The following planning work sheet contains information that you need to complete before completing these scenario tasks. The following planning work sheet illustrates the type of information you need before you begin setting up cross realm trust.
Questions | Answers |
---|---|
Is your i5/OS™ V5R3 or later (5722-SS1)? | Yes |
Are the following options and licensed products installed
on iSeries™ A:
|
Yes |
Are the following licensed products installed
on iSeries B:
|
Yes |
Have you installed Windows 2000 on all of your PCs? | Yes |
Is iSeries Access for Windows (5722-XE1) installed on the PC used to administer network authentication service? | Yes |
Have you installed iSeries Navigator and the following subcomponents
on the PC used to administer network authentication service?
|
Yes |
Have you installed the latest iSeries Access for Windows service pack? See iSeries Access for the latest service pack. | Yes |
Do you have *ALLOBJ special authority on the iSeries servers? | Yes |
Do you have administrative authorities on the Windows 2000 server? | Yes |
Do you have your DNS configured and the correct host names for your iSeries and Kerberos server? | Yes |
On which operating system do you want to
configure the Kerberos server?
|
i5/OS PASE |
Have you applied the latest program temporary fixes (PTFs)? | Yes |
Is the iSeries system time within five minutes of the Kerberos server's system time? If not see Synchronize system times. | Yes |
The following planning work sheet illustrates the type of information you need before you begin setting up cross realm trust.
Planning work sheet for cross realm trust | Answers |
---|---|
What are the names of the realms for which you want
to establish a trusted relationship?
|
ORDEPT.MYCO.COM |
Have all i5/OS service principals and user principals been added to their respective Kerberos servers? | Yes |
What is the default user name for the i5/OS PASE administrator? What is the password you want to specify for the i5/OS PASE administrator? Note: This
must be the same password you used when you created the Kerberos server in i5/OS PASE.
Any and all passwords specified in this scenario are for example purposes
only. To prevent a compromise to your system or network security, you should
never use these passwords as part of your own configuration.
|
User name: admin/admin |
What are the names of the principals that will be used
to set up cross realm trust? What is the password for each of these principals? Note: Any
and all passwords specified in this scenario are for example purposes only.
To prevent a compromise to your system or network security, you should never
use these passwords as part of your own configuration.
|
Principal: Principal: |
What are the fully qualified host names for each of
the Kerberos servers for these realms?
|
kdc1.ordept.myco.com |
Are the system times for all systems within five minutes of one another? If not see Synchronize system times. | Yes |