Jump to content United States-English
HP.com Home Products and Services Support and Drivers Solutions How to Buy
» Contact HP
More options
HP.com home
HP-UX 11i Version 3 Release Notes: HP 9000 and HP Integrity Servers > Chapter 8 Security

Kerberos Client

» 

Technical documentation

Complete book in PDF
» Feedback
Content starts here

 » Table of Contents

Kerberos Client version 1.3.5.03 helps to provide Kerberos authentication and strong cryptography for secure communication over the network.

Summary of Change

What’s New for Customers Migrating from HP-UX 11i v1 September 2005?

Kerberos Client version 1.3.5.03 includes the following features new from Kerberos Client version 1.0:

  • Administrators can now control the behavior of Kerberized login applications that call the krb5_kuserok() API provided by the libkrb5.sl library. In earlier versions of Kerberos Client, krb5_kuserok() checked the .k5login file in the user’s home directory for access permissions. This enabled users to modify the .k5login file and allow access to others.

  • Administrators can now create files with the name .k5login.username in the /etc/krb5 directory. Administrators can also create symbolic links pointing to the .k5login file in the user’s home directory. If the /etc/krb5 directory does not exist, krb5_kuserok() continues to check the .k5login file in the user’s home directory. If the /etc/krb5 directory exists, the krb5_kuserok() API ignores any corresponding .k5login files in the user’s home directory while making authorization decisions. The format of the entries in the new files in /etc/krb5 continues to be the same as that of the .k5login file in the user’s home directory.

  • SASL/GSS-API bind to Netscape Directory Server used to fail when SSL was enabled. This problem has been fixed in this release.

  • Support for powerful cryptographic algorithms like 3DES, RC4, and AES

  • Support for IPv6

  • Support for TCP. Kerberos Client libraries can now use TCP to connect to KDC. Libraries can use TCP to communicate with Microsoft KDCs (domain controllers) if they issue tickets with excessive PAC data.

  • All relevant security fixes up to version 1.5.1 made by MIT in the open source version of Kerberos Client

What’s New for Customers Migrating from HP-UX 11i v2 June 2006?

“What’s New for Customers Migrating from HP-UX 11i v1 September 2005?”

Impact

There is no impact other than that previously listed.

Compatibility

There are no known compatibility issues.

Performance

There are no known performance issues.

Documentation

Following Kerberos Client 1.3.5.03 documents are available on http://docs.hp.com in the Internet and Security Solutions section:

  • Release Notes

  • Configuration Guide for Kerberos Client Products

The following manpages are also available with Kerberos Client 1.3.5.03:

Obsolescence

Not applicable

Printable version
Privacy statement Using this site means you accept its terms Feedback to webmaster
© 2006-2007 Hewlett-Packard Development Company, L.P.