head 1.2; access; symbols perseant-exfatfs-base-20250801:1.2 perseant-exfatfs-base-20240630:1.2 perseant-exfatfs:1.2.0.46 perseant-exfatfs-base:1.2 cjep_sun2x:1.2.0.44 cjep_sun2x-base:1.2 cjep_staticlib_x-base1:1.2 cjep_staticlib_x:1.2.0.42 cjep_staticlib_x-base:1.2 phil-wifi-20200421:1.2 phil-wifi-20200411:1.2 phil-wifi-20200406:1.2 pgoyette-compat-merge-20190127:1.2 pgoyette-compat-20190127:1.2 pgoyette-compat-20190118:1.2 pgoyette-compat-1226:1.2 pgoyette-compat-1126:1.2 pgoyette-compat-1020:1.2 pgoyette-compat-0930:1.2 pgoyette-compat-0906:1.2 pgoyette-compat-0728:1.2 pgoyette-compat-0625:1.2 pgoyette-compat-0521:1.2 pgoyette-compat-0502:1.2 pgoyette-compat-0422:1.2 pgoyette-compat-0415:1.2 pgoyette-compat-0407:1.2 pgoyette-compat-0330:1.2 pgoyette-compat-0322:1.2 pgoyette-compat-0315:1.2 pgoyette-compat:1.2.0.40 pgoyette-compat-base:1.2 perseant-stdc-iso10646:1.2.0.38 perseant-stdc-iso10646-base:1.2 prg-localcount2-base3:1.2 prg-localcount2-base2:1.2 prg-localcount2-base1:1.2 prg-localcount2:1.2.0.36 prg-localcount2-base:1.2 pgoyette-localcount-20170426:1.2 bouyer-socketcan-base1:1.2 pgoyette-localcount-20170320:1.2 bouyer-socketcan:1.2.0.34 bouyer-socketcan-base:1.2 pgoyette-localcount-20170107:1.2 pgoyette-localcount-20161104:1.2 localcount-20160914:1.2 pgoyette-localcount-20160806:1.2 pgoyette-localcount-20160726:1.2 pgoyette-localcount:1.2.0.32 pgoyette-localcount-base:1.2 netbsd-5-2-3-RELEASE:1.2 netbsd-5-1-5-RELEASE:1.2 yamt-pagecache-base9:1.2 yamt-pagecache-tag8:1.2 tls-earlyentropy:1.2.0.28 tls-earlyentropy-base:1.2 riastradh-xf86-video-intel-2-7-1-pre-2-21-15:1.2 riastradh-drm2-base3:1.2 netbsd-5-2-2-RELEASE:1.2 netbsd-5-1-4-RELEASE:1.2 netbsd-5-2-1-RELEASE:1.2 netbsd-5-1-3-RELEASE:1.2 agc-symver:1.2.0.30 agc-symver-base:1.2 tls-maxphys-base:1.2 yamt-pagecache-base8:1.2 netbsd-5-2:1.2.0.26 yamt-pagecache-base7:1.2 netbsd-5-2-RELEASE:1.2 netbsd-5-2-RC1:1.2 yamt-pagecache-base6:1.2 yamt-pagecache-base5:1.2 yamt-pagecache-base4:1.2 netbsd-5-1-2-RELEASE:1.2 netbsd-5-1-1-RELEASE:1.2 yamt-pagecache-base3:1.2 yamt-pagecache-base2:1.2 yamt-pagecache:1.2.0.24 yamt-pagecache-base:1.2 bouyer-quota2-nbase:1.2 bouyer-quota2:1.2.0.22 bouyer-quota2-base:1.2 matt-nb5-pq3:1.2.0.20 matt-nb5-pq3-base:1.2 netbsd-5-1:1.2.0.18 netbsd-5-1-RELEASE:1.2 netbsd-5-1-RC4:1.2 netbsd-5-1-RC3:1.2 netbsd-5-1-RC2:1.2 netbsd-5-1-RC1:1.2 netbsd-5-0-2-RELEASE:1.2 netbsd-5-0-1-RELEASE:1.2 jym-xensuspend-nbase:1.2 netbsd-5-0:1.2.0.16 netbsd-5-0-RELEASE:1.2 netbsd-5-0-RC4:1.2 netbsd-5-0-RC3:1.2 netbsd-5-0-RC2:1.2 jym-xensuspend:1.2.0.14 jym-xensuspend-base:1.2 netbsd-5-0-RC1:1.2 netbsd-5:1.2.0.12 netbsd-5-base:1.2 mjf-devfs2:1.2.0.10 mjf-devfs2-base:1.2 yamt-pf42-base4:1.2 yamt-pf42-base3:1.2 hpcarm-cleanup-nbase:1.2 yamt-pf42-base2:1.2 yamt-pf42:1.2.0.8 yamt-pf42-base:1.2 keiichi-mipv6:1.2.0.6 keiichi-mipv6-base:1.2 cube-autoconf:1.2.0.4 cube-autoconf-base:1.2 hpcarm-cleanup:1.2.0.2 hpcarm-cleanup-base:1.2 krb4-1-1:1.1.1.1 KTH-KRB:1.1.1; locks; strict; comment @# @; 1.2 date 2001.09.24.12.37.59; author wiz; state dead; branches; next 1.1; 1.1 date 2001.09.17.12.10.06; author assar; state Exp; branches 1.1.1.1; next ; 1.1.1.1 date 2001.09.17.12.10.06; author assar; state Exp; branches; next ; desc @@ 1.2 log @Remove formatted man pages. Ok'd by joda. @ text @ KERBEROS(8) UNIX System Manager's Manual KERBEROS(8) NNAAMMEE kkeerrbbeerrooss - the kerberos daemon SSYYNNPPOOSSIISS kkeerrbbeerrooss [--mmnnss] [--aa _m_a_x _a_g_e] [--ii _a_d_d_r_e_s_s] [--ll _l_o_g] [--pp _p_a_u_s_e] [--PP _p_o_r_t_s_p_e_c] [--rr _r_e_a_l_m] [_d_a_t_a_b_a_s_e] DDEESSCCRRIIPPTTIIOONN This is the kkeerrbbeerrooss daemon. Options: --aa Set the _m_a_x _a_g_e before the database is considered stale. --ii Only listen on _a_d_d_r_e_s_s. Normally, the kerberos server listens on all addresses of all interfaces. --ll Write the log to _l_o_g --mm Run manually and prompt for master key. --nn Do not check max age. --pp Pause for _p_a_u_s_e before dying. --PP Listen to the ports specified by _p_o_r_t_s_p_e_c. This should be a white-space separated list of port specificatios. A port specifi- cation follows the format: _p_o_r_t[/_p_r_o_t_o_c_o_l]. The _p_o_r_t can be ei- ther a symbolic port name (from _/_e_t_c_/_s_e_r_v_i_c_e_s), or a number; _p_r_o_t_o_c_o_l _c_a_n _b_e _e_i_t_h_e_r udp, or tcp. If left out, the KDC will listen to both UDP and TCP sockets on the specified port. The special string + mean that the default set of ports (TCP and UDP on ports 88 and 750) should be included. --rr Run as a server for realm _r_e_a_l_m --ss Set slave parameters. This will enable check to see if data is getting too stale relative to the master. If no _d_a_t_a_b_a_s_e is given a default datbase will be used, normally _/_v_a_r_/_k_e_r_b_e_r_o_s_/_p_r_i_n_c_i_p_a_l. DDIIAAGGNNOOSSTTIICCSS The server logs several messages in a log file (_/_v_a_r_/_r_u_n_/_k_e_r_b_e_r_o_s_._l_o_g by default). The logging mechanism opens and closes the log file for each message, so you can safely rename the log file when the server is run- ning. OOppeerraattiioonnaall mmeessssaaggeess These are normal messages that you will see in the log. They might be followed by some error message. Getting key for _R_E_A_L_M The server fetched the key for `krbtgt.REALM' for the specific realm. You will see this at startup, and for every attempt to use cross realm authentication. Starting Kerberos for _R_E_A_L_M (kvno _k_v_n_o) You will see this also if you start with --mm. AS REQ _n_a_m_e_._i_n_s_t_a_n_c_e_@@_R_E_A_L_M for _s_n_a_m_e_._s_i_n_s_t_a_n_c_e from _i_p_-_n_u_m_b_e_r An initial (password authenticated) request was received. APPL REQ _n_a_m_e_._i_n_s_t_a_n_c_e_@@_R_E_A_L_M for _s_n_a_m_e_._s_i_n_s_t_a_n_c_e from _i_p_-_n_u_m_b_e_r A tgt-based request for a ticket was made. EErrrroorr mmeessssaaggeess These messages reflects misconfigured clients, invalid requests, or pos- sibly attepted attacks. UNKNOWN _n_a_m_e_._i_n_s_t_a_n_c_e The server received a request with an unknown principal. This is most likely because someone typed the wrong name at a login prompt. It could also be someone trying to get a list of possible users. Unknown realm _R_E_A_L_M from _i_p_-_n_u_m_b_e_r There isn't a principal for `krbtgt.REALM' in the database. Can't hop realms: _R_E_A_L_M_1 -> _R_E_A_L_M_2 There was a request for a ticket for another realm. This might be because of a misconfigured client. Principal not unique _n_a_m_e_._i_n_s_t_a_n_c_e There is more than one entry for this principal in the database. This is not very good. Null key _n_a_m_e_._i_n_s_t_a_n_c_e Someone tried to use a principal that for some reason doesn't have a key. Incorrect master key version for _n_a_m_e_._i_n_s_t_a_n_c_e : _n_u_m_b_e_r (should be _n_u_m_- _b_e_r) The principal has it's key encrypted with the wrong master key. Principal _n_a_m_e_._i_n_s_t_a_n_c_e expired at _d_a_t_e The principal's key has expired. krb_rd_req from _i_p_-_n_u_m_b_e_r: _e_r_r_o_r_-_m_e_s_s_a_g_e The message couldn't be decoded properly. The error message will give you further hints. You will see this if someone is trying to use expired tickets. Unknown message type: _n_u_m_b_e_r from _i_p_-_n_u_m_b_e_r The message received was not one that is understood by this serv- er. Can't authorize password changed based on TGT Someone tried to get a `changepw.kerberos' via a tgt exchange. This is because of a broken client, or possibly an attack. KRB protocol version mismatch (_n_u_m_b_e_r) The server received a request with an unknown version number. FFaattaall eerrrroorr mmeessssaaggeess The following messages indicate problems when starting the server. Database unavailable! There was some problem reading the database. Database currently being updated! Someone is currently updating the database (possibly via krop). Database out of date! The database is older than the maximum age specified. Couldn't get master key. The master key file wasn't found or the file is damaged. Can't verify master key. The key in the keyfile doesn't match the current databse. Ticket granting ticket service unknown The database doesn't contain a `krbtgt.REALM' for the local realm. SSEEEE AALLSSOO kprop(8), kpropd(8) KTH-KRB September 26, 1997 3 @ 1.1 log @Initial revision @ text @@ 1.1.1.1 log @import krb4-1.1 @ text @@