aboutsummaryrefslogtreecommitdiff
path: root/kadmin/kadmind.cat8
diff options
context:
space:
mode:
Diffstat (limited to 'kadmin/kadmind.cat8')
-rw-r--r--kadmin/kadmind.cat88
1 files changed, 5 insertions, 3 deletions
diff --git a/kadmin/kadmind.cat8 b/kadmin/kadmind.cat8
index 7f3565c687b8..d1607c9a4e4c 100644
--- a/kadmin/kadmind.cat8
+++ b/kadmin/kadmind.cat8
@@ -37,6 +37,7 @@ DDEESSCCRRIIPPTTIIOONN
++oo modify
++oo add
++oo get
+ ++oo get-keys
++oo all
And the optional _p_r_i_n_c_i_p_a_l_-_p_a_t_t_e_r_n restricts the rights to operations on
@@ -76,12 +77,13 @@ EEXXAAMMPPLLEESS
kkaaddmmiinndd ----ppoorrttss="+ 4711" &
This acl file will grant Joe all rights, and allow Mallory to view and
- add host principals.
+ add host principals, as well as extract host principal keys (e.g., into
+ keytabs).
joe/admin@EXAMPLE.COM all
- mallory/admin@EXAMPLE.COM add,get host/*@EXAMPLE.COM
+ mallory/admin@EXAMPLE.COM add,get-keys host/*@EXAMPLE.COM
SSEEEE AALLSSOO
- kpasswd(1), kadmin(8), kdc(8), kpasswdd(8)
+ kpasswd(1), kadmin(1), kdc(8), kpasswdd(8)
HEIMDAL December 8, 2004 HEIMDAL