The following planning work sheets illustrate the type of information you need before you begin configuring network authentication service. All answers on the prerequisite work sheet should be Yes before you proceed with network authentication service setup.
Questions | Answers |
---|---|
Is your i5/OS™ V5R3 or later (5722-SS1)? | Yes |
Are the following licensed products installed
on iSeries™ A:
|
Yes |
Have you installed Windows 2000 on your PCs? | Yes |
Is iSeries Access for Windows (5722-XE1) installed on the administrator's PC? | Yes |
Have you installed iSeries Navigator on the administrator's
PC?
|
Yes |
Have you installed the latest iSeries Access for Windows service pack? See iSeries Access for the latest service pack. | Yes |
Do you have *SECADM, *ALLOBJ, and *IOSYSCFG special authorities? | Yes |
Do you have one of the following installed
on the secure system that will act as a Kerberos server? If so which one?
|
Yes, Windows 2000 Server |
Are all your PCs in your network configured
in a Windows 2000
domain? Note: A Windows 2000 domain is similar to a Kerberos realm. Microsoft® Active
Directory uses Kerberos authentication as its default security mechanism.
|
Yes |
Have you applied the latest program temporary fixes (PTFs)? | Yes |
Is the iSeries system time within five minutes of the Kerberos server's system time? If not see Synchronize system times. | Yes |
Questions | Answers |
---|---|
What is the name of the Kerberos default realm to which
your iSeries will
belong? Note: A Windows 2000 domain is similar to a Kerberos realm. Microsoft Active
Directory uses Kerberos authentication as its default security mechanism.
|
MYCO.COM |
Are you using Microsoft Active Directory? | Yes |
What is the Kerberos server for this Kerberos default realm? What is the port on which the Kerberos server listens? | KDC: kdc1.myco.com Note: This is the default port for the Kerberos server.
|
Do you want to configure a password server
for this default realm? If yes, answer the following questions: What is name of the password server for this Kerberos server? |
Yes Password server:kdc1.myco.com Note: This is the default port for the password
server.
|
For which services do you want to create keytab entries?
|
i5/OS Kerberos Authentication |
What is the password you want to use for
your i5/OS service
principal(s)? Note: Any and all passwords used within this scenario are for
example purposes only. They should not be used during an actual configuration.
|
iseriesa123 |
Do you want to create a batch file to automate adding the service principals to Microsoft Active Directory? | Yes |
What are the i5/OS user profiles names for John Day and Sharon Jones? | JOHND |