Configure Windows 2000 and Windows XP workstations

Note: This step is optional for configuring a Kerberos server in i5/OS™ PASE. If you intend to create a single signon environment after configuring the Kerberos server, you must complete this step. If not, skip to Step 9 (Configure network authentication service).

Configure the client workstations as part of a workgroup by setting the Kerberos realm and Kerberos server on the workstation. You will also need to set a password that will be associated with the workstation.

Note: Any and all passwords specified in this scenario are for example purposes only. To prevent a compromise to your system or network security, you should never use these passwords as part of your own configuration.

To configure the workstations, complete these steps:

  1. From a command prompt on the Windows® 2000 workstation, enter:
    C:> ksetup /setdomain MYCO.COM
    C:> ksetup /addkdc MYCO.COM kdc1.myco.com
  2. Set the local machine account password by entering this at the Windows 2000 workstation command prompt:
    C:> ksetup /setmachpassword secret1
  3. Map John Day's Kerberos user principal (day@MYCO.COM) to his Windows 2000 user name (johnday). Enter this at the Windows 2000 workstation command prompt:
    C:> ksetup /mapuser day@MYCO.COM johnday
  4. To verify that John Day's Kerberos user principal maps to his Windows 2000 user name, enter this at the Windows 2000 workstation command prompt:
    C:> ksetup
    and view the results.
  5. Restart the PC for the changes to take effect.
  6. Repeat these steps for Karen Jones' workstation, but specify the following information:
    • Local machine account password: secret2
    • Kerberos user principal: jones@MYCO.COM
    • Windows 2000 user name: karenjones