5_ldap_util:kdb5-ldap-util-create-policy-end}}…
10265-policy}}\label{\detokenize{admin/admin_commands/kdb5_ldap_util:kdb5-ldap-util-modify-policy-end}}…
10290-policy}}\label{\detokenize{admin/admin_commands/kdb5_ldap_util:kdb5-ldap-util-view-policy-end}}\p…
10326-policy}}\label{\detokenize{admin/admin_commands/kdb5_ldap_util:kdb5-ldap-util-destroy-policy-end}…
10349 …nvironment}}\label{\detokenize{admin/admin_commands/kdb5_ldap_util:kdb5-ldap-util-list-policy-end}}
10351 See \DUrole{xref,std,std-ref}{kerberos(7)} for a description of Kerberos environment
10356 \label{\detokenize{admin/admin_commands/kdb5_ldap_util:see-also}}
10358 …dmin/admin_commands/kadmin_local:kadmin-1}]{\sphinxcrossref{\DUrole{std,std-ref}{kadmin}}}}, \DUro…
10362 …nds/krb5kdc:krb5kdc}}\label{\detokenize{admin/admin_commands/krb5kdc:krb5kdc-8}}\label{\detokenize…
10394 … {\hyperref[\detokenize{admin/conf_files/krb5_conf:krb5-conf-5}]{\sphinxcrossref{\DUrole{std,std-r…
10428 …nize{admin/conf_files/kdc_conf:kdcdefaults}]{\sphinxcrossref{\DUrole{std,std-ref}{{[}kdcdefaults{]…
10429 {\hyperref[\detokenize{admin/conf_files/kdc_conf:kdc-conf-5}]{\sphinxcrossref{\DUrole{std,std-ref}{…
10443 …ole{std,std-ref}{Database Options}}}} in {\hyperref[\detokenize{admin/admin_commands/kadmin_local:…
10469 …he {\hyperref[\detokenize{admin/conf_files/kdc_conf:kdc-conf-5}]{\sphinxcrossref{\DUrole{std,std-r…
10472 …he {\hyperref[\detokenize{admin/conf_files/kdc_conf:kdc-conf-5}]{\sphinxcrossref{\DUrole{std,std-r…
10479 See \DUrole{xref,std,std-ref}{kerberos(7)} for a description of Kerberos environment
10484 \label{\detokenize{admin/admin_commands/krb5kdc:see-also}}
10486-util-8}]{\sphinxcrossref{\DUrole{std,std-ref}{kdb5\_util}}}}, {\hyperref[\detokenize{admin/conf_f…
10487 …_commands/kdb5_ldap_util:kdb5-ldap-util-8}]{\sphinxcrossref{\DUrole{std,std-ref}{kdb5\_ldap\_util}…
10491 …in_commands/kprop:kprop}}\label{\detokenize{admin/admin_commands/kprop:kprop-8}}\label{\detokenize…
10511 …yperref[\detokenize{admin/admin_commands/kdb5_util:kdb5-util-8}]{\sphinxcrossref{\DUrole{std,std-r…
10524 {\hyperref[\detokenize{mitK5defaults:paths}]{\sphinxcrossref{\DUrole{std,std-ref}{LOCALSTATEDIR}}}}…
10528 … {\hyperref[\detokenize{admin/admin_commands/kpropd:kpropd-8}]{\sphinxcrossref{\DUrole{std,std-ref…
10545 See \DUrole{xref,std,std-ref}{kerberos(7)} for a description of Kerberos environment
10550 \label{\detokenize{admin/admin_commands/kprop:see-also}}
10552-8}]{\sphinxcrossref{\DUrole{std,std-ref}{kpropd}}}}, {\hyperref[\detokenize{admin/admin_commands/…
10553 \DUrole{xref,std,std-ref}{kerberos(7)}
10557 …ommands/kpropd:kpropd}}\label{\detokenize{admin/admin_commands/kpropd:kpropd-8}}\label{\detokenize…
10580 …he {\hyperref[\detokenize{admin/admin_commands/kprop:kprop-8}]{\sphinxcrossref{\DUrole{std,std-ref…
10587 …yperref[\detokenize{admin/admin_commands/kdb5_util:kdb5-util-8}]{\sphinxcrossref{\DUrole{std,std-r…
10588 …\hyperref[\detokenize{admin/admin_commands/krb5kdc:krb5kdc-8}]{\sphinxcrossref{\DUrole{std,std-ref…
10589 …se {\hyperref[\detokenize{admin/admin_commands/kprop:kprop-8}]{\sphinxcrossref{\DUrole{std,std-ref…
10615 …in {\hyperref[\detokenize{admin/conf_files/kdc_conf:kdc-conf-5}]{\sphinxcrossref{\DUrole{std,std-r…
10619 …yperref[\detokenize{admin/admin_commands/kproplog:kproplog-8}]{\sphinxcrossref{\DUrole{std,std-ref…
10627 {\hyperref[\detokenize{admin/admin_commands/kproplog:kproplog-8}]{\sphinxcrossref{\DUrole{std,std-r…
10645 …{\hyperref[\detokenize{mitK5defaults:paths}]{\sphinxcrossref{\DUrole{std,std-ref}{LOCALSTATEDIR}}}…
10653 …yperref[\detokenize{admin/admin_commands/kdb5_util:kdb5-util-8}]{\sphinxcrossref{\DUrole{std,std-r…
10654 …{\hyperref[\detokenize{mitK5defaults:paths}]{\sphinxcrossref{\DUrole{std,std-ref}{SBINDIR}}}}\sphi…
10676 …{\hyperref[\detokenize{mitK5defaults:paths}]{\sphinxcrossref{\DUrole{std,std-ref}{LOCALSTATEDIR}}}…
10689 …ole{std,std-ref}{Database Options}}}} in {\hyperref[\detokenize{admin/admin_commands/kadmin_local:…
10701 …ia {\hyperref[\detokenize{admin/admin_commands/kprop:kprop-8}]{\sphinxcrossref{\DUrole{std,std-ref…
10709 See \DUrole{xref,std,std-ref}{kerberos(7)} for a description of Kerberos environment
10714 \label{\detokenize{admin/admin_commands/kpropd:see-also}}
10716-8}]{\sphinxcrossref{\DUrole{std,std-ref}{kprop}}}}, {\hyperref[\detokenize{admin/admin_commands/k…
10717 \DUrole{xref,std,std-ref}{kerberos(7)}, inetd(8)
10721 …kproplog:kproplog}}\label{\detokenize{admin/admin_commands/kproplog:kproplog-8}}\label{\detokenize…
10736 …\hyperref[\detokenize{admin/admin_commands/kadmind:kadmind-8}]{\sphinxcrossref{\DUrole{std,std-ref…
10737 … {\hyperref[\detokenize{admin/admin_commands/kpropd:kpropd-8}]{\sphinxcrossref{\DUrole{std,std-ref…
10804 See \DUrole{xref,std,std-ref}{kerberos(7)} for a description of Kerberos environment
10809 \label{\detokenize{admin/admin_commands/kproplog:see-also}}
10811 …nize{admin/admin_commands/kpropd:kpropd-8}]{\sphinxcrossref{\DUrole{std,std-ref}{kpropd}}}}, \DUro…
10815 …ommands/ktutil:ktutil}}\label{\detokenize{admin/admin_commands/ktutil:ktutil-1}}\label{\detokenize…
10851 \label{\detokenize{admin/admin_commands/ktutil:read-kt}}\begin{quote}
10865 \label{\detokenize{admin/admin_commands/ktutil:write-kt}}\begin{quote}
10879 \label{\detokenize{admin/admin_commands/ktutil:clear-list}}\begin{quote}
10893 \label{\detokenize{admin/admin_commands/ktutil:delete-entry}}\begin{quote}
10907 \label{\detokenize{admin/admin_commands/ktutil:add-entry}}\begin{quote}
10927 \label{\detokenize{admin/admin_commands/ktutil:list-requests}}\begin{quote}
10973 See \DUrole{xref,std,std-ref}{kerberos(7)} for a description of Kerberos environment
10978 \label{\detokenize{admin/admin_commands/ktutil:see-also}}
10980-1}]{\sphinxcrossref{\DUrole{std,std-ref}{kadmin}}}}, {\hyperref[\detokenize{admin/admin_commands/…
10984 …vutil:k5srvutil}}\label{\detokenize{admin/admin_commands/k5srvutil:k5srvutil-1}}\label{\detokenize…
11000 or to delete non\sphinxhyphen{}current keys from a keytab.
11045 …erref[\detokenize{admin/admin_commands/kadmin_local:kadmin-1}]{\sphinxcrossref{\DUrole{std,std-ref…
11052 See \DUrole{xref,std,std-ref}{kerberos(7)} for a description of Kerberos environment
11057 \label{\detokenize{admin/admin_commands/k5srvutil:see-also}}
11059-1}]{\sphinxcrossref{\DUrole{std,std-ref}{kadmin}}}}, {\hyperref[\detokenize{admin/admin_commands/…
11063 …nds/sserver:sserver}}\label{\detokenize{admin/admin_commands/sserver:sserver-8}}\label{\detokenize…
11077 sserver and \DUrole{xref,std,std-ref}{sclient(1)} are a simple demonstration client/server
11087 …erref[\detokenize{admin/admin_commands/kadmin_local:kadmin-1}]{\sphinxcrossref{\DUrole{std,std-ref…
11088 installed as {\hyperref[\detokenize{mitK5defaults:paths}]{\sphinxcrossref{\DUrole{std,std-ref}{DEFK…
11112 …erref[\detokenize{admin/admin_commands/kadmin_local:kadmin-1}]{\sphinxcrossref{\DUrole{std,std-ref…
11113 Kerberos tickets, by using \DUrole{xref,std,std-ref}{kinit(1)}. Also, if you are running
11130 \label{\detokenize{admin/admin_commands/sserver:common-error-messages}}\begin{enumerate}
11181 …erref[\detokenize{admin/admin_commands/kadmin_local:kadmin-1}]{\sphinxcrossref{\DUrole{std,std-ref…
11203 See \DUrole{xref,std,std-ref}{kerberos(7)} for a description of Kerberos environment
11208 \label{\detokenize{admin/admin_commands/sserver:see-also}}
11210 \DUrole{xref,std,std-ref}{sclient(1)}, \DUrole{xref,std,std-ref}{kerberos(7)}, services(5), inetd(8)
11214 \label{\detokenize{mitK5defaults:mit-kerberos-defaults}}\label{\detokenize{mitK5defaults:mitk5defau…
11217 \label{\detokenize{mitK5defaults:general-defaults}}
11235 \DUrole{xref,std,std-ref}{keytab\_definition} file
11238 {\hyperref[\detokenize{mitK5defaults:paths}]{\sphinxcrossref{\DUrole{std,std-ref}{DEFKTNAME}}}}
11245 Client \DUrole{xref,std,std-ref}{keytab\_definition} file
11248 {\hyperref[\detokenize{mitK5defaults:paths}]{\sphinxcrossref{\DUrole{std,std-ref}{DEFCKTNAME}}}}
11255 … {\hyperref[\detokenize{admin/conf_files/krb5_conf:krb5-conf-5}]{\sphinxcrossref{\DUrole{std,std-r…
11258 …{\hyperref[\detokenize{mitK5defaults:paths}]{\sphinxcrossref{\DUrole{std,std-ref}{SYSCONFDIR}}}}\s…
11265 …le {\hyperref[\detokenize{admin/conf_files/kdc_conf:kdc-conf-5}]{\sphinxcrossref{\DUrole{std,std-r…
11268 {\hyperref[\detokenize{mitK5defaults:paths}]{\sphinxcrossref{\DUrole{std,std-ref}{LOCALSTATEDIR}}}}…
11278 {\hyperref[\detokenize{mitK5defaults:paths}]{\sphinxcrossref{\DUrole{std,std-ref}{SYSCONFDIR}}}}\sp…
11288 {\hyperref[\detokenize{mitK5defaults:paths}]{\sphinxcrossref{\DUrole{std,std-ref}{LOCALSTATEDIR}}}}…
11292 Master key \DUrole{xref,std,std-ref}{stash\_definition}
11295 {\hyperref[\detokenize{mitK5defaults:paths}]{\sphinxcrossref{\DUrole{std,std-ref}{LOCALSTATEDIR}}}}…
11299 … {\hyperref[\detokenize{admin/conf_files/kadm5_acl:kadm5-acl-5}]{\sphinxcrossref{\DUrole{std,std-r…
11302 {\hyperref[\detokenize{mitK5defaults:paths}]{\sphinxcrossref{\DUrole{std,std-ref}{LOCALSTATEDIR}}}}…
11306 OTP socket directory
11309 {\hyperref[\detokenize{mitK5defaults:paths}]{\sphinxcrossref{\DUrole{std,std-ref}{RUNSTATEDIR}}}}\s…
11316 {\hyperref[\detokenize{mitK5defaults:paths}]{\sphinxcrossref{\DUrole{std,std-ref}{LIBDIR}}}}\sphinx…
11320 \DUrole{xref,std,std-ref}{rcache\_definition} directory
11337 …{\hyperref[\detokenize{admin/conf_files/kdc_conf:keysalt-lists}]{\sphinxcrossref{\DUrole{std,std-r…
11377 \label{\detokenize{mitK5defaults:replica-kdc-propagation-defaults}}
11379 …he {\hyperref[\detokenize{admin/admin_commands/kprop:kprop-8}]{\sphinxcrossref{\DUrole{std,std-ref…
11380 {\hyperref[\detokenize{admin/admin_commands/kpropd:kpropd-8}]{\sphinxcrossref{\DUrole{std,std-ref}{…
11402 {\hyperref[\detokenize{mitK5defaults:paths}]{\sphinxcrossref{\DUrole{std,std-ref}{LOCALSTATEDIR}}}}…
11409 {\hyperref[\detokenize{mitK5defaults:paths}]{\sphinxcrossref{\DUrole{std,std-ref}{LOCALSTATEDIR}}}}…
11416 {\hyperref[\detokenize{mitK5defaults:paths}]{\sphinxcrossref{\DUrole{std,std-ref}{SBINDIR}}}}\sphin…
11423 {\hyperref[\detokenize{mitK5defaults:paths}]{\sphinxcrossref{\DUrole{std,std-ref}{SBINDIR}}}}\sphin…
11430 {\hyperref[\detokenize{mitK5defaults:paths}]{\sphinxcrossref{\DUrole{std,std-ref}{LOCALSTATEDIR}}}}…
11449 \label{\detokenize{mitK5defaults:default-paths-for-unix-like-systems}}\label{\detokenize{mitK5defau…
11605 \label{\detokenize{admin/env_variables:environment-variables}}\label{\detokenize{admin/env_variable…
11607 This content has moved to \DUrole{xref,std,std-ref}{kerberos(7)}.
11614 \label{\detokenize{admin/troubleshoot:trace-logging}}\label{\detokenize{admin/troubleshoot:id1}}
11625 secure library contexts (this generally applies to setuid programs and
11631 of the \DUrole{xref,std,std-ref}{kvno(1)} command:
11646 \label{\detokenize{admin/troubleshoot:list-of-errors}}
11649 \label{\detokenize{admin/troubleshoot:frequently-seen-errors}}\begin{enumerate}
11653 {\hyperref[\detokenize{admin/troubleshoot:init-creds-etype-nosupp}]{\sphinxcrossref{\DUrole{std,std
11657 {\hyperref[\detokenize{admin/troubleshoot:cert-chain-etype-nosupp}]{\sphinxcrossref{\DUrole{std,std
11661 {\hyperref[\detokenize{admin/troubleshoot:err-cert-chain-cert-expired}]{\sphinxcrossref{\DUrole{std…
11667 …etokenize{admin/troubleshoot:errors-seen-by-admins}}\phantomsection\label{\detokenize{admin/troubl…
11671 {\hyperref[\detokenize{admin/troubleshoot:kprop-no-route}]{\sphinxcrossref{\DUrole{std,std-ref}{kpr…
11675 {\hyperref[\detokenize{admin/troubleshoot:kprop-con-refused}]{\sphinxcrossref{\DUrole{std,std-ref}{…
11679 {\hyperref[\detokenize{admin/troubleshoot:kprop-sendauth-exchange}]{\sphinxcrossref{\DUrole{std,std
11682 \phantomsection\label{\detokenize{admin/troubleshoot:prop-failed-end}}
11689 …ubleshoot:kdc-has-no-support-for-encryption-type-while-getting-initial-credentials}}\label{\detoke…
11692 …leshoot:credential-verification-failed-kdc-has-no-support-for-encryption-type}}\label{\detokenize{…
11698 …ize{admin/conf_files/krb5_conf:libdefaults}]{\sphinxcrossref{\DUrole{std,std-ref}{{[}libdefaults{]…
11699 … {\hyperref[\detokenize{admin/conf_files/krb5_conf:krb5-conf-5}]{\sphinxcrossref{\DUrole{std,std-r…
11703 …admin/troubleshoot:cannot-create-cert-chain-certificate-has-expired}}\label{\detokenize{admin/trou…
11718 …[\detokenize{admin/troubleshoot:trace-logging}]{\sphinxcrossref{trace\_logging}}} output from \DUr…
11725 …enize{admin/troubleshoot:kprop-no-route-to-host-while-connecting-to-server}}\label{\detokenize{adm…
11733 …ize{admin/troubleshoot:kprop-connection-refused-while-connecting-to-server}}\label{\detokenize{adm…
11743 …kprop-server-rejected-authentication-during-sendauth-exchange-while-authenticating-to-server}}\lab…
11766 \label{\detokenize{admin/advanced/index:advanced-topics}}\label{\detokenize{admin/advanced/index::d…
11769 …n/advanced/retiring-des:retiring-des}}\label{\detokenize{admin/advanced/retiring-des:id1}}\label{\…
11773 While it was considered secure at the time, advancements in computational
11780 \label{\detokenize{admin/advanced/retiring-des:history}}
11799 \label{\detokenize{admin/advanced/retiring-des:types-of-keys}}\begin{itemize}
11831 …perref[\detokenize{admin/enctypes:enctypes}]{\sphinxcrossref{\DUrole{std,std-ref}{Encryption types…
11832 …erref[\detokenize{admin/admin_commands/kadmin_local:kadmin-1}]{\sphinxcrossref{\DUrole{std,std-ref…
11850 \label{\detokenize{admin/advanced/retiring-des:upgrade-procedure}}
11853 to a modern version of krb5 that supports non\sphinxhyphen{}DES keys, so that the
11858 …in {\hyperref[\detokenize{admin/conf_files/kdc_conf:kdc-conf-5}]{\sphinxcrossref{\DUrole{std,std-r…
11873 …erref[\detokenize{admin/admin_commands/kadmin_local:kadmin-1}]{\sphinxcrossref{\DUrole{std,std-ref…
11903 \label{\detokenize{admin/advanced/retiring-des:the-krbtgt-key-and-kdc-keys}}
11916 (see {\hyperref[\detokenize{admin/database:changing-krbtgt-key}]{\sphinxcrossref{\DUrole{std,std-re…
11945 in {\hyperref[\detokenize{admin/enctypes:session-key-selection}]{\sphinxcrossref{\DUrole{std,std-re…
11974 …bed in {\hyperref[\detokenize{admin/enctypes:session-key-selection}]{\sphinxcrossref{\DUrole{std,s…
11998 are rekeyed to non\sphinxhyphen{}DES enctypes. Such problems can be detected early
12003 \label{\detokenize{admin/advanced/retiring-des:adding-strong-keys-to-application-servers}}
12008 …nize{admin/admin_commands/kadmin_local:kadmin-1}]{\sphinxcrossref{\DUrole{std,std-ref}{kadmin}}}} …
12036 \label{\detokenize{admin/advanced/retiring-des:adding-strong-keys-by-default}}
12039 …ge {\hyperref[\detokenize{admin/conf_files/kdc_conf:kdc-conf-5}]{\sphinxcrossref{\DUrole{std,std-r…
12041 …erref[\detokenize{admin/admin_commands/k5srvutil:k5srvutil-1}]{\sphinxcrossref{\DUrole{std,std-ref…
12064 …version supporting non\sphinxhyphen{}DES keys. See {\hyperref[\detokenize{admin/enctypes:enctypes…
12066 Only when the service is configured to accept non\sphinxhyphen{}DES keys should
12099 \label{\detokenize{admin/advanced/retiring-des:removing-des-keys-from-usage}}
12115 …rref[\detokenize{admin/admin_commands/kadmin_local:add-principal}]{\sphinxcrossref{\DUrole{std,std
12186 … {\hyperref[\detokenize{admin/conf_files/krb5_conf:krb5-conf-5}]{\sphinxcrossref{\DUrole{std,std-r…
12193 \label{\detokenize{admin/advanced/retiring-des:support-for-legacy-services}}
12195 If there remain legacy services which do not support non\sphinxhyphen{}DES enctypes
12215 \label{\detokenize{admin/advanced/retiring-des:the-database-master-key}}
12224 broken by non\sphinxhyphen{}cryptographic means. As such, upgrading \sphinxcode{\sphinxupquote{K/M…
12229 …yperref[\detokenize{admin/admin_commands/kdb5_util:kdb5-util-8}]{\sphinxcrossref{\DUrole{std,std-r…
12236 \label{\detokenize{admin/various_envs:various-links}}\label{\detokenize{admin/various_envs::doc}}
12271 \sphinxurl{https://docs.oracle.com/cd/E19253-01/816-4557/trouble-1/index.html}
12275 \sphinxurl{https://docs.microsoft.com/en-us/previous-versions/tn-archive/bb463167(v=technet.10})\#E…
12279 \sphinxurl{https://bugs.launchpad.net/ubuntu/+source/libpam-heimdal/+bug/86528}