diff options
Diffstat (limited to 'kadmin/kadmind.cat8')
-rw-r--r-- | kadmin/kadmind.cat8 | 8 |
1 files changed, 5 insertions, 3 deletions
diff --git a/kadmin/kadmind.cat8 b/kadmin/kadmind.cat8 index 7f3565c687b8..d1607c9a4e4c 100644 --- a/kadmin/kadmind.cat8 +++ b/kadmin/kadmind.cat8 @@ -37,6 +37,7 @@ DDEESSCCRRIIPPTTIIOONN ++oo modify ++oo add ++oo get + ++oo get-keys ++oo all And the optional _p_r_i_n_c_i_p_a_l_-_p_a_t_t_e_r_n restricts the rights to operations on @@ -76,12 +77,13 @@ EEXXAAMMPPLLEESS kkaaddmmiinndd ----ppoorrttss="+ 4711" & This acl file will grant Joe all rights, and allow Mallory to view and - add host principals. + add host principals, as well as extract host principal keys (e.g., into + keytabs). joe/admin@EXAMPLE.COM all - mallory/admin@EXAMPLE.COM add,get host/*@EXAMPLE.COM + mallory/admin@EXAMPLE.COM add,get-keys host/*@EXAMPLE.COM SSEEEE AALLSSOO - kpasswd(1), kadmin(8), kdc(8), kpasswdd(8) + kpasswd(1), kadmin(1), kdc(8), kpasswdd(8) HEIMDAL December 8, 2004 HEIMDAL |