k5srvutil allows an administrator to list or change keys currently in a keytab or to add new keys to the keytab.
kadmin and kadmin.local are command-line interfaces to the Kerberos V5 administration system. They provide nearly identical functionalities; the difference is...
The kdestroy utility destroys the user's active Kerberos authorization tickets by overwriting and deleting the credentials cache that contains them. If the...
kinit obtains and caches an initial ticket-granting ticket for principal.
klist lists the Kerberos principal and Kerberos tickets held in a credentials cache, or the keys held in a keytab file.
The kpasswd command is used to change a Kerberos principal's password. kpasswd first prompts for the current Kerberos password, then prompts the user twice for...
krb5-config tells the application programmer what flags to use to compile and link programs against the installed Kerberos libraries.
ksu is a Kerberized version of the su program that has two missions: one is to securely change the real and effective user ID to that of the target user, and...
kswitch makes the specified credential cache the primary cache for the collection, if a cache collection is available.
The ktutil command invokes a command interface from which an administrator can read, write, or edit entries in a keytab or Kerberos V4 srvtab file.
kvno acquires a service ticket for the specified Kerberos principals and prints out the key version numbers of each.
sclient is a sample application, primarily useful for testing purposes. It contacts a sample server sserver(8) and authenticates to it using Kerberos version 5...
The .k5identity file, which resides in a user's home directory, contains a list of rules for selecting a client principals based on the server being accessed...
The .k5login file, which resides in a user's home directory, contains a list of the Kerberos principals. Anyone with valid tickets for a principal in the file...
The Kerberos kadmind(8) daemon uses an Access Control List (ACL) file to manage access rights to the Kerberos database. For operations that affect principals...
The kdc.conf file is set up in the same format as the krb5.conf(5) file.
The krb5.conf file is set up in the style of a Windows INI file. Sections are headed by the section name, in square brackets.
kadmind starts the Kerberos administration server. kadmind typically runs on the master Kerberos server, which stores the KDC database. If the KDC database uses...
kdb5_ldap_util allows an administrator to manage realms, Kerberos services and ticket policies.
kdb5_util allows an administrator to perform maintenance procedures on the KDC database. Databases can be created, destroyed, and dumped to or loaded from ASCII...
kprop is used to securely propagate a Kerberos V5 database dump file from the master Kerberos server to a slave Kerberos server, which is specified by...
The kpropd command runs on the slave KDC server. It listens for update requests made by the kprop(8) program. If incremental propagation is enabled, it...
The kproplog command displays the contents of the KDC database update log to standard output. It can be used to keep track of incremental updates to the...
krb5kdc is the Kerberos version 5 Authentication Service and Key Distribution Center (AS/KDC).
sserver and sclient(1) are a simple demonstration client/server application. When sclient connects to sserver, it performs a Kerberos authentication, and then...