Complete the planning work sheets

The following planning work sheets illustrates the type of information you need before you begin using iSeries™ Navigator to propagate the configuration on a model system to target systems.

Table 1. Propagate network authentication service - prerequisite work sheet
Prerequisite work sheet Answers
Is your i5/OS™ V5R3 (5722-SS1) or later for the following systems:
  • Central system
  • iSeries A
  • iSeries B
  • iSeries C
Yes
Have you applied the latest program temporary fixes (PTFs)? Yes
For iSeries D, is your i5/OS V5R2 (5722-SS1) or later? Yes
For iSeries D, have you applied the latest program temporary fixes (PTFs), including the following:
  • SI08977
  • SI08979
 
Are the following options and licensed products installed on all your iSeries systems?
  • i5/OS Host Servers (5722-SS1 Option 12)
  • iSeries Access for Windows® (5722-XE1)
  • Start of changeNetwork Authentication Enablement (5722-NAE) if you are using V5R4 or laterEnd of change
  • Start of changeCryptographic Access Provider (5722-AC3) if you are running V5R3End of change
Yes
Is iSeries Access for Windows (5722-XE1) installed on the administrator's PC? Yes
Is iSeries Navigator installed on the administrator's PC?
  • Is the Network subcomponent of iSeries Navigator installed on the administrator's PC?
  • Is the Security subcomponent of iSeries Navigator installed on the administrator's PC?
Yes
Have you installed the latest IBMe(logo) server iSeries Access for Windows service pack? See iSeries Accesslink outside the Information Center for the latest service pack. Yes
Do you have *SECADM, *ALLOBJ, and *IOSYSCFG special authorities? Yes
Do you have one of the following systems acting as the Kerberos server? If yes, specify which system.
  1. Microsoft® Windows 2000 Server
    Note: Microsoft Windows 2000 Server uses Kerberos authentication as its default security mechanism.
  2. Windows Server 2003
  3. i5/OS PASE (V5R3 or later)
  4. AIX® server
  5. zSeries®
Yes, Windows 2000 Server
For Windows 2000 Server and Windows Server 2003, do you have Windows Support Tools (which provides the ktpass tool) installed? Yes
Is the iSeries system time within 5 minutes of the system time on the Kerberos server? If not see Synchronize system times. Yes
Table 2. Synchronize functions planning work sheet
Questions Answers
What is the name of the system group? MyCo system group
What systems will be included in this system group? iSeries B, iSeries C, iSeries D
What functions do you plan to propagate to this system group? Network authentication service
For which services do you want to create keytab entries?
  • i5/OS Kerberos Authentication
  • LDAP
  • iSeries IBM® HTTP Server
  • iSeries NetServer™
i5/OS Kerberos Authentication
What are the service principal names for the iSeries systems to which you want to propagate configuration?

krbsvr400/iseriesa.myco.com@MYCO.COM
krbsvr400/iseriesb.myco.com@MYCO.COM
krbsvr400/iseriesc.myco.com@MYCO.COM
krbsvr400/iseriesd.myco.com@MYCO.COM

What are the passwords that are associated with each of these principals?
Note: All passwords are for example purposes only and should not be used in any actual configuration.

The password for the principals for iSeries A, B, and C will be iseriesa123. The password for the principal for iSeries D will be iseriesd123.

What is the fully qualified host name for each iSeries server?
Note: All host names are for example purposes only and should not be used in any actual configuration.

iseriesa.myco.com
iseriesb.myco.com
iseriesc.myco.com
iseriesd.myco.com

What is the name of the Windows 2000 domain?
Note: A Windows 2000 domain is similar to a Kerberos realm. Microsoft Active Directory uses Kerberos authentication as its default security mechanism.
MYCO.COM
Table 3. Network authentication service planning work sheet for iSeries D
Questions Answers
What is the name of the Kerberos default realm to which your iSeries will belong?
Note: A Windows 2000 domain is similar to a Kerberos realm. Microsoft Active Directory uses Kerberos authentication as its default security mechanism.
MYCO.COM
Are you using Microsoft Active Directory? Yes
What is the Kerberos server for this Kerberos default realm? What is the port on which the Kerberos server listens?

KDC: kdc1.myco.com
Port: 88

Note: This is the default port for the Kerberos server.
Do you want to configure a password server for this default realm? If yes, answer the following questions:

What is name of the password server for this Kerberos server?
What is the port on which the password server listens?

Yes

Password server: kdc1.myco.com
Port: 464

Note: This is the default port for the password server.
For which services do you want to create keytab entries?
  • i5/OS Kerberos Authentication
  • LDAP
  • iSeries IBM HTTP Server
  • iSeries NetServer
i5/OS Kerberos Authentication
What is the password for your i5/OS service principal(s)?
Note: Any and all passwords used within this scenario are for example purposes only. They should not be used during an actual configuration.
iseriesd123