Valid on z/OS.
Use the REALM(FOREIGN_REALM) keyword to provides a label for nodes other than for the local TCP/IP node. Parameters of the REALM must correspond to those of the USS configuration file described by the IBM Administration Guide for this service. The label must begin with an alphabetic or national character and may consist of up to 8 alphanumeric characters. The label for a REALM, other than KERBDFLT, is knows as a foreign realm. The REALMNAME specification is used to describe the link between the local URL with the foreign URL.
KERBDFLT is known as the "local" realm.
This keyword has the following format:
TSS ADD(SDT) REALM(foreign_realm)
REALMNAME(fully_qualified_kerberos_name)
ENCRYPT('[DES|NODES]
[DES3|NODES3]
[DESD|NODESD]
[AES128|NOAES128]
[AES256|NOAES256]')
KERBPASS(password)
This keyword is used with:
This example describes the link between the local REALM at HYPOTHETICAL.CA.COM with foreign realm CLIENT1 at HONEYPOT.CLIENT1.COM:
TSS ADD(SDT) REALM(CLIENT1)
REALMNAME(/.../HYPOTHETICAL.CA.COM/krbtgt/HONEYPOT.CLIENT1.COM)
ENCRYPT('DES DES3')
KERBPASS(KRYPTO)
The ellipsis ("...") in the REALMNAME is a literal part of the required Kerberos naming convention. For information, see the Secureway Server Network Authentication Service documentation.
|
Copyright © 2014 CA Technologies.
All rights reserved.
|
|