Kerberos 命令使用

认证登录

kinit admin/admin@EXAMPLE.COM

Password for admin/admin@EXAMPLE.COM: 123456

查询登录

klist

Ticket cache: FILE:/tmp/krb5cc_0

Default principal: admin/admin@EXAMPLE.COM

 

Valid starting                      Expires                                Service principal

2018-07-12T00:54:55        2018-07-13T00:54:55          krbtgt/EXAMPLE.COM@EXAMPLE.COM

退出

kdestory

klist

klist: No credentials cache found (filename: /tmp/krb5cc_0)

登录管理KDC服务器

kadmin.local

Authenticating as principal root/admin@EXAMPLE.COM with password.

kadmin.local:

查看用户列表

listprincs

K/M@EXAMPLE.COM

activity_analyzer/host1.demo.com@EXAMPLE.COM

activity_explorer/host1.demo.com@EXAMPLE.COM

admin/admin@EXAMPLE.COM

...

修改账号密码

kadmin.local

Authenticating as principal root/admin@EXAMPLE.COM with password.

kadmin.local: change_password admin/admin@EXAMPLE.COM

Enter password for principal "admin/admin@EXAMPLE.COM": 123456

Re-enter password for principal "admin/admin@EXAMPLE.COM": 123456

Password for "admin/admin@EXAMPLE.COM" changed.

创建用户

kadmin.local

Authentication as principal root/admin@EXAMPLE.COM with password.

kadmin.local: add_principal test1

WARNING: no policy specified for test1@EXAMPLE.COM; defaulting to no policy

Enter password for prncipal "test1@EXAMPLE.COM": 123456

Re-enter password for pricipal "test1@EXAMPLE.COM": 123456

Principal "test1@EXAMPLE.COM" created.

删除用户

kadmin.local

Authenticating as principal root/admin@EXAMPLE.COM with password.

kadmin.local: delete_principal teset1

Are you sure you want to delete the principal "test1@EXAMPLE.COM"?(yes/no): yes

Principal "test1@EXAMPLE.COM" deleted.

Make sure that you have removed this principal from all ACLs before reusing.

只导出用户keytab文件(并且不要修改密码)

kadmin.local

Authenticating as principal root/admin@EXAMPLE.COM with password.

kadmin.local: xst -k admin.keytab -norandkey admin/admin@EXAMPLE.COM

Entry for principal admin/admin@EXAMPLE.COM with kvno 6, encryption type aes256-cts-hmac-sha1-96 add keytab WRFILE:admin.keytab.

......

使用keytab验证是否可以登录

kinit -kt /etc/security/keytabs/admin.keytab admin/admin@EXAMPLE.COM

 

 

“相关推荐”对你有帮助么?

  • 非常没帮助
  • 没帮助
  • 一般
  • 有帮助
  • 非常有帮助
提交
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值