Lines Matching refs:code
421 @samp{APPROVED} on standard out and exit with exit code 0. If it
424 should exit with exit code 0. In case of a fatal error, the
426 error and exit with a non-zero error code.
451 the source code distribution. It requires that the cracklib library
510 @code{hprop} on the master:
619 In @code{des} there is the Kerberos 4 salt
623 In @code{arcfour} (the encryption type that Microsoft Windows 2000 uses)
627 @code{[kadmin]default_keys} in @file{krb5.conf} controls
630 The syntax of @code{[kadmin]default_keys} is
633 @code{salt-type} is the type of salt (pw-salt or afs3-salt), and the
641 @item @code{v4} (or @code{des:pw-salt:})
647 @item @code{v5} (or @code{pw-salt})
649 @code{pw-salt} uses the default salt for each encryption type is
653 @item @code{afs3-salt}
655 @code{afs3-salt} is the salt that is used with Transarc kaserver. It's
808 @code{[capaths]} section.
821 the transited realms must be listed as trusted in the @code{[capaths]}
825 The syntax for @code{[capaths]} section is:
834 In the following example, the realm @code{STACKEN.KTH.SE} only has
835 direct cross-realm set up with @code{KTH.SE}. @code{KTH.SE} has
836 direct cross-realm set up with @code{STACKEN.KTH.SE} and @code{SU.SE}.
837 @code{DSV.SU.SE} only has direct cross-realm set up with @code{SU.SE}.
838 The goal is to allow principals in the @code{DSV.SU.SE} or
839 @code{SU.SE} realms to authenticate to services in
840 @code{STACKEN.KTH.SE}. This is done with the following
841 @code{[capaths]} entry on either the server accepting authentication
842 or on the KDC for @code{STACKEN.KTH.SE}.
855 @code{SU.SE} transiting through @code{KTH.SE} to
856 @code{STACKEN.KTH.SE}. The second entry allows cross-realm
857 authentication from clients in @code{DSV.SU.SE} transiting through
858 both @code{SU.SE} and @code{KTH.SE} to @code{STACKEN.KTH.SE}.
867 The order of the @code{PERMITTED-CROSS-REALMS} is not important when
872 The @code{[capaths]} section is also used for another purpose: to tell
875 by either putting a @code{[capaths]} entry in the configuration of the
882 For client configuration, the order of @code{PERMITTED-CROSS-REALMS}
886 For example, again consider the @code{[capaths]} entry above for the
887 case of a client in the @code{SU.SE} realm, and assume that the client
888 or the @code{SU.SE} KDC has that @code{[capaths]} entry. If the
890 @code{STACKEN.KTH.SE} realm, that entry says to first authenticate
891 cross-realm to the @code{KTH.SE} realm (the first realm listed in the
892 @code{PERMITTED-CROSS-REALMS} section), and then from there to
893 @code{STACKEN.KTH.SE}.
895 Each entry in @code{[capaths]} can only give the next hop, since only
896 the first realm in @code{PERMITTED-CROSS-REALMS} is used. If, for
897 instance, a client in @code{DSV.SU.SE} had a @code{[capaths]}
898 configuration as above but without the first block for @code{SU.SE},
899 they would not be able to reach @code{STACKEN.KTH.SE}. They would get
900 as far as @code{SU.SE} based on the @code{DSV.SU.SE} entry in
901 @code{[capaths]} and then attempt to go directly from there to
902 @code{STACKEN.KTH.SE} and get stuck (unless, of course, the
903 @code{SU.SE} KDC had the additional entry required to tell the client
904 to go through @code{KTH.SE}).
908 One common place where a @code{[capaths]} configuration is desirable
917 @code{EXAMPLE.COM}, a Windows Active Directory realm
918 @code{WIN.EXAMPLE.COM}, and then child Active Directory realms
919 @code{ENGR.WIN.EXAMPLE.COM} and @code{SALES.WIN.EXAMPLE.COM}. The
921 services in any of these realms. The @code{EXAMPLE.COM} KDC (and
923 @code{[capaths]} section as follows:
939 The first two blocks allow clients in the @code{ENGR.WIN.EXAMPLE.COM}
940 and @code{SALES.WIN.EXAMPLE.COM} realms to authenticate to services in
941 the @code{EXAMPLE.COM} realm. The third block tells the client (or
943 @code{WIN.EXAMPLE.COM} to reach these realms. Both sides of the
961 will try to find a @code{SRV} resource record (RR) for the realm. If no
962 SRV RRs are found, it will fall back to looking for an @code{A} RR for
975 An example of the configuration for the realm @code{EXAMPLE.COM}:
1033 @code{--with-openldap=/usr/local} (adjust according to where you have
1369 certificates and the code will try to match the private key and
1428 PIN code for SoftToken (slot):