GSP
Quick Navigator

Search Site

Unix VPS
A - Starter
B - Basic
C - Preferred
D - Commercial
MPS - Dedicated
Previous VPSs
* Sign Up! *

Support
Contact Us
Online Help
Handbooks
Domain Status
Man Pages

FAQ
Virtual Servers
Pricing
Billing
Technical

Network
Facilities
Connectivity
Topology Map

Miscellaneous
Server Agreement
Year 2038
Credits
 

USA Flag

 

 

Man Pages
KIMPERSONATE(8) FreeBSD System Manager's Manual KIMPERSONATE(8)

kimpersonateimpersonate a user when there exist a keyfile or KeyFile

kimpersonate [-s string | --ccache=string] [-s string | --server=string] [-c string | --client=string] [-k string | --keytab=string] [-5 | --krb5] [-A | --add] [-R | --referral] [-e integer | --expire-time=integer] [-a string | --client-address=string] [-t string | --enc-type=string] [--session-enc-type=string] [-f string | --ticket-flags=string] [--verbose] [--version] [--help]

The kimpersonate program creates a "fake" ticket using the service-key of the service and stores it in the given (or default) ccache. This is useful for testing. The service key can be read from a Kerberos 5 keytab or AFS KeyFile. Supported options:

string
ccache into which to store the ticket
string, --server=string
name of server principal
string, --client=string
name of client principal
string, --keytab=string
name of keytab file
, --krb5
create a Kerberos 5 ticket
, --add
don't re-initialize the ccache, instead add the ticket to an existing ccache.
, --referral
simulate a referrals-based KDC client by storing two entries, one with the empty realm for the service principal name.
integer, --expire-time=integer
lifetime of ticket in seconds
string, --client-address=string
address of client
string, --enc-type=string
encryption type (defaults to "aes256-cts-hmac-sha1-96")
string
session encryption type (defaults to enc-type or "des-cbc-crc" for afs service tickets)
string, --ticket-flags=string
ticket flags for krb5 ticket
Verbose output
Print version
 

Uses /etc/krb5.keytab, and /usr/afs/etc/KeyFile when available and the -k option is used with an appropriate prefix.

kimpersonate can be used in samba root preexec option or for debugging. kimpersonate -s host/hummel.e.kth.se@E.KTH.SE -c lha@E.KTH.SE -5 will create a Kerberos 5 ticket for lha@E.KTH.SE for the host hummel.e.kth.se if there exists a keytab entry for it in /etc/krb5.keytab.

In combination with the ktutil command, this is useful for testing. For example,

ktutil -k tkt add -p host/foo.test@TEST -V2 -e aes256-cts-hmac-sha1-96 -r

kimpersonate --cache=tcc -s host/foo.test@TEST -c jdoe@TEST -k tkt --referral

kinit(1), klist(1)

Love Hornquist Astrand <lha@kth.se>

September 18, 2006 FreeBSD 14.3-RELEASE

Search for    or go to Top of page |  Section 8 |  Main Index

Powered by GSP Visit the GSP FreeBSD Man Page Interface.
Output converted with ManDoc.