Timestamps, Microseconds, and Clock Skew
Untrusted Environments: A Priori Trust and Trust Chains
Kerberos Key Distribution (Authentication) Service (KDS)
Key Distribution (Authentication) Services
The sec_cred API for Abstracting EPAC Contents
Generalities on Security-The Architecture of Trust
ACL Managers, Permissions, Access Determination Algorithms
The Common Access Determination Algorithm for Delegation
Access Control for the xattrschema Object
Access Control for Attribute Types
Access Control on Attributes with Triggers
Common Access Determination Algorithm
access determination algorithm
Access Control for Attribute Types
Access Control on Attributes with Triggers
Subjects and Objects, Privilege and Authorisation
Access Control on Attributes with Triggers
Access Control for Attribute Types
ACL Managers, Permissions, Access Determination Algorithms
The Common Access Determination Algorithm for Delegation
Subjects and Objects, Privilege and Authorisation
Subjects and Objects, Privilege and Authorisation
EPAC Accessor Function (sec_cred) API
Accounts; rs_acct RPC interface
Registration Service (RS) and RS Editors
Login Facility and Security Client Daemon (SCD)
Accounts; rs_acct RPC interface
Accounts; rs_acct RPC interface
Security Attributes: Authenticity, Integrity, Confidentiality
Integration with Time Services
Object Types, ACL Types, and ACL Inheritance
ACL Managers, Permissions, Access Determination Algorithms
Delegation Common ACL Manager Algorithm
Notes on Common ACL Manager ACLs
Multiple ACLs and ACL Managers
ACL Manager Types Supported by the RS
RS Protected Objects and their ACL Manager Types
ACL Managers, Permissions, Access Determination Algorithms
The Common Access Determination Algorithm for Delegation
ACL Managers, Permissions, Access Determination Algorithms
RS Protected Objects and their ACL Manager Types
ACL Managers, Permissions, Access Determination Algorithms
Multiple ACLs and ACL Managers
RS Protected Objects and their ACL Manager Types
Identifying Protected Objects and ACLs
RS Protected Objects and their ACL Manager Types
ACL Manager Types Supported by the RS
RS Protected Objects and their ACL Manager Types
ACL Managers, Permissions, Access Determination Algorithms
Subjects and Objects, Privilege and Authorisation
Object Types, ACL Types, and ACL Inheritance
Access Control for the xattrschema Object
Object Types, ACL Types, and ACL Inheritance
Object Types, ACL Types, and ACL Inheritance
Object Types, ACL Types, and ACL Inheritance
Multiple ACLs and ACL Managers
Name-based versus PAC-based Authorisation
Object Types, ACL Types, and ACL Inheritance
ACL Managers, Permissions, Access Determination Algorithms
Identifying Protected Objects and ACLs
Privilege (Authorisation) Service (PS)
Notes on Common ACL Manager ACLs
Multiple ACLs and ACL Managers
Identifying Protected Objects and ACLs
Unknown Intercell Action Attribute
Subjects and Objects, Privilege and Authorisation
Additional Attribute Permission Bits
Policy versus Service versus Mechanism
The Common Access Determination Algorithm for Delegation
Delegation Common ACL Manager Algorithm
The intercell_action Algorithm
Details of Basic DES Algorithm
Key Distribution (Authentication) Services
Common Access Determination Algorithm
access determination algorithm
ACL Managers, Permissions, Access Determination Algorithms
Details of Basic DES Algorithm
The Common Access Determination Algorithm for Delegation
Common Access Determination Algorithm
Server Receives Authentication Header and Sends Reverse-Authentication Header
KDS Server Receives AS Request and Sends AS Response
The intercell_action Algorithm
Client Sends Authentication Header
Privilege (Reverse-)Authentication Header Processing
TGS Request/Response Processing (By KDS)
Untrusted Environments: A Priori Trust and Trust Chains
ACL Managers, Permissions, Access Determination Algorithms
Accounts; rs_acct RPC interface
PGO Items; rs_pgo RPC Interface
CO Establishment of Credentials (bind, bind_ack, alter_context, alter_context_response)
CO Verifier auth_value.assoc_uuid_crc
CO Establishment of Credentials (bind, bind_ack, alter_context, alter_context_response)
CO Verifier auth_value.assoc_uuid_crc
Outline of the Remainder of this Chapter, and of this Specification
Generalities on Security-The Architecture of Trust
Integration with Naming Services
Bitwise Operations and Rotations
Login Facility and Security Client Daemon (SCD)
Privilege (Authorisation) Service (PS)
Security-Version (Version 2) UUIDs
Encryption/Decryption Mechanisms
Encryption/Decryption Mechanisms
ACL Managers, Permissions, Access Determination Algorithms
RS Binding; rs_bind Interface and sec_rgy_bind API
The sec_cred API for Abstracting EPAC Contents
EPAC Accessor Function (sec_cred) API
Security Application Programming Interface
Generalities on Security-The Architecture of Trust
Timestamps, Microseconds, and Clock Skew
The Timestamps (AS + TGS) Protocol
The Third-Party (AS + TGS) Protocol
AS Request/Response Processing
Client Sends AS Request to KDS
KDS Server Receives AS Request and Sends AS Response
Kerberos Key Distribution (Authentication) Service (KDS)
Client Sends AS Request to KDS
Privilege (Authorisation) Service (PS)
Kerberos Key Distribution (Authentication) Service (KDS)
KDS Server Receives AS Request and Sends AS Response
AS Request/Response Processing
Registered Password-to-Key Mappings
Key Distribution (Authentication) Services
Subjects and Objects, Privilege and Authorisation
Privilege (Authorisation) Service (PS)
Privilege Attribute Certificates (PACs)
Groups Associated With a Foreign Cell
Security Attributes: Authenticity, Integrity, Confidentiality
Cells-Cross-cell Authentication and Authorisation
RS Protected Objects and their ACL Manager Types
RS Protected Objects and their ACL Manager Types
RS Protected Objects and their ACL Manager Types
Extended Privilege Attribute Facility
Extended Registry Attribute Facility
Access Control for Attribute Types
Additional Attribute Permission Bits
Unknown Intercell Action Attribute
Privilege Attribute Certificates (PACs)
Handle for Privilege Attribute Data
privilege attribute certificate (PAC)
Additional Attribute Permission Bits
Schemas for Well-Known Attributes
Security Attributes: Authenticity, Integrity, Confidentiality
Privilege (Authorisation) Service (PS)
Cursor for Extended Attributee Iteration
Security Attributes: Authenticity, Integrity, Confidentiality
Access Control on Attributes with Triggers
Environmental Parameters and Registry Attributes
Schemas for Well-Known Attributes
Privilege Attributes for the EPAC
Additional Attribute Permission Bits
Privilege Attributes for the EPAC
Environmental Parameters and Registry Attributes
Outline of the Remainder of this Chapter, and of this Specification
CO Verifier auth_value.assoc_uuid_crc
CO Verifier auth_value.checksum
CO Verifier auth_value.credentials
Privilege Attribute Certificates (PACs)
Kerberos Key Distribution (Authentication) Service (KDS)
Cells-Cross-cell Authentication and Authorisation
Key Distribution (Authentication) Services
Registered Authentication Data Types
Client Sends Authentication Header
Server Receives Authentication Header and Sends Reverse-Authentication Header
Registered Authentication Services
Privilege Authentication Headers
Client Sends Privilege Authentication Header
Server Receives Privilege Authentication Header and Sends Privilege Reverse-Authentication Header
Authentication between Replicas
KDS Server Receives TGS Request and Sends TGS Response
Registered Authentication Data Types
Privilege (Authorisation) Service (PS)
(Reverse-)Authentication Header Processing
Policy Item, Policies and Properties; rs_policy RPC Interface
Registered Authentication Services
Kerberos Key Distribution (Authentication) Service (KDS)
Kerberos Key Distribution (Authentication) Service (KDS)
Client Sends Authentication Header
Cells-Cross-cell Authentication and Authorisation
(Reverse-)Authentication Header Processing
Kerberos Key Distribution (Authentication) Service (KDS)
TGS Request/Response Processing
Server Receives Authentication Header and Sends Reverse-Authentication Header
Kerberos Key Distribution (Authentication) Service (KDS)
Kerberos Key Distribution (Authentication) Service (KDS)
Kerberos Key Distribution (Authentication) Service (KDS)
What is Specified in this Chapter
KDS Server Receives TGS Request and Sends TGS Response
Kerberos Key Distribution (Authentication) Service (KDS)
Kerberos Key Distribution (Authentication) Service (KDS)
Integration with Time Services
Security Attributes: Authenticity, Integrity, Confidentiality
Security Attributes: Authenticity, Integrity, Confidentiality
Data Encryption Standard (DES)
Message Digests 4 and 5 (MD4, MD5)
Subjects and Objects, Privilege and Authorisation
Privilege (Authorisation) Service (PS)
Name-based versus PAC-based Authorisation
Cells-Cross-cell Authentication and Authorisation
Registered Authorisation Data Types
Privilege (Authorisation) Services
Registered Authorisation Services
Local and Foreign Authorisation Identities
Registered Authorisation Data Types
ACL Managers, Permissions, Access Determination Algorithms
Privilege (Authorisation) Service (PS)
Privilege (Authorisation) Services
Registered Authorisation Services
Subjects and Objects, Privilege and Authorisation
Cells-Cross-cell Authentication and Authorisation
Groups Associated With a Foreign Cell
PS Server Receives PTGS Request and Sends PTGS Response
Local and Foreign Authorisation Identities
Name-based versus PAC-based Authorisation
Cross-cell Authorisation-Vetting the Privilege-ticket-granting-ticket
Login Facility and Security Client Daemon (SCD)
Untrusted Environments: A Priori Trust and Trust Chains
Details of Basic DES Algorithm
Details of Basic DES Algorithm
Part of Ticket to be Encrypted
Part of Reverse-authentication Header to be Encrypted
Part of KDS Response to be Encrypted
Knowledge versus Belief; Trust
Knowledge versus Belief; Trust
Registration Service (RS) and RS Editors
Key Distribution (Authentication) Services
Authentication between Replicas
Integer Representations (Endianness)
Mapping Bit-Sequences to Integers
CO Establishment of Credentials (bind, bind_ack, alter_context, alter_context_response)
CO Verifier auth_value.assoc_uuid_crc
CO Establishment of Credentials (bind, bind_ack, alter_context, alter_context_response)
CO Verifier auth_value.assoc_uuid_crc
RS Binding; rs_bind Interface and sec_rgy_bind API
Identifying Protected Objects and ACLs
Key Distribution (Authentication) Services
Key Distribution (Authentication) Services
ACL Managers, Permissions, Access Determination Algorithms
Key Distribution (Authentication) Services
Mapping Bit-Sequences to Integers
Mapping Bit-Sequences to Integers
ACL Managers, Permissions, Access Determination Algorithms
Mapping Mixed Bit/Byte-Sequences to Integers
Additional Attribute Permission Bits
Bitwise Operations and Rotations
Bitwise Operations and Rotations
Bitwise Operations and Rotations
Bitwise Operations and Rotations
Bitwise Operations and Rotations
Bitwise Operations and Rotations
Rounds (T): Cipher Function (F), Expansion (E), Permutation (P) and Selection/Substitution (S)
CL Integrity and Confidentiality (PDU Verifiers and Bodies)
CO Integrity and Confidentiality (PDU Verifiers and Bodies)
What is Specified in this Chapter
CO Integrity and Confidentiality (PDU Verifiers and Bodies)
Login Facility and Security Client Daemon (SCD)
Untrusted Environments: A Priori Trust and Trust Chains
Policy Item, Policies and Properties; rs_policy RPC Interface
Initialise State Buffer and Trigonometric Vector
Initialise State Buffer and Trigonometric Vector
ACL Manager Types Supported by the RS
TGS Request/Response Processing (By KDS)
Mapping Bit-Sequences to Integers
Mapping Byte-Sequences to Integers
Mapping Byte-Sequences to Integers
Kerberos Key Distribution (Authentication) Service (KDS)
Privilege (Authorisation) Service (PS)
The Common Access Determination Algorithm for Delegation
Common Access Determination Algorithm
Name-based versus PAC-based Authorisation
Registered Password-to-Key Mappings
Key Distribution (Authentication) Services
Key Distribution (Authentication) Services
Key Distribution (Authentication) Services
sec_rgy_name_t-Short and Long PGO Names
Registered Syntaxes for Cell Names
Groups Associated With a Foreign Cell
Policy Item, Policies and Properties; rs_policy RPC Interface
Kerberos Key Distribution (Authentication) Service (KDS)
Privilege (Authorisation) Service (PS)
Cells-Cross-cell Authentication and Authorisation
KDS Server Receives TGS Request and Sends TGS Response
Registration Service (RS) and RS Editors
Cells-Cross-cell Authentication and Authorisation
privilege attribute certificate (PAC)
Privilege Attribute Certificates (PACs)
Further Discussion of Certification
Further Discussion of Certification
Login Facility and Security Client Daemon (SCD)
Login Facility and Security Client Daemon (SCD)
Untrusted Environments: A Priori Trust and Trust Chains
Untrusted Environments: A Priori Trust and Trust Chains
Composition Laws (Chaining Properties)
Composition Laws (Chaining Properties)
Untrusted Environments: A Priori Trust and Trust Chains
ACL Managers, Permissions, Access Determination Algorithms
Outline of the Remainder of this Chapter, and of this Specification
What is Specified in this Chapter
Minimum Implementation Requirements
Minimum Implementation Requirements
Message Digests 4 and 5 (MD4, MD5)
KDS Server Receives TGS Request and Sends TGS Response
Object Types, ACL Types, and ACL Inheritance
Login Facility and Security Client Daemon (SCD)
Key Schedule (KS): Permuted Choices (PC1, PC2) and Left Shift (LS)
Compress Message in 16-Word Chunks
Compress Message in 16-Word Chunks
Rounds (T): Cipher Function (F), Expansion (E), Permutation (P) and Selection/Substitution (S)
Data Encryption Standard (DES)
Rounds (T): Cipher Function (F), Expansion (E), Permutation (P) and Selection/Substitution (S)
Data Encryption Standard (DES)
Bitwise Operations and Rotations
Security in the CL RPC Protocol
CL Establishment of Credentials (Conversation Manager)
CL Integrity and Confidentiality (PDU Verifiers and Bodies)
CL dce_c_authn_level_integrity
CL Integrity and Confidentiality (PDU Verifiers and Bodies)
Security in the CL RPC Protocol
What is Specified in this Chapter
Tickets, Keys, and Cross-Registration
Login Facility and Security Client Daemon (SCD)
Client Sends AS Request to KDS
Client Sends Authentication Header
Client Receives Reverse-Authentication Header
Client Sends Privilege Authentication Header
Client Receives Privilege Reverse-Authentication Header
Login Facility and Security Client Daemon (SCD) RPC Interface
Integration with Naming Services
Client Receives Reverse-Authentication Header
Client Sends AS Request to KDS
CL Establishment of Credentials (Conversation Manager)
Kerberos Key Distribution (Authentication) Service (KDS)
Tickets, Keys, and Cross-Registration
Privilege (Authorisation) Service (PS)
Client Receives Privilege Reverse-Authentication Header
Client Sends Authentication Header
Client Sends Privilege Authentication Header
Subjects and Objects, Privilege and Authorisation
Login Facility and Security Client Daemon (SCD)
Knowledge versus Belief; Trust
Timestamps, Microseconds, and Clock Skew
Kerberos Key Distribution (Authentication) Service (KDS)
Security in the CO RPC Protocol
CO Establishment of Credentials (bind, bind_ack, alter_context, alter_context_response)
CO Verifier auth_value.assoc_uuid_crc
CO Verifier auth_value.checksum
CO Verifier auth_value.credentials
CO Integrity and Confidentiality (PDU Verifiers and Bodies)
CO dce_c_authn_level_pkt_integrity
CO dce_c_authn_level_pkt_privacy
CO Integrity and Confidentiality (PDU Verifiers and Bodies)
Security in the CO RPC Protocol
What is Specified in this Chapter
Encoding/Decoding and Encryption/Decryption of Messages
Status Codes Specific to Delegation
Registered Error Status Codes/Text/Data
Integer Representations (Endianness)
Message Digests 4 and 5 (MD4, MD5)
Multiple ACLs and ACL Managers
Combined First and Second Steps
The Common Access Determination Algorithm for Delegation
Delegation Common ACL Manager Algorithm
Notes on Common ACL Manager ACLs
Common Access Determination Algorithm
Common Data Types and Constants for rdacl Interface
Common Data Types and Constants for RS Editors
Common Data Types and Constants for rs_bind
Common Data Types and Constants for rs_policy
Common Data Types and Constants for rs_pgo
Common Data Types and Constants for rs_acct
Common Data Types and Constants for rs_misc
Common Data Types and Constants for rs_attr
Common Data Types and Constants for rs_attr_schema
Common Data Types and Constants for rs_prop_acct
Common Data Types and Constants for rs_prop_acl
Common Data Types and Constants for rs_prop_attr
Common Data Types and Constants for rs_prop_attr_schema
Common Data Types and Constants for rs_prop_pgo
Common Data Types and Constants for rs_pwd_mgmt
Common Data Types and Constants for rs_repadm
Common Data Types and Constants for rs_replist
Common Data Types and Constants for rs_repmgr
Common Data Types and Constants for rs_unix
Common Data Types and Constants for the secidmap Interface
Common Data Types and Constants for Key Management
Common Data Types and Constants for scd Interface
Privilege (Authorisation) Service (PS)
Common Access Determination Algorithm
The Common Access Determination Algorithm for Delegation
ACL Managers, Permissions, Access Determination Algorithms
Kerberos Key Distribution (Authentication) Service (KDS)
Delegation Compatibility Modes
The Complete Cross-cell Scenario
Knowledge versus Belief; Trust
Components of Delegation Model
Composition Laws (Chaining Properties)
Composition Laws (Chaining Properties)
Compress Message in 16-Word Chunks
Compress Message in 16-Word Chunks
Security Attributes: Authenticity, Integrity, Confidentiality
Integration with Time Services
ACL Managers, Permissions, Access Determination Algorithms
Knowledge versus Belief; Trust
Subjects and Objects, Privilege and Authorisation
Knowledge versus Belief; Trust
Security Attributes: Authenticity, Integrity, Confidentiality
CL Integrity and Confidentiality (PDU Verifiers and Bodies)
CO Integrity and Confidentiality (PDU Verifiers and Bodies)
Security Attributes: Authenticity, Integrity, Confidentiality
CL Integrity and Confidentiality (PDU Verifiers and Bodies)
CO Integrity and Confidentiality (PDU Verifiers and Bodies)
Data Encryption Standard (DES)
Message Digests 4 and 5 (MD4, MD5)
Bitwise Operations and Rotations
Security in the CO RPC Protocol
What is Specified in this Chapter
Security in the CL RPC Protocol
What is Specified in this Chapter
Common Data Types and Constants for rdacl Interface
Common Data Types and Constants for RS Editors
Common Data Types and Constants for rs_bind
Common Data Types and Constants for rs_policy
Common Data Types and Constants for rs_pgo
Common Data Types and Constants for rs_acct
Common Data Types and Constants for rs_misc
Common Data Types and Constants for rs_attr
Common Data Types and Constants for rs_attr_schema
Common Data Types and Constants for rs_prop_acct
Common Data Types and Constants for rs_prop_acl
Common Data Types and Constants for rs_prop_attr
Common Data Types and Constants for rs_prop_attr_schema
Common Data Types and Constants for rs_prop_pgo
Common Data Types and Constants for rs_pwd_mgmt
Common Data Types and Constants for rs_repadm
Common Data Types and Constants for rs_replist
Common Data Types and Constants for rs_repmgr
Common Data Types and Constants for rs_unix
Common Data Types and Constants for the secidmap Interface
Common Data Types and Constants for Key Management
Common Data Types and Constants for scd Interface
Key Distribution (Authentication) Services
Privilege (Authorisation) Service (PS)
Object Types, ACL Types, and ACL Inheritance
Privilege (Authorisation) Service (PS)
The sec_cred API for Abstracting EPAC Contents
Login Facility and Security Client Daemon (SCD)
Login Facility and Security Client Daemon (SCD)
Security-Version (Version 2) UUIDs
Login Facility and Security Client Daemon (SCD)
Access Control for the xattrschema Object
Access Control for Attribute Types
Access Control on Attributes with Triggers
ACL Managers, Permissions, Access Determination Algorithms
Supported Permissions
Local and Foreign Authorisation Identities
Groups Associated With a Foreign Cell
Local and Foreign Authorisation Identities
Privilege Attribute Certificates (PACs)
Groups Associated With a Foreign Cell
Groups Associated With a Foreign Cell
Privilege (Authorisation) Service (PS)
GROUP_OBJ/GROUP/FOREIGN_GROUP Subalgorithm
ACL Managers, Permissions, Access Determination Algorithms
GROUP_OBJ_DEL/GROUP_DEL/FOREIGN_GROUP_DEL Subalgorithm
ACL Managers, Permissions, Access Determination Algorithms
FOREIGN_OTHER_DEL Subalgorithm
FOREIGN_OTHER_DEL Subalgorithm
USER/FOREIGN_USER Subalgorithm
ACL Managers, Permissions, Access Determination Algorithms
USER_DEL/FOREIGN_USER_DEL Subalgorithm
Generalities on Security-The Architecture of Trust
Delegation Token (Version 0) Format
Privilege Attribute Certificates (PACs)
Terminology, Notation, and Conventions
KDS Server Receives AS Request and Sends AS Response
Client Sends AS Request to KDS
Initial Permutation (IP) and Final Permutation (FP)
Integration with Time Services
Key Distribution (Authentication) Services
Rounds (T): Cipher Function (F), Expansion (E), Permutation (P) and Selection/Substitution (S)
EPAC Accessor Function (sec_cred) API
Further Discussion of Certification
Integration with Naming Services
Generalities on Security-The Architecture of Trust
Generalities on Security-The Architecture of Trust
Privilege (Authorisation) Service (PS)
Distributed Security: Secrets and Cryptology
Privilege (Authorisation) Service (PS)
Privilege (Authorisation) Service (PS)
Privilege (Authorisation) Service (PS)
Security-Version (Version 2) UUIDs
Security Attributes: Authenticity, Integrity, Confidentiality
Data Encryption Standard (DES)
(Reverse-)Authentication Header Processing
Subjects and Objects, Privilege and Authorisation
Timestamps, Microseconds, and Clock Skew
Registration Service (RS) and RS Editors
Privilege (Authorisation) Service (PS)
RS Protected Objects and their ACL Manager Types
ACL Manager Types Supported by the RS
RS Protected Objects and their ACL Manager Types
GROUP_OBJ/GROUP/FOREIGN_GROUP Subalgorithm
Accounts; rs_acct RPC interface
Privilege Attribute Certificates (PACs)
Privilege (Authorisation) Service (PS)
PGO Items; rs_pgo RPC Interface
RS Protected Objects and their ACL Manager Types
ACL Managers, Permissions, Access Determination Algorithms
Integration with Naming Services
GROUP_OBJ_DEL/GROUP_DEL/FOREIGN_GROUP_DEL Subalgorithm
GROUP_OBJ/GROUP/FOREIGN_GROUP Subalgorithm
ACL Managers, Permissions, Access Determination Algorithms
GROUP_OBJ/GROUP/FOREIGN_GROUP Subalgorithm
GROUP_OBJ_DEL/GROUP_DEL/FOREIGN_GROUP_DEL Subalgorithm
GROUP_OBJ_DEL/GROUP_DEL/FOREIGN_GROUP_DEL Subalgorithm
Groups Associated With a Foreign Cell
Further Discussion of Certification
Data Encryption Standard (DES)
Handle for Privilege Attribute Data
Login Facility and Security Client Daemon (SCD)
Handle for Privilege Attribute Data
Identifying Protected Objects and ACLs
RS Binding; rs_bind Interface and sec_rgy_bind API
Subjects and Objects, Privilege and Authorisation
Message Digests 4 and 5 (MD4, MD5)
Part of Reverse-authentication Header to be Encrypted
(Reverse-)Authentication Header Processing
Client Sends Authentication Header
Server Receives Authentication Header and Sends Reverse-Authentication Header
Client Receives Reverse-Authentication Header
Privilege (Reverse-)Authentication Header Processing
Client Sends Privilege Authentication Header
Server Receives Privilege Authentication Header and Sends Privilege Reverse-Authentication Header
Client Receives Privilege Reverse-Authentication Header
(Reverse-)Authentication Header Processing
Privilege (Reverse-)Authentication Header Processing
Client Sends Authentication Header
What is Specified in this Chapter
Privilege Authentication Headers
Privilege Reverse-Authentication Headers
Client Receives Reverse-Authentication Header
Reverse-Authentication Headers
Reverse-Authentication Headers
Privilege Authentication Headers
Privilege Reverse-Authentication Headers
ACL Managers, Permissions, Access Determination Algorithms
ACL Managers, Permissions, Access Determination Algorithms
PGO Items; rs_pgo RPC Interface
Policy versus Service versus Mechanism
Integration with Time Services
PGO Items; rs_pgo RPC Interface
Accounts; rs_acct RPC interface
PGO Items; rs_pgo RPC Interface
Login Facility and Security Client Daemon (SCD)
Generalities on Security-The Architecture of Trust
PGO Items; rs_pgo RPC Interface
ACL Managers, Permissions, Access Determination Algorithms
Identifying Protected Objects and ACLs
Local and Foreign Authorisation Identities
Generalities on Security-The Architecture of Trust
Privilege (Authorisation) Service (PS)
Security Attributes: Authenticity, Integrity, Confidentiality
Kerberos Key Distribution (Authentication) Service (KDS)
Kerberos Key Distribution (Authentication) Service (KDS)
Policy versus Service versus Mechanism
Key-based Security: Kerckhoffs' Doctrine
Security Attributes: Authenticity, Integrity, Confidentiality
Login Facility and Security Client Daemon (SCD)
Minimum Implementation Requirements
Implementation Variability Regarding Required Rights
Minimum Implementation Requirements
Implementation Variability Regarding Required Rights
(Reverse-)Authentication Header Processing
Data Encryption Standard (DES)
Compress Message in 16-Word Chunks
Compress Message in 16-Word Chunks
What is Specified in this Chapter
Security in the CL RPC Protocol
Security in the CO RPC Protocol
Untrusted Environments: A Priori Trust and Trust Chains
The Complete Cross-cell Scenario
Further Discussion of Certification
Subjects and Objects, Privilege and Authorisation
Object Types, ACL Types, and ACL Inheritance
Object Types, ACL Types, and ACL Inheritance
ACL Managers, Permissions, Access Determination Algorithms
Login Facility and Security Client Daemon (SCD)
Login Facility and Security Client Daemon (SCD)
Login Facility and Security Client Daemon (SCD)
Initial Permutation (IP) and Final Permutation (FP)
Object Types, ACL Types, and ACL Inheritance
Object Types, ACL Types, and ACL Inheritance
Tickets, Keys, and Cross-Registration
Object Types, ACL Types, and ACL Inheritance
Initial Permutation (IP) and Final Permutation (FP)
Kerberos Key Distribution (Authentication) Service (KDS)
Initialise State Buffer and Trigonometric Vector
Initialise State Buffer and Trigonometric Vector
Subjects and Objects, Privilege and Authorisation
Security Attributes: Authenticity, Integrity, Confidentiality
ACL Managers, Permissions, Access Determination Algorithms
RS Binding; rs_bind Interface and sec_rgy_bind API
Integer Representations (Endianness)
Mapping Bit-Sequences to Integers
Mapping Byte-Sequences to Integers
Mapping Mixed Bit/Byte-Sequences to Integers
Mapping Bit-Sequences to Integers
Mapping Byte-Sequences to Integers
Mapping Mixed Bit/Byte-Sequences to Integers
Integration with Time Services
Integration with Naming Services
Integration with Time Services
Security Attributes: Authenticity, Integrity, Confidentiality
CL Integrity and Confidentiality (PDU Verifiers and Bodies)
CO Integrity and Confidentiality (PDU Verifiers and Bodies)
Security Attributes: Authenticity, Integrity, Confidentiality
CL Integrity and Confidentiality (PDU Verifiers and Bodies)
CO Integrity and Confidentiality (PDU Verifiers and Bodies)
Data Encryption Standard (DES)
Message Digests 4 and 5 (MD4, MD5)
Subjects and Objects, Privilege and Authorisation
Unknown Intercell Action Attribute
The intercell_action Algorithm
The intercell_action Algorithm
Combined First and Second Steps
RS Binding; rs_bind Interface and sec_rgy_bind API
Policy Item, Policies and Properties; rs_policy RPC Interface
PGO Items; rs_pgo RPC Interface
Accounts; rs_acct RPC interface
Miscellaneous; rs_misc RPC Interface
Common Data Types and Constants for rdacl Interface
Interface UUID and Version Number for rdacl Interface
Interface UUID and Version Number for rs_bind
Interface UUID and Version Number for rs_policy
Interface UUID and Version Number for rs_pgo
Interface UUID and Version Number for rs_acct
Interface UUID and Version Number for rs_misc
The rs_attr_schema RPC Interface
Interface UUID for rs_attr_schema
The rs_prop_acct RPC Interface
Interface UUID and Version Number for rs_prop_acct
Interface UUID and Version Number for rs_prop_acl
The rs_prop_attr RPC Interface
Interface UUID and Version Number for rs_prop_attr
The rs_prop_attr_schema RPC Interface
Interface UUID and Version Number for rs_prop_attr_schema
Interface UUID and Version Number for rs_prop_pgo
The rs_prop_plcy RPC Interface
Interface UUID and Version Number for rs_prop_plcy
The rs_prop_replist RPC Interface
Interface UUID and Version Number for rs_prop_replist
Interface UUID and Version Number for rs_pwd_mgmt
Interface UUID and Version Number for rs_qry
Interface UUID and Version Number for rs_repadm
Interface UUID and Version Number for rs_replist
Interface UUID and Version Number for rs_repmgr
Interface UUID and Version Number for rs_rpladmn
Interface UUID and Version Number for rs_unix
Interface UUID and Version Number for rs_update
Common Data Types and Constants for the secidmap Interface
Interface UUID and Version Number for the secidmap Interface
Key Management Facility RPC Interface
The Key Management RPC Interface
Login Facility and Security Client Daemon (SCD) RPC Interface
Common Data Types and Constants for scd Interface
Interface UUID and Version Number for scd Interface
Security Application Programming Interface
Interface UUID and Version Number for rs_acct
Interface UUID for rs_attr_schema
Interface UUID and Version Number for rs_bind
Interface UUID and Version Number for rs_misc
Interface UUID and Version Number for rs_pgo
Interface UUID and Version Number for rs_policy
Interface UUID and Version Number for rs_prop_acct
Interface UUID and Version Number for rs_prop_acl
Interface UUID and Version Number for rs_prop_attr
Interface UUID and Version Number for rs_prop_attr_schema
Interface UUID and Version Number for rs_prop_pgo
Interface UUID and Version Number for rs_prop_plcy
Interface UUID and Version Number for rs_prop_replist
Interface UUID and Version Number for rs_pwd_mgmt
Interface UUID and Version Number for rs_qry
Interface UUID and Version Number for rs_repadm
Interface UUID and Version Number for rs_replist
Interface UUID and Version Number for rs_repmgr
Interface UUID and Version Number for rs_rpladmn
Interface UUID and Version Number for rs_unix
Interface UUID and Version Number for rs_update
Interface UUID and Version Number for scd Interface
Interface UUID and Version Number for the secidmap Interface
Subjects and Objects, Privilege and Authorisation
The Complete Cross-cell Scenario
Login Facility and Security Client Daemon (SCD)
Registered Syntaxes for Cell Names
Part of Ticket to be Encrypted
DCE Security Replication and Propagation
Introduction to Security Services
Generalities on Security-The Architecture of Trust
Initial Permutation (IP) and Final Permutation (FP)
Initial Permutation (IP) and Final Permutation (FP)
What is Specified in this Chapter
Registered Password-to-Key Mappings
Versions and Issues of Specifications
Tickets, Keys, and Cross-Registration
Privilege (Authorisation) Service (PS)
Kerberos Key Distribution (Authentication) Service (KDS)
Policy Item, Policies and Properties; rs_policy RPC Interface
Registration Service (RS) and RS Editors
Registration Service (RS) and RS Editors
PGO Items; rs_pgo RPC Interface
Cursor for Extended Attributee Iteration
Key Distribution (Authentication) Services
Kerberos Key Distribution (Authentication) Service (KDS)
Part of KDS Response to be Encrypted
Client Sends AS Request to KDS
KDS Server Receives AS Request and Sends AS Response
KDS Server Receives TGS Request and Sends TGS Response
TGS Request/Response Processing (By KDS)
Tickets, Keys, and Cross-Registration
Kerberos Key Distribution (Authentication) Service (KDS)
Key Distribution (Authentication) Services
Registration Service (RS) and RS Editors
Cells-Cross-cell Authentication and Authorisation
Name-based versus PAC-based Authorisation
Kerberos Key Distribution (Authentication) Service (KDS)
Part of KDS Response to be Encrypted
KDS Server Receives TGS Request and Sends TGS Response
TGS Request/Response Processing (By KDS)
Login Facility and Security Client Daemon (SCD)
Kerberos Key Distribution (Authentication) Service (KDS)
Kerberos Key Distribution (Authentication) Service (KDS)
Kerberos Key Distribution (Authentication) Service (KDS)
Key Distribution (Authentication) Services
Kerberos Key Distribution (Authentication) Service (KDS)
Registered Authentication Services
PS Server Receives PTGS Request and Sends PTGS Response
Key-based Security: Kerckhoffs' Doctrine
Key-based Security: Kerckhoffs' Doctrine
Kerberos Key Distribution (Authentication) Service (KDS)
Key Schedule (KS): Permuted Choices (PC1, PC2) and Left Shift (LS)
Key Distribution (Authentication) Services
Registered Encryption Key Types
Key Management Facility RPC Interface
The Key Management RPC Interface
Common Data Types and Constants for Key Management
Kerberos Key Distribution (Authentication) Service (KDS)
Key Distribution (Authentication) Services
The Key Management RPC Interface
Key Schedule (KS): Permuted Choices (PC1, PC2) and Left Shift (LS)
Key-based Security: Kerckhoffs' Doctrine
Data Encryption Standard (DES)
Kerberos Key Distribution (Authentication) Service (KDS)
Kerberos Key Distribution (Authentication) Service (KDS)
Kerberos Key Distribution (Authentication) Service (KDS)
Kerberos Key Distribution (Authentication) Service (KDS)
Integration with Time Services
KDS Server Receives AS Request and Sends AS Response
Tickets, Keys, and Cross-Registration
PGO Items; rs_pgo RPC Interface
Key-based Security: Kerckhoffs' Doctrine
Registered Password-to-Key Mappings
Message Digests 4 and 5 (MD4, MD5)
Message Digests 4 and 5 (MD4, MD5)
Integration with Time Services
Data Encryption Standard (DES)
Kerberos Key Distribution (Authentication) Service (KDS)
Tickets, Keys, and Cross-Registration
Key-based Security: Kerckhoffs' Doctrine
Tickets, Keys, and Cross-Registration
Knowledge versus Belief; Trust
Knowledge versus Belief; Trust
Accounts; rs_acct RPC interface
PGO Items; rs_pgo RPC Interface
Key Schedule (KS): Permuted Choices (PC1, PC2) and Left Shift (LS)
Key Distribution (Authentication) Services
Kerberos Key Distribution (Authentication) Service (KDS)
Timestamps, Microseconds, and Clock Skew
Timestamps, Microseconds, and Clock Skew
Composition Laws (Chaining Properties)
Composition Laws (Chaining Properties)
Mapping Byte-Sequences to Integers
Key Schedule (KS): Permuted Choices (PC1, PC2) and Left Shift (LS)
Key Schedule (KS): Permuted Choices (PC1, PC2) and Left Shift (LS)
Bitwise Operations and Rotations
Kerberos Key Distribution (Authentication) Service (KDS)
Kerberos Key Distribution (Authentication) Service (KDS)
Policy Item, Policies and Properties; rs_policy RPC Interface
Integration with Time Services
Kerberos Key Distribution (Authentication) Service (KDS)
Distributed Security: Secrets and Cryptology
Privilege (Authorisation) Service (PS)
Generalities on Security-The Architecture of Trust
Integer Representations (Endianness)
Mapping Bit-Sequences to Integers
Local and Foreign Authorisation Identities
Local and Foreign Authorisation Identities
Privilege (Authorisation) Service (PS)
Groups Associated With a Foreign Cell
Privilege Attribute Certificates (PACs)
Key-based Security: Kerckhoffs' Doctrine
Distributed Security: Secrets and Cryptology
Accounts; rs_acct RPC interface
Login Facility and Security Client Daemon (SCD)
Extended Login and Password Management Overview
Login Facility and Security Client Daemon (SCD) RPC Interface
Login Facility and Security Client Daemon (SCD)
The Timestamps (AS + TGS) Protocol
Environmental Parameters and Registry Attributes
Login Facility and Security Client Daemon (SCD)
Accounts; rs_acct RPC interface
Login Facility and Security Client Daemon (SCD)
Pre-Authentication and Obtaining a TGT
Pre-Authentication and Obtaining a TGT
Minimum Implementation Requirements
sec_rgy_name_t-Short and Long PGO Names
sec_rgy_name_t-Short and Long PGO Names
Tickets, Keys, and Cross-Registration
KDS Server Receives AS Request and Sends AS Response
Key Schedule (KS): Permuted Choices (PC1, PC2) and Left Shift (LS)
Mapping Byte-Sequences to Integers
Login Facility and Security Client Daemon (SCD)
PGO Items; rs_pgo RPC Interface
Extended Login and Password Management Overview
Key Management Facility RPC Interface
The Key Management RPC Interface
Common Data Types and Constants for Key Management
Delegation Common ACL Manager Algorithm
Notes on Common ACL Manager ACLs
ACL Manager Types Supported by the RS
CL Establishment of Credentials (Conversation Manager)
RS Protected Objects and their ACL Manager Types
ACL Managers, Permissions, Access Determination Algorithms
ACL Managers, Permissions, Access Determination Algorithms
Multiple ACLs and ACL Managers
Key-based Security: Kerckhoffs' Doctrine
Policy versus Service versus Mechanism
Login Facility and Security Client Daemon (SCD)
Mapping Bit-Sequences to Integers
Mapping Byte-Sequences to Integers
Mapping Mixed Bit/Byte-Sequences to Integers
Registered Password-to-Key Mappings
Registered Password-to-Key Mappings
ACL Managers, Permissions, Access Determination Algorithms
Delegation Common ACL Manager Algorithm
RS Binding; rs_bind Interface and sec_rgy_bind API
Delegation Common ACL Manager Algorithm
Knowledge versus Belief; Trust
Subjects and Objects, Privilege and Authorisation
Message Digests 4 and 5 (MD4, MD5)
Message Digests 4 and 5 (MD4, MD5)
Message Digests 4 and 5 (MD4, MD5)
Message Digests 4 and 5 (MD4, MD5)
Message Digests 4 and 5 (MD4, MD5)
Message Digests 4 and 5 (MD4, MD5)
Policy versus Service versus Mechanism
Policy versus Service versus Mechanism
Encryption/Decryption Mechanisms
Cells-Cross-cell Authentication and Authorisation
Registration Service (RS) and RS Editors
Message Digests 4 and 5 (MD4, MD5)
Compress Message in 16-Word Chunks
Compress Message in 16-Word Chunks
Registered Protocol Message Types
Message Digests 4 and 5 (MD4, MD5)
Message Digests 4 and 5 (MD4, MD5)
Encoding/Decoding and Encryption/Decryption of Messages
Kerberos Key Distribution (Authentication) Service (KDS)
Encoding/Decoding and Encryption/Decryption of Messages
Kerberos Key Distribution (Authentication) Service (KDS)
Message Digests 4 and 5 (MD4, MD5)
Timestamps, Microseconds, and Clock Skew
Timestamps, Microseconds, and Clock Skew
KDS Server Receives TGS Request and Sends TGS Response
Timestamps, Microseconds, and Clock Skew
Minimum Implementation Requirements
Minimum Implementation Requirements
Key Distribution (Authentication) Services
minimum_password_cycle_time ERA
RS Binding; rs_bind Interface and sec_rgy_bind API
Miscellaneous; rs_misc RPC Interface
Miscellaneous Routines Needed for DCE Security
Security Attributes: Authenticity, Integrity, Confidentiality
Registered Password-to-Key Mappings
Mapping Mixed Bit/Byte-Sequences to Integers
Mapping Mixed Bit/Byte-Sequences to Integers
Subjects and Objects, Privilege and Authorisation
Components of Delegation Model
Cells-Cross-cell Authentication and Authorisation
Generalities on Security-The Architecture of Trust
Delegation Compatibility Modes
Untrusted Environments: A Priori Trust and Trust Chains
Mapping Byte-Sequences to Integers
Mapping Byte-Sequences to Integers
Cells-Cross-cell Authentication and Authorisation
Further Discussion of Certification
Multiple ACLs and ACL Managers
Multiple ACLs and ACL Managers
Privilege (Authorisation) Service (PS)
Server Receives Authentication Header and Sends Reverse-Authentication Header
KDS Server Receives TGS Request and Sends TGS Response
TGS Request/Response Processing
Cells-Cross-cell Authentication and Authorisation
Accounts; rs_acct RPC interface
PGO Items; rs_pgo RPC Interface
Name-based versus PAC-based Authorisation
Name-based versus PAC-based Authorisation
Name-based versus PAC-based Authorisation
Kerberos Key Distribution (Authentication) Service (KDS)
Tickets, Keys, and Cross-Registration
Privilege (Authorisation) Service (PS)
Registered Syntaxes for Cell Names
sec_rgy_name_t-Short and Long PGO Names
PGO Items; rs_pgo RPC Interface
Registered Syntaxes for Cell Names
Integration with Naming Services
sec_rgy_name_t-Short and Long PGO Names
Integration with Naming Services
sec_rgy_name_t-Short and Long PGO Names
Key Distribution (Authentication) Services
Miscellaneous Routines Needed for DCE Security
Bitwise Operations and Rotations
Kerberos Key Distribution (Authentication) Service (KDS)
Login Facility and Security Client Daemon (SCD)
Login Facility and Security Client Daemon (SCD)
Key-based Security: Kerckhoffs' Doctrine
Privilege (Authorisation) Service (PS)
Non-Intermediary Subalgorithms
Rounds (T): Cipher Function (F), Expansion (E), Permutation (P) and Selection/Substitution (S)
Kerberos Key Distribution (Authentication) Service (KDS)
Client Sends AS Request to KDS
PGO Items; rs_pgo RPC Interface
PGO Items; rs_pgo RPC Interface
Bitwise Operations and Rotations
Kerberos Key Distribution (Authentication) Service (KDS)
Terminology, Notation, and Conventions
Terminology, Notation, and Conventions
Notes on Common ACL Manager ACLs
Interface UUID and Version Number for rdacl Interface
Interface UUID and Version Number for rs_bind
Interface UUID and Version Number for rs_policy
Interface UUID and Version Number for rs_pgo
Interface UUID and Version Number for rs_acct
Interface UUID and Version Number for rs_misc
Interface UUID and Version Number for rs_prop_acct
Interface UUID and Version Number for rs_prop_acl
Interface UUID and Version Number for rs_prop_attr
Interface UUID and Version Number for rs_prop_attr_schema
Interface UUID and Version Number for rs_prop_pgo
Interface UUID and Version Number for rs_prop_plcy
Interface UUID and Version Number for rs_prop_replist
Interface UUID and Version Number for rs_pwd_mgmt
Interface UUID and Version Number for rs_qry
Interface UUID and Version Number for rs_repadm
Interface UUID and Version Number for rs_replist
Interface UUID and Version Number for rs_repmgr
Interface UUID and Version Number for rs_rpladmn
Interface UUID and Version Number for rs_unix
Interface UUID and Version Number for rs_update
Interface UUID and Version Number for the secidmap Interface
Interface UUID and Version Number for scd Interface
Registered Protocol Version Numbers
Bitwise Operations and Rotations
Bitwise Operations and Rotations
Integration with Naming Services
Object Types, ACL Types, and ACL Inheritance
Access Control for the xattrschema Object
Object Types, ACL Types, and ACL Inheritance
Subjects and Objects, Privilege and Authorisation
Object Types, ACL Types, and ACL Inheritance
Registration Service (RS) and RS Editors
Registration Service (RS) and RS Editors
Registration Service (RS) and RS Editors
Identifying Protected Objects and ACLs
Identifying Protected Objects and ACLs
Knowledge versus Belief; Trust
Subjects and Objects, Privilege and Authorisation
Identifying Protected Objects and ACLs
RS Protected Objects and their ACL Manager Types
Key-based Security: Kerckhoffs' Doctrine
Pre-Authentication and Obtaining a TGT
Login Facility and Security Client Daemon (SCD)
Subjects and Objects, Privilege and Authorisation
Bitwise Operations and Rotations
Bitwise Operations and Rotations
Knowledge versus Belief; Trust
Kerberos Key Distribution (Authentication) Service (KDS)
Optional and Required Restrictions
Bitwise Operations and Rotations
Key Distribution (Authentication) Services
Integration with Naming Services
Registration Service (RS) and RS Editors
RS Protected Objects and their ACL Manager Types
ACL Manager Types Supported by the RS
RS Protected Objects and their ACL Manager Types
Accounts; rs_acct RPC interface
PGO Items; rs_pgo RPC Interface
RS Protected Objects and their ACL Manager Types
CL Establishment of Credentials (Conversation Manager)
ACL Managers, Permissions, Access Determination Algorithms
Outline of the Remainder of this Chapter, and of this Specification
Outline of the Remainder of this Chapter, and of this Specification
Kerberos Key Distribution (Authentication) Service (KDS)
Policy versus Service versus Mechanism
Extended Login and Password Management Overview
ACL Managers, Permissions, Access Determination Algorithms
Rounds (T): Cipher Function (F), Expansion (E), Permutation (P) and Selection/Substitution (S)
Integration with Naming Services
Server Receives Privilege Authentication Header and Sends Privilege Reverse-Authentication Header
Client Sends Privilege Authentication Header
privilege attribute certificate (PAC)
Privilege (Authorisation) Service (PS)
Privilege Attribute Certificates (PACs)
Name-based versus PAC-based Authorisation
PAC-Based Privilege Service (PS)
Name-based versus PAC-based Authorisation
PAC-Based Privilege Service (PS)
Privilege Attribute Certificates (PACs)
Privilege (Authorisation) Service (PS)
Environmental Parameters and Registry Attributes
Object Types, ACL Types, and ACL Inheritance
Part of Ticket to be Encrypted
Part of Reverse-authentication Header to be Encrypted
Part of KDS Response to be Encrypted
Part of KDS Response to be Encrypted
Kerberos Key Distribution (Authentication) Service (KDS)
Part of Reverse-authentication Header to be Encrypted
Part of Ticket to be Encrypted
Integration with Naming Services
PAC-Based Privilege Service (PS)
Subjects and Objects, Privilege and Authorisation
Key Schedule (KS): Permuted Choices (PC1, PC2) and Left Shift (LS)
Extended Login and Password Management Overview
Extended Login and Password Management Overview
Data Encryption Standard (DES)
Knowledge versus Belief; Trust
Login Facility and Security Client Daemon (SCD)
Tickets, Keys, and Cross-Registration
Registered Password-to-Key Mappings
Registered Password-to-Key Mappings
Kerberos Key Distribution (Authentication) Service (KDS)
Key Schedule (KS): Permuted Choices (PC1, PC2) and Left Shift (LS)
Key Schedule (KS): Permuted Choices (PC1, PC2) and Left Shift (LS)
Key Schedule (KS): Permuted Choices (PC1, PC2) and Left Shift (LS)
Minimum Implementation Requirements
CL Integrity and Confidentiality (PDU Verifiers and Bodies)
CO Integrity and Confidentiality (PDU Verifiers and Bodies)
CO Integrity and Confidentiality (PDU Verifiers and Bodies)
Registered Password-to-Key Mappings
ACL Managers, Permissions, Access Determination Algorithms
Additional Attribute Permission Bits
ACL Managers, Permissions, Access Determination Algorithms
Multiple ACLs and ACL Managers
ACL Managers, Permissions, Access Determination Algorithms
Name-based versus PAC-based Authorisation
Initial Permutation (IP) and Final Permutation (FP)
Rounds (T): Cipher Function (F), Expansion (E), Permutation (P) and Selection/Substitution (S)
Rounds (T): Cipher Function (F), Expansion (E), Permutation (P) and Selection/Substitution (S)
Key Schedule (KS): Permuted Choices (PC1, PC2) and Left Shift (LS)
Key Schedule (KS): Permuted Choices (PC1, PC2) and Left Shift (LS)
PGO Items; rs_pgo RPC Interface
sec_rgy_name_t-Short and Long PGO Names
sec_rgy_name_t-Short and Long PGO Names
Integration with Naming Services
Integration with Naming Services
Untrusted Environments: A Priori Trust and Trust Chains
Kerberos Key Distribution (Authentication) Service (KDS)
Encoding/Decoding and Encryption/Decryption of Messages
Data Encryption Standard (DES)
Login Facility and Security Client Daemon (SCD)
Policy Item, Policies and Properties; rs_policy RPC Interface
Policy versus Service versus Mechanism
Policy Item, Policies and Properties; rs_policy RPC Interface
Integration with Naming Services
Registration Service (RS) and RS Editors
Policy Item, Policies and Properties; rs_policy RPC Interface
Policy versus Service versus Mechanism
RS Protected Objects and their ACL Manager Types
ACL Manager Types Supported by the RS
RS Protected Objects and their ACL Manager Types
Policy versus Service versus Mechanism
Policy Item, Policies and Properties; rs_policy RPC Interface
Policy Item, Policies and Properties; rs_policy RPC Interface
Registration Service (RS) and RS Editors
Integration with Naming Services
RS Protected Objects and their ACL Manager Types
ACL Manager Types Supported by the RS
Identifying Protected Objects and ACLs
Minimum Implementation Requirements
Minimum Implementation Requirements
Knowledge versus Belief; Trust
KDS Server Receives AS Request and Sends AS Response
Client Sends AS Request to KDS
Pre-Authentication and Obtaining a TGT
Pre-Authentication and Obtaining a TGT
Third-Party Pre-Authentication Protocol
Third-Party Pre-Authentication Protocol
Registered Syntaxes for Cell Names
Accounts; rs_acct RPC interface
Registration Service (RS) and RS Editors
PGO Items; rs_pgo RPC Interface
Login Facility and Security Client Daemon (SCD)
Privilege (Authorisation) Service (PS)
RS Protected Objects and their ACL Manager Types
ACL Manager Types Supported by the RS
RS Protected Objects and their ACL Manager Types
Kerberos Key Distribution (Authentication) Service (KDS)
Cells-Cross-cell Authentication and Authorisation
The Common Access Determination Algorithm for Delegation
Tickets, Keys, and Cross-Registration
PGO Items; rs_pgo RPC Interface
RS Protected Objects and their ACL Manager Types
Integration with Naming Services
ACL Managers, Permissions, Access Determination Algorithms
ACL Managers, Permissions, Access Determination Algorithms
Untrusted Environments: A Priori Trust and Trust Chains
Security Attributes: Authenticity, Integrity, Confidentiality
Subjects and Objects, Privilege and Authorisation
Privilege (Authorisation) Service (PS)
Extended Privilege Attribute Facility
Privilege (Authorisation) Services
PAC-Based Privilege Service (PS)
Privilege Attribute Certificates (PACs)
Privilege Authentication Headers
Privilege Reverse-Authentication Headers
Privilege Attributes for the EPAC
Handle for Privilege Attribute Data
Privilege (Reverse-)Authentication Header Processing
Client Sends Privilege Authentication Header
Server Receives Privilege Authentication Header and Sends Privilege Reverse-Authentication Header
Client Receives Privilege Reverse-Authentication Header
privilege attribute certificate (PAC)
Privilege (Authorisation) Service (PS)
Privilege Attribute Certificates (PACs)
Client Sends Privilege Authentication Header
Privilege Authentication Headers
Privilege (Reverse-)Authentication Header Processing
Privilege Reverse-Authentication Headers
Privilege (Authorisation) Service (PS)
Privilege (Authorisation) Services
PAC-Based Privilege Service (PS)
Privilege (Authorisation) Service (PS)
Name-based versus PAC-based Authorisation
Privilege (Authorisation) Service (PS)
Subjects and Objects, Privilege and Authorisation
Cross-cell Authorisation-Vetting the Privilege-ticket-granting-ticket
Knowledge versus Belief; Trust
Login Facility and Security Client Daemon (SCD)
Login Facility and Security Client Daemon (SCD)
AS Request/Response Processing
(Reverse-)Authentication Header Processing
TGS Request/Response Processing
PTGS Request/Response Processing
Privilege (Reverse-)Authentication Header Processing
TGS Request/Response Processing (By KDS)
AS Request/Response Processing
(Reverse-)Authentication Header Processing
Privilege (Reverse-)Authentication Header Processing
TGS Request/Response Processing (By KDS)
The Development of Product Standards
Security Application Programming Interface
Accounts; rs_acct RPC interface
DCE Security Replication and Propagation
Security Attributes: Authenticity, Integrity, Confidentiality
Policy Item, Policies and Properties; rs_policy RPC Interface
Composition Laws (Chaining Properties)
Composition Laws (Chaining Properties)
Policy Item, Policies and Properties; rs_policy RPC Interface
Identifying Protected Objects and ACLs
RS Protected Objects and their ACL Manager Types
Kerberos Key Distribution (Authentication) Service (KDS)
Identifying Protected Objects and ACLs
Security Attributes: Authenticity, Integrity, Confidentiality
Object Types, ACL Types, and ACL Inheritance
Kerberos Key Distribution (Authentication) Service (KDS)
Kerberos Key Distribution (Authentication) Service (KDS)
Key-based Security: Kerckhoffs' Doctrine
The Timestamps (AS + TGS) Protocol
The Third-Party (AS + TGS) Protocol
Third-Party Pre-Authentication Protocol
Registered Protocol Version Numbers
Registered Protocol Message Types
Security in the CL RPC Protocol
Security in the CO RPC Protocol
Registered Protocol Message Types
Registered Protocol Version Numbers
Kerberos Key Distribution (Authentication) Service (KDS)
Untrusted Environments: A Priori Trust and Trust Chains
Security Services and Protocols
Knowledge versus Belief; Trust
KDS Server Receives AS Request and Sends AS Response
Client Sends AS Request to KDS
Cells-Cross-cell Authentication and Authorisation
Privilege (Authorisation) Service (PS)
PAC-Based Privilege Service (PS)
PS Server Receives PTGS Request and Sends PTGS Response
Privilege (Authorisation) Service (PS)
Privilege (Authorisation) Service (PS)
Privilege (Authorisation) Service (PS)
Privilege (Authorisation) Services
Registration Service (RS) and RS Editors
Cells-Cross-cell Authentication and Authorisation
Privilege (Authorisation) Service (PS)
Name-based versus PAC-based Authorisation
Privilege (Authorisation) Service (PS)
ps_request_become_impersonator
Privilege (Authorisation) Service (PS)
Privilege (Authorisation) Service (PS)
Privilege (Authorisation) Service (PS)
PTGS Request/Response Processing
PS Server Receives PTGS Request and Sends PTGS Response
PS Server Receives PTGS Request and Sends PTGS Response
PTGS Request/Response Processing
Initialise State Buffer and Trigonometric Vector
Initialise State Buffer and Trigonometric Vector
Integration with Naming Services
(Reverse-)Authentication Header Processing
Client Receives Privilege Reverse-Authentication Header
Server Receives Privilege Authentication Header and Sends Privilege Reverse-Authentication Header
Client Receives Reverse-Authentication Header
Common Data Types and Constants for rdacl Interface
Interface UUID and Version Number for rdacl Interface
rdacl_get_mgr_types_semantics()
rdacl_get_mgr_types_semantics()
ACL Managers, Permissions, Access Determination Algorithms
Security Attributes: Authenticity, Integrity, Confidentiality
RS Binding; rs_bind Interface and sec_rgy_bind API
Policy versus Service versus Mechanism
Cells-Cross-cell Authentication and Authorisation
Key Distribution (Authentication) Services
KDS Server Receives AS Request and Sends AS Response
Server Receives Authentication Header and Sends Reverse-Authentication Header
Client Receives Reverse-Authentication Header
KDS Server Receives TGS Request and Sends TGS Response
PS Server Receives PTGS Request and Sends PTGS Response
Server Receives Privilege Authentication Header and Sends Privilege Reverse-Authentication Header
Client Receives Privilege Reverse-Authentication Header
Transmitting and Receiving EPACs
Privilege (Authorisation) Service (PS)
Untrusted Environments: A Priori Trust and Trust Chains
ACL Manager Types Supported by the RS
Privilege (Authorisation) Service (PS)
The Complete Cross-cell Scenario
Implementation Variability Regarding Required Rights
Registered Protocol Version Numbers
Registered Protocol Message Types
Registered Syntaxes for Cell Names
Registered Error Status Codes/Text/Data
Registered Encryption Key Types
Registered Password-to-Key Mappings
Registered Authentication Data Types
Registered Authorisation Data Types
Registered Authentication Services
Registered Authorisation Services
Registered Authentication Data Types
Registered Authentication Services
Registered Authorisation Data Types
Registered Authorisation Services
Registered Syntaxes for Cell Names
Registered Encryption Key Types
Registered Error Status Codes/Text/Data
Registered Password-to-Key Mappings
Registered Protocol Message Types
Registered Protocol Version Numbers
Registration Service (RS) and RS Editors
Registration Service (RS) and RS Editors
Cells-Cross-cell Authentication and Authorisation
Tickets, Keys, and Cross-Registration
Integration with Naming Services
Extended Registry Attribute Facility
Environmental Parameters and Registry Attributes
Environmental Parameters and Registry Attributes
Registration Service (RS) and RS Editors
Login Facility and Security Client Daemon (SCD)
Policy Item, Policies and Properties; rs_policy RPC Interface
Registration Service (RS) and RS Editors
ACL Manager Types Supported by the RS
Privilege (Authorisation) Service (PS)
Further Discussion of Certification
ACL Managers, Permissions, Access Determination Algorithms
Security Attributes: Authenticity, Integrity, Confidentiality
Outline of the Remainder of this Chapter, and of this Specification
KDS Server Receives AS Request and Sends AS Response
Client Sends AS Request to KDS
Integration with Time Services
Server Receives Authentication Header and Sends Reverse-Authentication Header
RS Binding; rs_bind Interface and sec_rgy_bind API
Authentication between Replicas
DCE Security Replication and Propagation
RS Binding; rs_bind Interface and sec_rgy_bind API
RS Binding; rs_bind Interface and sec_rgy_bind API
RS Protected Objects and their ACL Manager Types
RS Protected Objects and their ACL Manager Types
RS Protected Objects and their ACL Manager Types
Integer Representations (Endianness)
Security Attributes: Authenticity, Integrity, Confidentiality
Client Sends AS Request to KDS
KDS Server Receives AS Request and Sends AS Response
KDS Server Receives TGS Request and Sends TGS Response
PS Server Receives PTGS Request and Sends PTGS Response
TGS Request/Response Processing
Kerberos Key Distribution (Authentication) Service (KDS)
KDS Server Receives AS Request and Sends AS Response
AS Request/Response Processing
PTGS Request/Response Processing
PS Server Receives PTGS Request and Sends PTGS Response
Kerberos Key Distribution (Authentication) Service (KDS)
Kerberos Key Distribution (Authentication) Service (KDS)
KDS Server Receives TGS Request and Sends TGS Response
AS Request/Response Processing
TGS Request/Response Processing
PTGS Request/Response Processing
TGS Request/Response Processing (By KDS)
Optional and Required Restrictions
Implementation Variability Regarding Required Rights
Minimum Implementation Requirements
PGO Items; rs_pgo RPC Interface
Security Attributes: Authenticity, Integrity, Confidentiality
Part of KDS Response to be Encrypted
KDS Server Receives AS Request and Sends AS Response
KDS Server Receives TGS Request and Sends TGS Response
PS Server Receives PTGS Request and Sends PTGS Response
TGS Request/Response Processing
Kerberos Key Distribution (Authentication) Service (KDS)
KDS Server Receives AS Request and Sends AS Response
AS Request/Response Processing
PTGS Request/Response Processing
PS Server Receives PTGS Request and Sends PTGS Response
Kerberos Key Distribution (Authentication) Service (KDS)
Kerberos Key Distribution (Authentication) Service (KDS)
KDS Server Receives TGS Request and Sends TGS Response
KDS Server Receives TGS Request and Sends TGS Response
Optional and Required Restrictions
Entry Types for Delegate and Target Restrictions
Delegate and Target Restriction Types
Set of Delegation and Target Restrictions
Optional and Required Restrictions
Entry Types for Delegate and Target Restrictions
Delegate and Target Restriction Types
Set of Delegation and Target Restrictions
Client Receives Reverse-Authentication Header
Reverse-Authentication Headers
(Reverse-)Authentication Header Processing
(Reverse-)Authentication Header Processing
Server Receives Authentication Header and Sends Reverse-Authentication Header
Privilege (Authorisation) Service (PS)
Registered Password-to-Key Mappings
(Reverse-)Authentication Header Processing
Privilege (Reverse-)Authentication Header Processing
Reverse-Authentication Headers
Part of Reverse-authentication Header to be Encrypted
Server Receives Authentication Header and Sends Reverse-Authentication Header
Client Receives Reverse-Authentication Header
Privilege Reverse-Authentication Headers
Server Receives Privilege Authentication Header and Sends Privilege Reverse-Authentication Header
Client Receives Privilege Reverse-Authentication Header
Key Distribution (Authentication) Services
Part of Ticket to be Encrypted
Implementation Variability Regarding Required Rights
Implementation Variability Regarding Required Rights
Generalities on Security-The Architecture of Trust
Accounts; rs_acct RPC interface
Bitwise Operations and Rotations
Bitwise Operations and Rotations
Bitwise Operations and Rotations
Rounds (T): Cipher Function (F), Expansion (E), Permutation (P) and Selection/Substitution (S)
Miscellaneous Routines Needed for DCE Security
Policy Item, Policies and Properties; rs_policy RPC Interface
PGO Items; rs_pgo RPC Interface
Accounts; rs_acct RPC interface
Miscellaneous; rs_misc RPC Interface
Security in the CL RPC Protocol
Security in the CO RPC Protocol
The rs_attr_schema RPC Interface
The rs_prop_acct RPC Interface
The rs_prop_attr RPC Interface
The rs_prop_attr_schema RPC Interface
The rs_prop_plcy RPC Interface
The rs_prop_replist RPC Interface
Key Management Facility RPC Interface
The Key Management RPC Interface
Login Facility and Security Client Daemon (SCD) RPC Interface
Identifying Protected Objects and ACLs
What is Specified in this Chapter
Login Facility and Security Client Daemon (SCD)
Login Facility and Security Client Daemon (SCD)
Name-based versus PAC-based Authorisation
Registration Service (RS) and RS Editors
ACL Manager Types Supported by the RS
RS Binding; rs_bind Interface and sec_rgy_bind API
RS Protected Objects and their ACL Manager Types
Common Data Types and Constants for RS Editors
RS Binding; rs_bind Interface and sec_rgy_bind API
Registration Service (RS) and RS Editors
Registration Service (RS) and RS Editors
Registration Service (RS) and RS Editors
ACL Manager Types Supported by the RS
ACL Manager Types Supported by the RS
Cells-Cross-cell Authentication and Authorisation
Integration with Naming Services
Registration Service (RS) and RS Editors
Accounts; rs_acct RPC interface
Common Data Types and Constants for rs_acct
Interface UUID and Version Number for rs_acct
Accounts; rs_acct RPC interface
Accounts; rs_acct RPC interface
Accounts; rs_acct RPC interface
Accounts; rs_acct RPC interface
Accounts; rs_acct RPC interface
Accounts; rs_acct RPC interface
Common Data Types and Constants for rs_attr
The rs_attr_schema RPC Interface
Common Data Types and Constants for rs_attr_schema
Interface UUID for rs_attr_schema
The rs_attr_schema RPC Interface
rs_attr_schema_aclmgr_strings()
rs_attr_schema_aclmgr_strings()
rs_attr_schema_lookup_by_name()
rs_attr_schema_lookup_by_name()
rs_auth_policy_get_effective()
Policy Item, Policies and Properties; rs_policy RPC Interface
rs_auth_policy_get_effective()
Policy Item, Policies and Properties; rs_policy RPC Interface
Policy Item, Policies and Properties; rs_policy RPC Interface
RS Binding; rs_bind Interface and sec_rgy_bind API
Common Data Types and Constants for rs_bind
Interface UUID and Version Number for rs_bind
RS Binding; rs_bind Interface and sec_rgy_bind API
RS Binding; rs_bind Interface and sec_rgy_bind API
Miscellaneous; rs_misc RPC Interface
Miscellaneous; rs_misc RPC Interface
Common Data Types and Constants for rs_misc
Interface UUID and Version Number for rs_misc
Miscellaneous; rs_misc RPC Interface
Registration Service (RS) and RS Editors
PGO Items; rs_pgo RPC Interface
Common Data Types and Constants for rs_pgo
Interface UUID and Version Number for rs_pgo
PGO Items; rs_pgo RPC Interface
PGO Items; rs_pgo RPC Interface
PGO Items; rs_pgo RPC Interface
PGO Items; rs_pgo RPC Interface
PGO Items; rs_pgo RPC Interface
PGO Items; rs_pgo RPC Interface
PGO Items; rs_pgo RPC Interface
PGO Items; rs_pgo RPC Interface
PGO Items; rs_pgo RPC Interface
PGO Items; rs_pgo RPC Interface
Registration Service (RS) and RS Editors
Policy Item, Policies and Properties; rs_policy RPC Interface
Common Data Types and Constants for rs_policy
Interface UUID and Version Number for rs_policy
Policy Item, Policies and Properties; rs_policy RPC Interface
Policy Item, Policies and Properties; rs_policy RPC Interface
Policy Item, Policies and Properties; rs_policy RPC Interface
The rs_prop_acct RPC Interface
Common Data Types and Constants for rs_prop_acct
Interface UUID and Version Number for rs_prop_acct
The rs_prop_acct RPC Interface
rs_prop_acct_add_key_version()
rs_prop_acct_add_key_version()
Common Data Types and Constants for rs_prop_acl
Interface UUID and Version Number for rs_prop_acl
The rs_prop_attr RPC Interface
Common Data Types and Constants for rs_prop_attr
Interface UUID and Version Number for rs_prop_attr
The rs_prop_attr RPC Interface
rs_prop_attr_sch_create_data_t
rs_prop_attr_sch_create_data_t
The rs_prop_attr_schema RPC Interface
Common Data Types and Constants for rs_prop_attr_schema
Interface UUID and Version Number for rs_prop_attr_schema
The rs_prop_attr_schema RPC Interface
Common Data Types and Constants for rs_prop_pgo
Interface UUID and Version Number for rs_prop_pgo
The rs_prop_plcy RPC Interface
Interface UUID and Version Number for rs_prop_plcy
The rs_prop_plcy RPC Interface
rs_prop_plcy_set_dom_cache_info()
rs_prop_plcy_set_dom_cache_info()
The rs_prop_replist RPC Interface
Interface UUID and Version Number for rs_prop_replist
The rs_prop_replist RPC Interface
Policy Item, Policies and Properties; rs_policy RPC Interface
Policy Item, Policies and Properties; rs_policy RPC Interface
Common Data Types and Constants for rs_pwd_mgmt
Interface UUID and Version Number for rs_pwd_mgmt
Interface UUID and Version Number for rs_qry
rs_rep_mgr_get_info_and_creds()
rs_rep_mgr_get_info_and_creds()
rs_rep_mgr_stop_until_compat_sw()
rs_rep_mgr_stop_until_compat_sw()
Common Data Types and Constants for rs_repadm
Interface UUID and Version Number for rs_repadm
rs_replica_auth_t and rs_replica_auth_p_t
rs_replica_auth_t and rs_replica_auth_p_t
rs_replica_auth_t and rs_replica_auth_p_t
rs_replica_auth_t and rs_replica_auth_p_t
rs_replica_item_t and rs_replica_item_p_t
rs_replica_item_t and rs_replica_item_p_t
rs_replica_item_t and rs_replica_item_p_t
rs_replica_item_t and rs_replica_item_p_t
rs_replica_master_info_t and rs_replica_master_info_p_t
rs_replica_master_info_t and rs_replica_master_info_p_t
rs_replica_master_info_t and rs_replica_master_info_p_t
rs_replica_master_info_t and rs_replica_master_info_p_t
Common Data Types and Constants for rs_replist
Interface UUID and Version Number for rs_replist
Common Data Types and Constants for rs_repmgr
Interface UUID and Version Number for rs_repmgr
Interface UUID and Version Number for rs_rpladmn
Common Data Types and Constants for rs_unix
Interface UUID and Version Number for rs_unix
Interface UUID and Version Number for rs_update
Policy versus Service versus Mechanism
Object Types, ACL Types, and ACL Inheritance
Rounds (T): Cipher Function (F), Expansion (E), Permutation (P) and Selection/Substitution (S)
Rounds (T): Cipher Function (F), Expansion (E), Permutation (P) and Selection/Substitution (S)
Third-Party Pre-Authentication Protocol
Registered Password-to-Key Mappings
Registered Authentication Data Types
PTGS Request/Response Processing
Login Facility and Security Client Daemon (SCD)
Login Facility and Security Client Daemon (SCD) RPC Interface
Common Data Types and Constants for scd Interface
Interface UUID and Version Number for scd Interface
The Complete Cross-cell Scenario
Key Schedule (KS): Permuted Choices (PC1, PC2) and Left Shift (LS)
Schemas for Well-Known Attributes
Schemas for Well-Known Attributes
Encoding/Decoding and Encryption/Decryption of Messages
Minimum Implementation Requirements
Integration with Naming Services
RS Binding; rs_bind Interface and sec_rgy_bind API
sec_acl_get_mgr_types_semantics
sec_attr_bind_auth_info_type_t
sec_attr_bind_auth_info_type_t
The sec_cred API for Abstracting EPAC Contents
EPAC Accessor Function (sec_cred) API
sec_cred_get_authz_session_info
sec_cred_get_client_princ_name
sec_cred_get_deleg_restrictions
sec_cred_initialize_attr_cursor
sec_key_mgmt_initialize_cursor
Login Facility and Security Client Daemon (SCD)
Login Facility and Security Client Daemon (SCD)
Enabling and Disabling Delegation
Further Discussion of Certification
Login Facility and Security Client Daemon (SCD)
Login Facility and Security Client Daemon (SCD)
Login Facility and Security Client Daemon (SCD)
Login Facility and Security Client Daemon (SCD)
Login Facility and Security Client Daemon (SCD)
Login Facility and Security Client Daemon (SCD)
Login Facility and Security Client Daemon (SCD)
Login Facility and Security Client Daemon (SCD)
Login Facility and Security Client Daemon (SCD)
Login Facility and Security Client Daemon (SCD)
Login Facility and Security Client Daemon (SCD)
Login Facility and Security Client Daemon (SCD)
Login Facility and Security Client Daemon (SCD)
Login Facility and Security Client Daemon (SCD)
Login Facility and Security Client Daemon (SCD)
Login Facility and Security Client Daemon (SCD)
Login Facility and Security Client Daemon (SCD)
sec_login_valid_and_cert_ident
Login Facility and Security Client Daemon (SCD)
Further Discussion of Certification
Login Facility and Security Client Daemon (SCD)
Login Facility and Security Client Daemon (SCD)
sec_rgy_attr_sch_aclmgr_strings
sec_rgy_attr_sch_cursor_release
sec_rgy_attr_sch_lookup_by_name
sec_rgy_auth_plcy_get_effective
RS Binding; rs_bind Interface and sec_rgy_bind API
RS Binding; rs_bind Interface and sec_rgy_bind API
RS Binding; rs_bind Interface and sec_rgy_bind API
sec_rgy_name_t-Short and Long PGO Names
sec_rgy_name_t-Short and Long PGO Names
sec_rgy_pgo_get_by_eff_unix_num
RS Binding; rs_bind Interface and sec_rgy_bind API
RS Binding; rs_bind Interface and sec_rgy_bind API
RS Binding; rs_bind Interface and sec_rgy_bind API
RS Binding; rs_bind Interface and sec_rgy_bind API
RS Binding; rs_bind Interface and sec_rgy_bind API
RS Binding; rs_bind Interface and sec_rgy_bind API
RS Binding; rs_bind Interface and sec_rgy_bind API
Common Data Types and Constants for the secidmap Interface
Interface UUID and Version Number for the secidmap Interface
Combined First and Second Steps
Privilege (Authorisation) Service (PS)
Accounts; rs_acct RPC interface
Security Attributes: Authenticity, Integrity, Confidentiality
Untrusted Environments: A Priori Trust and Trust Chains
Distributed Security: Secrets and Cryptology
Distributed Security: Secrets and Cryptology
Security Attributes: Authenticity, Integrity, Confidentiality
Introduction to Security Services
Security Attributes: Authenticity, Integrity, Confidentiality
Distributed Security: Secrets and Cryptology
Key-based Security: Kerckhoffs' Doctrine
Login Facility and Security Client Daemon (SCD)
Security Services and Protocols
DCE Security Replication and Propagation
Security in the CL RPC Protocol
Security in the CO RPC Protocol
Login Facility and Security Client Daemon (SCD) RPC Interface
Security Application Programming Interface
Miscellaneous Routines Needed for DCE Security
Login Facility and Security Client Daemon (SCD)
Login Facility and Security Client Daemon (SCD)
Integration with Naming Services
Introduction to Security Services
Security Attributes: Authenticity, Integrity, Confidentiality
Integration with Time Services
Distributed Security: Secrets and Cryptology
Generalities on Security-The Architecture of Trust
Integration with Naming Services
Data Encryption Standard (DES)
Distributed Security: Secrets and Cryptology
Integration with Time Services
Untrusted Environments: A Priori Trust and Trust Chains
What is Specified in this Chapter
Cryptography- and Security-Related Data Types
Generalities on Security-The Architecture of Trust
Security-Version (Version 2) UUIDs
Security-Version (Version 2) UUIDs
Registered Password-to-Key Mappings
Rounds (T): Cipher Function (F), Expansion (E), Permutation (P) and Selection/Substitution (S)
Untrusted Environments: A Priori Trust and Trust Chains
Encoding/Decoding and Encryption/Decryption of Messages
ACL Managers, Permissions, Access Determination Algorithms
Client Sends AS Request to KDS
KDS Server Receives AS Request and Sends AS Response
Client Sends Authentication Header
Server Receives Authentication Header and Sends Reverse-Authentication Header
KDS Server Receives TGS Request and Sends TGS Response
PS Server Receives PTGS Request and Sends PTGS Response
Client Sends Privilege Authentication Header
Server Receives Privilege Authentication Header and Sends Privilege Reverse-Authentication Header
KDS Server Receives TGS Request and Sends TGS Response
Integer Representations (Endianness)
Key Distribution (Authentication) Services
KDS Server Receives AS Request and Sends AS Response
Server Receives Authentication Header and Sends Reverse-Authentication Header
KDS Server Receives TGS Request and Sends TGS Response
PS Server Receives PTGS Request and Sends PTGS Response
Server Receives Privilege Authentication Header and Sends Privilege Reverse-Authentication Header
KDS Server Receives TGS Request and Sends TGS Response
Integration with Naming Services
CL Establishment of Credentials (Conversation Manager)
RS Binding; rs_bind Interface and sec_rgy_bind API
Server Receives Authentication Header and Sends Reverse-Authentication Header
Server Receives Privilege Authentication Header and Sends Privilege Reverse-Authentication Header
PS Server Receives PTGS Request and Sends PTGS Response
Kerberos Key Distribution (Authentication) Service (KDS)
Tickets, Keys, and Cross-Registration
Policy versus Service versus Mechanism
Kerberos Key Distribution (Authentication) Service (KDS)
Privilege (Authorisation) Service (PS)
Registration Service (RS) and RS Editors
PAC-Based Privilege Service (PS)
distributed time service (DTS)
PAC-Based Privilege Service (PS)
Kerberos Key Distribution (Authentication) Service (KDS)
Kerberos Key Distribution (Authentication) Service (KDS)
Policy versus Service versus Mechanism
Security Attributes: Authenticity, Integrity, Confidentiality
Policy versus Service versus Mechanism
Privilege (Authorisation) Service (PS)
Tickets, Keys, and Cross-Registration
Introduction to Security Services
Integration with Time Services
Integration with Naming Services
Security Services and Protocols
Key Distribution (Authentication) Services
Privilege (Authorisation) Services
Registered Authentication Services
Registered Authorisation Services
Kerberos Key Distribution (Authentication) Service (KDS)
Tickets, Keys, and Cross-Registration
Kerberos Key Distribution (Authentication) Service (KDS)
KDS Server Receives AS Request and Sends AS Response
Kerberos Key Distribution (Authentication) Service (KDS)
Kerberos Key Distribution (Authentication) Service (KDS)
Kerberos Key Distribution (Authentication) Service (KDS)
Set of Delegation and Target Restrictions
Bitwise Operations and Rotations
Key Schedule (KS): Permuted Choices (PC1, PC2) and Left Shift (LS)
Key Schedule (KS): Permuted Choices (PC1, PC2) and Left Shift (LS)
sec_rgy_name_t-Short and Long PGO Names
Kerberos Key Distribution (Authentication) Service (KDS)
Tickets, Keys, and Cross-Registration
Message Digests 4 and 5 (MD4, MD5)
Object Types, ACL Types, and ACL Inheritance
RS Binding; rs_bind Interface and sec_rgy_bind API
Kerberos Key Distribution (Authentication) Service (KDS)
Integration with Time Services
Timestamps, Microseconds, and Clock Skew
RS Binding; rs_bind Interface and sec_rgy_bind API
Status Codes Specific to Delegation
Versions and Issues of Specifications
Outline of the Remainder of this Chapter, and of this Specification
What is Specified in this Chapter
The Development of Product Standards
Data Encryption Standard (DES)
data encryption standard (DES)
Kerberos Key Distribution (Authentication) Service (KDS)
Client Sends AS Request to KDS
Initialise State Buffer and Trigonometric Vector
Initialise State Buffer and Trigonometric Vector
Login Facility and Security Client Daemon (SCD)
Registered Error Status Codes/Text/Data
Status Codes Specific to Delegation
Combined First and Second Steps
Key-based Security: Kerckhoffs' Doctrine
Name-based versus PAC-based Authorisation
PGO Items; rs_pgo RPC Interface
Security in the CO RPC Protocol
USER/FOREIGN_USER Subalgorithm
GROUP_OBJ/GROUP/FOREIGN_GROUP Subalgorithm
USER_DEL/FOREIGN_USER_DEL Subalgorithm
GROUP_OBJ_DEL/GROUP_DEL/FOREIGN_GROUP_DEL Subalgorithm
FOREIGN_OTHER_DEL Subalgorithm
Non-Intermediary Subalgorithms
Subjects and Objects, Privilege and Authorisation
Subjects and Objects, Privilege and Authorisation
Subjects and Objects, Privilege and Authorisation
Rounds (T): Cipher Function (F), Expansion (E), Permutation (P) and Selection/Substitution (S)
Rounds (T): Cipher Function (F), Expansion (E), Permutation (P) and Selection/Substitution (S)
ACL Manager Types Supported by the RS
Tickets, Keys, and Cross-Registration
Cells-Cross-cell Authentication and Authorisation
Privilege (Authorisation) Service (PS)
Cells-Cross-cell Authentication and Authorisation
Kerberos Key Distribution (Authentication) Service (KDS)
Encoding/Decoding and Encryption/Decryption of Messages
Registered Syntaxes for Cell Names
Rounds (T): Cipher Function (F), Expansion (E), Permutation (P) and Selection/Substitution (S)
Initialise State Buffer and Trigonometric Vector
Entry Types for Delegate and Target Restrictions
Delegate and Target Restriction Types
Set of Delegation and Target Restrictions
Kerberos Key Distribution (Authentication) Service (KDS)
Tickets, Keys, and Cross-Registration
Kerberos Key Distribution (Authentication) Service (KDS)
Untrusted Environments: A Priori Trust and Trust Chains
Tickets, Keys, and Cross-Registration
Generalities on Security-The Architecture of Trust
Terminology, Notation, and Conventions
Terminology, Notation, and Conventions
Generalities on Security-The Architecture of Trust
ACL Managers, Permissions, Access Determination Algorithms
The Timestamps (AS + TGS) Protocol
The Third-Party (AS + TGS) Protocol
TGS Request/Response Processing
KDS Server Receives TGS Request and Sends TGS Response
TGS Request/Response Processing (By KDS)
Kerberos Key Distribution (Authentication) Service (KDS)
Privilege (Authorisation) Service (PS)
Privilege (Authorisation) Service (PS)
Kerberos Key Distribution (Authentication) Service (KDS)
Privilege (Authorisation) Service (PS)
KDS Server Receives TGS Request and Sends TGS Response
KDS Server Receives TGS Request and Sends TGS Response
TGS Request/Response Processing
Pre-Authentication and Obtaining a TGT
RS Protected Objects and their ACL Manager Types
Generalities on Security-The Architecture of Trust
Untrusted Environments: A Priori Trust and Trust Chains
The Third-Party (AS + TGS) Protocol
Third-Party Pre-Authentication Protocol
The Third-Party (AS + TGS) Protocol
Outline of the Remainder of this Chapter, and of this Specification
What is Specified in this Chapter
Policy versus Service versus Mechanism
Part of Ticket to be Encrypted
Part of Ticket to be Encrypted
Privilege (Authorisation) Service (PS)
Kerberos Key Distribution (Authentication) Service (KDS)
Part of Ticket to be Encrypted
Kerberos Key Distribution (Authentication) Service (KDS)
Kerberos Key Distribution (Authentication) Service (KDS)
Kerberos Key Distribution (Authentication) Service (KDS)
Part of Ticket to be Encrypted
Tickets, Keys, and Cross-Registration
Kerberos Key Distribution (Authentication) Service (KDS)
Policy Item, Policies and Properties; rs_policy RPC Interface
Login Facility and Security Client Daemon (SCD)
Privilege (Authorisation) Service (PS)
The Complete Cross-cell Scenario
Kerberos Key Distribution (Authentication) Service (KDS)
Kerberos Key Distribution (Authentication) Service (KDS)
Tickets, Keys, and Cross-Registration
Integration with Time Services
Kerberos Key Distribution (Authentication) Service (KDS)
Tickets, Keys, and Cross-Registration
Integration with Time Services
distributed time service (DTS)
Integration with Time Services
Integration with Time Services
Timestamps, Microseconds, and Clock Skew
Kerberos Key Distribution (Authentication) Service (KDS)
Timestamps, Microseconds, and Clock Skew
Security Attributes: Authenticity, Integrity, Confidentiality
KDS Server Receives TGS Request and Sends TGS Response
Timestamps, Microseconds, and Clock Skew
Integration with Time Services
Timestamps, Microseconds, and Clock Skew
Kerberos Key Distribution (Authentication) Service (KDS)
Kerberos Key Distribution (Authentication) Service (KDS)
Timestamps, Microseconds, and Clock Skew
Integration with Time Services
The Timestamps (AS + TGS) Protocol
Timestamps, Microseconds, and Clock Skew
The Timestamps (AS + TGS) Protocol
Delegation Token (Version 0) Format
ACL Managers, Permissions, Access Determination Algorithms
Knowledge versus Belief; Trust
Kerberos Key Distribution (Authentication) Service (KDS)
KDS Server Receives TGS Request and Sends TGS Response
Kerberos Key Distribution (Authentication) Service (KDS)
Privilege (Authorisation) Service (PS)
Untrusted Environments: A Priori Trust and Trust Chains
Transmitting and Receiving EPACs
Access Control on Attributes with Triggers
Initialise State Buffer and Trigonometric Vector
Initialise State Buffer and Trigonometric Vector
Initialise State Buffer and Trigonometric Vector
Registered Encryption Key Types
Generalities on Security-The Architecture of Trust
Knowledge versus Belief; Trust
Untrusted Environments: A Priori Trust and Trust Chains
Untrusted Environments: A Priori Trust and Trust Chains
Cells-Cross-cell Authentication and Authorisation
The Complete Cross-cell Scenario
Distributed Security: Secrets and Cryptology
Knowledge versus Belief; Trust
Privilege (Authorisation) Service (PS)
Cells-Cross-cell Authentication and Authorisation
Privilege (Authorisation) Service (PS)
Privilege (Authorisation) Service (PS)
Login Facility and Security Client Daemon (SCD)
Cells-Cross-cell Authentication and Authorisation
Untrusted Environments: A Priori Trust and Trust Chains
ACL Managers, Permissions, Access Determination Algorithms
Identifying Protected Objects and ACLs
ACL Manager Types Supported by the RS
Identifying Protected Objects and ACLs
RS Protected Objects and their ACL Manager Types
Object Types, ACL Types, and ACL Inheritance
ACL Manager Types Supported by the RS
Access Control for Attribute Types
Registered Protocol Message Types
Cryptography- and Security-Related Data Types
Registered Encryption Key Types
Registered Authentication Data Types
Registered Authorisation Data Types
Entry Types for Delegate and Target Restrictions
Delegate and Target Restriction Types
Common Data Types and Constants for rdacl Interface
RS Protected Objects and their ACL Manager Types
Common Data Types and Constants for RS Editors
Common Data Types and Constants for rs_bind
Common Data Types and Constants for rs_policy
Common Data Types and Constants for rs_pgo
Common Data Types and Constants for rs_acct
Common Data Types and Constants for rs_misc
Common Data Types and Constants for rs_attr
Common Data Types and Constants for rs_attr_schema
Common Data Types and Constants for rs_prop_acct
Common Data Types and Constants for rs_prop_acl
Common Data Types and Constants for rs_prop_attr
Common Data Types and Constants for rs_prop_attr_schema
Common Data Types and Constants for rs_prop_pgo
Common Data Types and Constants for rs_pwd_mgmt
Common Data Types and Constants for rs_repadm
Common Data Types and Constants for rs_replist
Common Data Types and Constants for rs_repmgr
Common Data Types and Constants for rs_unix
Common Data Types and Constants for the secidmap Interface
Common Data Types and Constants for Key Management
Common Data Types and Constants for scd Interface
Multiple ACLs and ACL Managers
Privilege (Authorisation) Service (PS)
ACL Managers, Permissions, Access Determination Algorithms
Registered Encryption Key Types
Cells-Cross-cell Authentication and Authorisation
Identifying Protected Objects and ACLs
Security-Version (Version 2) UUIDs
PGO Items; rs_pgo RPC Interface
Unknown Intercell Action Attribute
Unknown Intercell Action Attribute
PS Server Receives PTGS Request and Sends PTGS Response
Key Distribution (Authentication) Services
Untrusted Environments: A Priori Trust and Trust Chains
Key Distribution (Authentication) Services
Login Facility and Security Client Daemon (SCD)
Registered Password-to-Key Mappings
KDS Server Receives TGS Request and Sends TGS Response
USER/FOREIGN_USER Subalgorithm
ACL Managers, Permissions, Access Determination Algorithms
ACL Managers, Permissions, Access Determination Algorithms
USER/FOREIGN_USER Subalgorithm
USER_DEL/FOREIGN_USER_DEL Subalgorithm
USER_DEL/FOREIGN_USER_DEL Subalgorithm
ACL Managers, Permissions, Access Determination Algorithms
Timestamps, Microseconds, and Clock Skew
Interface UUID and Version Number for rdacl Interface
Interface UUID and Version Number for rs_bind
Interface UUID and Version Number for rs_policy
Interface UUID and Version Number for rs_pgo
Interface UUID and Version Number for rs_acct
Interface UUID and Version Number for rs_misc
Interface UUID for rs_attr_schema
Interface UUID and Version Number for rs_prop_acct
Interface UUID and Version Number for rs_prop_acl
Interface UUID and Version Number for rs_prop_attr
Interface UUID and Version Number for rs_prop_attr_schema
Interface UUID and Version Number for rs_prop_pgo
Interface UUID and Version Number for rs_prop_plcy
Interface UUID and Version Number for rs_prop_replist
Interface UUID and Version Number for rs_pwd_mgmt
Interface UUID and Version Number for rs_qry
Interface UUID and Version Number for rs_repadm
Interface UUID and Version Number for rs_replist
Interface UUID and Version Number for rs_repmgr
Interface UUID and Version Number for rs_rpladmn
Interface UUID and Version Number for rs_unix
Interface UUID and Version Number for rs_update
Interface UUID and Version Number for the secidmap Interface
Interface UUID and Version Number for scd Interface
Identifying Protected Objects and ACLs
RS Protected Objects and their ACL Manager Types
Login Facility and Security Client Daemon (SCD)
Privilege (Authorisation) Service (PS)
PGO Items; rs_pgo RPC Interface
Policy Item, Policies and Properties; rs_policy RPC Interface
Privilege (Authorisation) Service (PS)
Privilege (Authorisation) Service (PS)
Privilege (Authorisation) Service (PS)
Privilege (Authorisation) Service (PS)
Interface UUID and Version Number for rdacl Interface
Interface UUID and Version Number for rs_acct
Interface UUID for rs_attr_schema
Interface UUID and Version Number for rs_bind
Interface UUID and Version Number for rs_misc
Interface UUID and Version Number for rs_pgo
Interface UUID and Version Number for rs_policy
Interface UUID and Version Number for rs_prop_acct
Interface UUID and Version Number for rs_prop_acl
Interface UUID and Version Number for rs_prop_attr
Interface UUID and Version Number for rs_prop_attr_schema
Interface UUID and Version Number for rs_prop_pgo
Interface UUID and Version Number for rs_prop_plcy
Interface UUID and Version Number for rs_prop_replist
Interface UUID and Version Number for rs_pwd_mgmt
Interface UUID and Version Number for rs_qry
Interface UUID and Version Number for rs_repadm
Interface UUID and Version Number for rs_replist
Interface UUID and Version Number for rs_repmgr
Interface UUID and Version Number for rs_rpladmn
Interface UUID and Version Number for rs_unix
Interface UUID and Version Number for rs_update
Interface UUID and Version Number for scd Interface
Interface UUID and Version Number for the secidmap Interface
Security-Version (Version 2) UUIDs
Login Facility and Security Client Daemon (SCD)
Security in the CO RPC Protocol
Security-Version (Version 2) UUIDs
Login Facility and Security Client Daemon (SCD)
Login Facility and Security Client Daemon (SCD)
Login Facility and Security Client Daemon (SCD)
Integration with Time Services
Implementation Variability Regarding Required Rights
(Reverse-)Authentication Header Processing
Initialise State Buffer and Trigonometric Vector
Initialise State Buffer and Trigonometric Vector
What is Specified in this Chapter
CO Verifier auth_value.assoc_uuid_crc
CO Verifier auth_value.checksum
CO Verifier auth_value.credentials
What is Specified in this Chapter
CO Integrity and Confidentiality (PDU Verifiers and Bodies)
CL Integrity and Confidentiality (PDU Verifiers and Bodies)
CO Integrity and Confidentiality (PDU Verifiers and Bodies)
Registered Protocol Version Numbers
Security-Version (Version 2) UUIDs
Delegation Token (Version 0) Format
Interface UUID and Version Number for rdacl Interface
Interface UUID and Version Number for rs_bind
Interface UUID and Version Number for rs_policy
Interface UUID and Version Number for rs_pgo
Interface UUID and Version Number for rs_acct
Interface UUID and Version Number for rs_misc
Interface UUID and Version Number for rs_prop_acct
Interface UUID and Version Number for rs_prop_acl
Interface UUID and Version Number for rs_prop_attr
Interface UUID and Version Number for rs_prop_attr_schema
Interface UUID and Version Number for rs_prop_pgo
Interface UUID and Version Number for rs_prop_plcy
Interface UUID and Version Number for rs_prop_replist
Interface UUID and Version Number for rs_pwd_mgmt
Interface UUID and Version Number for rs_qry
Interface UUID and Version Number for rs_repadm
Interface UUID and Version Number for rs_replist
Interface UUID and Version Number for rs_repmgr
Interface UUID and Version Number for rs_rpladmn
Interface UUID and Version Number for rs_unix
Interface UUID and Version Number for rs_update
Interface UUID and Version Number for the secidmap Interface
Interface UUID and Version Number for scd Interface
Security-Version (Version 2) UUIDs
KDS Server Receives TGS Request and Sends TGS Response
Policy Item, Policies and Properties; rs_policy RPC Interface
Security-Version (Version 2) UUIDs
Interface UUID and Version Number for rdacl Interface
Interface UUID and Version Number for rs_acct
Interface UUID and Version Number for rs_bind
Interface UUID and Version Number for rs_misc
Interface UUID and Version Number for rs_pgo
Interface UUID and Version Number for rs_policy
Interface UUID and Version Number for rs_prop_acct
Interface UUID and Version Number for rs_prop_acl
Interface UUID and Version Number for rs_prop_attr
Interface UUID and Version Number for rs_prop_attr_schema
Interface UUID and Version Number for rs_prop_pgo
Interface UUID and Version Number for rs_prop_plcy
Interface UUID and Version Number for rs_prop_replist
Interface UUID and Version Number for rs_pwd_mgmt
Interface UUID and Version Number for rs_qry
Interface UUID and Version Number for rs_repadm
Interface UUID and Version Number for rs_replist
Interface UUID and Version Number for rs_repmgr
Interface UUID and Version Number for rs_rpladmn
Interface UUID and Version Number for rs_unix
Interface UUID and Version Number for rs_update
Interface UUID and Version Number for scd Interface
Interface UUID and Version Number for the secidmap Interface
Versions and Issues of Specifications
Policy versus Service versus Mechanism
Knowledge versus Belief; Trust
Name-based versus PAC-based Authorisation
Cross-cell Authorisation-Vetting the Privilege-ticket-granting-ticket
Untrusted Environments: A Priori Trust and Trust Chains
Privilege (Authorisation) Service (PS)
PS Server Receives PTGS Request and Sends PTGS Response
Schemas for Well-Known Attributes
What is Specified in this Chapter
Security Attributes: Authenticity, Integrity, Confidentiality
Compress Message in 16-Word Chunks
Compress Message in 16-Word Chunks
Bitwise Operations and Rotations
Policy Item, Policies and Properties; rs_policy RPC Interface
RS Binding; rs_bind Interface and sec_rgy_bind API
ACL Managers, Permissions, Access Determination Algorithms
Security Attributes: Authenticity, Integrity, Confidentiality
ACL Managers, Permissions, Access Determination Algorithms
Key Distribution (Authentication) Services
Key Distribution (Authentication) Services
Registered Syntaxes for Cell Names
Key Distribution (Authentication) Services
Access Control for the xattrschema Object
Bitwise Operations and Rotations
Registered Authentication Data Types
Timestamps, Microseconds, and Clock Skew
flag, ticket (data type)
flag, word, POSIX semantics
flags
foreign
foreign ACLE type
foreign authorisation, data type
foreign group, in PAC
foreign groups authorisation, data type
foreign groupsets authorisation, data type
foreign secondary group ID
FOREIGN_GROUP
FOREIGN_GROUP, algorithm
FOREIGN_GROUP, limitation in common ACL
FOREIGN_GROUP, supported by common ACL manager
FOREIGN_GROUP_DEL, algorithm
FOREIGN_GROUP_DELEG
FOREIGN_OTHER
FOREIGN_OTHER, algorithm
FOREIGN_OTHER, limitation in common ACL
FOREIGN_OTHER, supported by common ACL manager
FOREIGN_OTHER_DEL
FOREIGN_OTHER_DEL, algorithm
FOREIGN_OTHER_DELEG
FOREIGN_USER
FOREIGN_USER, algorithm
FOREIGN_USER, limitation in common ACL
FOREIGN_USER, supported by common ACL manager
FOREIGN_USER_DEL, algorithm
FOREIGN_USER_DELEG
formalisation of security theory
format
format, for displaying permission
format, of PAC
format, PAC (data type)
formats
formatting details,
forward, combined with proxy
forwardable, in AS response
forwardable, in RS information
forwardable, in TGS request
forwardable, initialisation
forwardable, KDS request flag
forwardable, ticket flag
FP
frequency of changing password
freshness, of authenticator
frontmatter
full BER
full name
fullname permission
function
fundamental
further
future work, solve multi-hop trust chain problem
G() (used in definition of MD4)
G() (used in definition of MD5)
G-name
gecos
generalities
generalities on security
generation of ticket
generation of weak keys
generator, of CRC
generic permissions
genuine, received ticket
geographic dispersion
global
Global Group Name
Global Group Name, from Cell UUID and Group UUID
global KDS cross-registration
global PGO name
Global Principal Name, from Cell UUID and Principal UUID
global root
global uniqueness
glossary
goal of security
good password
government, restriction on use of DES
grace period
granting access
granting ticket
granularity of time
group
group delegate
group domain
group permission
group UUID,
group, ACL manager permission
group, ACL manager type
group, ACL manager type UUID
GROUP, algorithm
group, identity (data type)
group, in account item
group, in PAC
GROUP, limitation in common ACL
group, primary vs. secondary
group, separate namespace
group, supported ACLE types
GROUP, supported by common ACL manager
group-ID
group-name
GROUP_DEL, algorithm
GROUP_DELEG
GROUP_OBJ
GROUP_OBJ, algorithm
GROUP_OBJ, at most one
GROUP_OBJ, optional in common ACL manager
GROUP_OBJ/GROUP/FOREIGN_GROUP
GROUP_OBJ_DEL, algorithm
GROUP_OBJ_DEL/GROUP_DEL/FOREIGN_GROUP_DEL
GROUP_OBJ_DELEG
groups
guarantee, that SCD server is genuine
guarantee, unique stringname
guessing password
H() (used in definition of MD4)
H() (used in definition of MD5)
hand-rolled pickle
handle
handle, binding, annotating
Handle, for Privilege Attribute Data
handle, protected, obtain
handle, RPC binding
handle_t
hardware
hardware, basis of key security
hash
hash,
hash, CRC-32
header
header, authentication (data type)
header, authentication, omitted
header, authentication, processing
header, client sends authentication
header, of PDU
header, of pickle
header, privilege authentication (data type)
header, privilege RA (data type)
header, RA, client receives
header, reverse authentication (data type)
header, version number
headers
helpstring
helpstring, and common ACL manager
helpstring, common
helpstrings
hierarchy, of principals, groups and orgs
hierarchy, organisational
high-level ACL manipulation, not specified
high-order bit, use of, in permission
hint, in secidmap interface
home
home cell
home cell,
home directory
honouring a ticket, time constraints on
hop, in RS information
host
host address, communications, not security
host address, data type
host address, registered
host principal name
host-name, reserved account
host-name, reserved name
host-name, versus other machine name
hot list, in RS information
human understanding of security
human-friendly stringname, in PGO item
human-readable
I() (used in definition of MD5)
ID
ID map facility
ID map facility, bidirectional mapping
identifier, definitive
identifier, of RPC transfer syntax
identifying
identities
identity
identity, authorisation (data type)
identity, authorisation, by PS
identity, certainty of
identity, data type
identity, establishing
identity, in AS response
identity, in Kerberos protocol
identity-based policy
IDL, specifies pickles
IDL/NDR
idl_pkl_header_t,
ignorance of algorithm
illicit use of resources
immediate
impersonation
implementation
implementation requirement
implementation variability
implementation variability, in header processing
implementation, not constrained by pseudocode
import/export of DES
in
in_data
in_data, CL
indicator of position
indirect trust
indirect trust chain
infallibility, relative
infinite privilege
information
information, administration-level
information, registry (RS)
information, RS (data type)
inheritance
inheritance model
inheritance of ACLs
inheritance rules, and common ACL manager
inheritance, of login context
init process, login context
init, use of sec_login API
initial
initial ACL,
initial container ACL,
initial key
initial object ACL,
initial permutation
initial registration
initial ticket, issuing
initialisation vector, DES
initialisation vector, of CRC
initialise
initialise permission
initiator
input
Input/Output
insecure
insert permission
instance
instance, synonymous with server
integer
integer, mapping to bit-sequence
integer, mapping to byte-sequence
integer, mapping to mixed bit/byte-sequence
integers
integration
integration with time services
integrator
integrity
integrity,
integrity, built-in
integrity, CL
integrity, CO
integrity, protected by DES
integrity, protected by DES-MD4/5
intended
intentional request, of cross-cell referral ticket
inter-cell coordination
interaction
intercell
intercell_action
intercell_action, Algorithm
interchangeability, of CADA steps
interests of client
interface
interface UUID, ACLs
interface UUID, rs_acct
interface UUID, rs_attr
interface UUID, rs_attr_schema
interface UUID, rs_bind
interface UUID, rs_misc
interface UUID, rs_pgo
interface UUID, rs_policy
interface UUID, rs_prop_acct
interface UUID, rs_prop_acl
interface UUID, rs_prop_attr
interface UUID, rs_prop_attr_schema
interface UUID, rs_prop_pgo
interface UUID, rs_prop_plcy
interface UUID, rs_prop_replist
interface UUID, rs_pwd_mgmt
interface UUID, rs_qry
interface UUID, rs_repadm
interface UUID, rs_replist
interface UUID, rs_repmgr
interface UUID, rs_rpladmn
interface UUID, rs_unix
interface UUID, rs_update
interface UUID, scd
interface UUID, secidmap
interface, administrative
interface, RPC
Interface, rpriv
Interface, sec_id_epac_base
interfaces
intermediary
intermediate
intermediate cell in trust chain
Internet host name, versus host-name
Internet, DNS name type
Internet, registered address type
interpret, ticket
interval, data type
introduction, replication and propagation
introduction, security services
intuitive model
invalid, ticket flag
inverse initial permutation
invisible, password
IP
irreducible generator
is
ISO 8859-1
ISO, registered address type
issues
issuing cell TCB
issuing credential
issuing initial ticket
item
item,
item, policy
items
iteration
junction, namespace
KDC (RFC 1510)
KDS
KDS request, data type
KDS server, must be principal
KDS,
KDS, as registry client
KDS, at least one per cell
KDS, basis of name-based authorisation
KDS, counterfeit
KDS, error (data type)
KDS, error message
KDS, error processing
KDS, invoked only indirectly
KDS, knowledge of foreign servers
KDS, password irrelevant to
KDS, request body bgcolor="#FFFFFF" (data type)
KDS, request flag (data type)
KDS, response (data type)
KDS, response, encrypted part
KDS, server receives TGS request
KDS, TGS request/response processing
KDS, ticket obtained at login
KDS, two services
KDS, use of protected RPC
kds_request(), overview
kerberos
Kerberos,
Kerberos, and use of most recent key
Kerberos, maximum ticket lifetime
Kerberos, outline of protocol
Kerberos, registered service
Kerberos, unregisterable data
kerckhoffs
kerckhoffs´
Kerckhoffs', doctrine
key
key distribution service (KDS),
key distribution service,
key management facility,
key management, no special RPC interfaces
key schedule
key type
key version number, presence/absence of
key,
key, deletion of
key, DES
key, DES (data type)
key, distributed by KDS
key, distribution service
key, encryption (data type)
key, exactly one per account
key, frequency of changes
key, in AS response
key, in Kerberos protocol
key, in TGS response
key, limit on duration of validity
key, long-term
key, long-term, retrieval
key, long-term/short-term
key, lookup, in PGO item
key, management
key, mapping to password, registered
key, MD4 does not depend on
key, MD5 does not depend on
key, most recent
key, possibly-weak
key, query, type
key, safe lifetime
key, search attack
key, semi-weak
key, session
key, session/conversation
key, to be avoided
key, true session
key, type, in RS information
key, version number
key, weak
key-based
key_seq_num
keying information
keys
knowledge
knowledge of foreign KDS servers
knowledge,
krb5rpc
krb5rpc identity, element of cell-profile node
krb5rpc, metadata explicit in
krb5tgt, reserved account
krb5tgt, reserved name
krbtgt
KS
language, natural
LAS+TGS,
last
last request, data type
last request, in RS information
last request, in TGS response
last request, inspection
last request, registered
later, end of time timestamp
later, in comparing timestamps
laws
laws, composition
least privilege
least-significant byte (LSB),
left
left shift, in DES
left shift/rotate
legal ACL
length
length, of pickle
length, password
lifetime timestamp
lifetime, account
lifetime, in AS request
lifetime, in registry property
lifetime, of key in DES
lifetime, of ticket
lifetime, password
lifetime, renewable
lifetime, ticket
lifetime, ticket, in RS information
link, in trust chain
linking
links of chains
list
list of UUIDs
list, access control (ACL),
list, of pointers to ACL
lists
literature, current
little-endian,
local
local ACLE type
local authorisation, vs. foreign
local cell UUID,
local group, in groupset
local group, in PAC
local ID
local ID, account (data type)
local ID, lookup by
local key store, management of keys in
local password, data type
locate
lock,
locking, semantics not specified
logical security,
login
login context, non-interactive basis
Login Denial
Login Denial, Client Overview
Login Denial, Overview
Login Denial, Server Overview
login facility,
Login Functions, for delegation
login name, equals account name
login program,
login request protocol
login response protocol
login shell
login, availability of characters
login_set
long
long PGO name
long-term key
long-term key, in RS information
long-term key, one per account
long-term key, retrieval
longword,
lookup by local ID
lookup by UUID
lookup key, data type
lookup, result
lost, information in PTGS request
low-order bit, use of, in permission
LS
LSB,
lt;dce/acct.h>
lt;dce/aclbase.h>
lt;dce/binding.h>
lt;dce/keymgmt.h>
lt;dce/misc.h>
lt;dce/pgo.h>
lt;dce/policy.h>
lt;dce/rgynbase.h>
lt;dce/sec_login.h>
lt;dce/sec_rgy_attr.h>
lt;dce/sec_rgy_attr_sch.h>
lt;dce/secidmap.h>
machine name, versus host-name
machine principal name
management
management information permission
manager
manager, ACL,
managers
managing keys
mandatory policy
manipulated old ticket
map
map, endpoint
map, password to cryptographic key
mapping
mapping, password-to-key, registered
mappings
marshall, pickle
mask ACLE type
MASK_OBJ
MASK_OBJ, and sec_acl_calc_mask()
MASK_OBJ, at most one
MASK_OBJ, optional in common ACL manager
masking step in CADA
masking step in DADA
masquerade
master
master replica
master/slave RS server
matching
matching step in CADA
matching step in DADA
mathematical probability
matrix, access
max_invalid_attempts
maxClockSkew
maximum
maximum clock skew
maximum clock skew, in RS information
maximum ticket lifetime
MD4
MD4,
MD4, no raw interface
MD5
MD5,
MD5, no raw interface
MD5, usage to ensure integrity
mechanism
mechanism,
mechanisms
mediation, of trust link across cells
member of group,
membership permission
memorisation of password
memory, inability to allocate
message
Message Digest 5 (MD5),
message digest, produced by MD4
message digest, produced by MD5
message identity code (MIC),
message type, data type
message type, in KDS Error message
message,
message, KDS Error
message, notation
messages
metacharacter, escaping
metacharacter, in cell name
metacharacter, in transit path
metadata
metadata, pickle header
metadata, tickets and authenticators
metaticket,
MIC,
microsecond timestamp
microsecond timestamp, alternative implementation
microsecond, checked by KDS server
microsecond, in KDS Error message
microseconds
minimum
minimum implementation requirement
minimum number of octets
minimum_password_cycle_time
mirrored RS server
miscellaneous
misuse of resources
mix-in string
mixed
mixed bit/byte-sequence, mapping to integer
mode
mode, access
model
model of security,
model, extend to multi-cell case
model, extension of
model, federated naming
model, inheritance
model, programming, RPC
model, RPC binding
model, shape, trusted
models
models, academic
modes
modification, date/time
modular
modular arithmetic
monitor
monitor, reference
most recent key
most-significant byte (MSB),
MSB,
multi-cell TCB
Multi-Hop
multi-hop trust chain
multi-prong
multi-prong attack
multi-valued
multiple
multiple ACLs,
multiple UUIDs
mutual authentication
mutual authentication, checked by KDS server
mutual authentication, future work
mutual authentication, in TGS request
mutual authentication, of TGS service
mutual required
mutual trust
n-tuple
name permission
name, data type
name, full
name, global PGO
name, mapping by ID map facility
name, of account
name, of cell (data type
name, principal (data type)
name, reserved
name, RS (data type)
name-based
name-based authorisation
name-based group, not supported
named client
named client, in privilege ticket
names
namespace junction
namespace, separate
NAMETYPE
naming
naming domain
naming domain, data type
naming model, extension of
naming services, integration with security
naming syntax, CDS
natural language
NDR format label
NDR, encoding/marshalling of pickles
NDR, not used in pickle fields
needed
negation, boolean,
negotiation, in RS information
negotiation, of conversation key
network
network delay
network identity information, mapped at login
network login context
network TCB,
network, compromise
new ticket
newly issued ticket
next hop, in RS information
nibble, not used in this specification
no-op
no-op, protected
node, RPC cell profile
nominate client,
nominated client
non-alphabetic, required in password
non-cryptographic checksum
non-empty, header and body bgcolor="#FFFFFF" of pickle
non-interactive subject, and key management facility
Non-Intermediary
non-invertible digest
non-linearity of DES
nonce, as challenge
nonce, checking
nonce, data type
nonce, in AS request
nonce, in TGS request
nonce, in TGS response
nonce, initialisation
nonces
none, reserved group name
none, reserved organisation name
normal form, bytes of DES key
not,
notation
notation,
notation, for CBC encryption/decryption
notation, for decryption
notation, for encryption
notes
number
number, random (data type)
number, sequence (data type)
numbers
numerical rotation
numerical rotation,
O-name
object
object ACL,
object,
object, control of access to
object, group
object, identity of
object, organisation
object, principal
object, protected
object, underlying
object, uniqueness of identification
objective criterion of belief
objects
obscurity
obtaining
odd parity
old ticket, manipulated
one-way authentication in sec_acl
opaque pointer, login context as
opaque RPC transport
opaque, cell name
open
operating system
operating system, basis of key security
operation, on bit-sequences
operations
opinion
optimisation
option
optional
OR,
order of reporting errors
ordering
org-name
organisation domain
organisation, ACL manager permission
organisation, ACL manager type
organisation, ACL manager type UUID
organisation, identity (data type)
organisation, in account item
organisation, policy information
organisation, separate namespace
organisation, supported ACLE types
organization-ID
organization-name
original RPC
origination
OTHER_OBJ
OTHER_OBJ, algorithm
OTHER_OBJ, at most one
OTHER_OBJ, supported by common ACL manager
OTHER_OBJ_DEL
OTHER_OBJ_DEL, algorithm
OTHER_OBJ_DELEG
out of band
out_data
out_data, in CL security
outline
outline of specification
outline, of Kerberos protocol
output
overlap, of security domains
overview
owner, can control object's ACL
owning group
owning user
p
P-name
PA header, received by server
PA, client sends header
PAC
PAC attribute, in RS information
PAC format, data type
PAC, (Set of) Extended (EPACs)
PAC, contained in privilege ticket
PAC, data type
PAC, empty
PAC, Extended (EPAC)
PAC, pickled
PAC-based
PAC-based authorisation
PAC-based PS
PACs
padata
padding
padding bits
pair of UUIDs
parameters
parent object,
parity, odd in DES key
part
part of KDS response
part of message, notation
part of RA header to be encrypted
part of ticket to be encrypted
partial block, encryption of
partial qualification
partitioned RPC
partitioned, RPC service
partitioning, of network TCB
passive aspect
passive bits of DES vector
passive bits, destroying
Passsword Strength
passwd_override
password
Password Expiration
Password Management
Password Management,
Password Management, Overview
password, and key search attack
password, basis of long-term key
password, change
password, changing
password, data type
password, expiration
password, level of confidence in
password, lifetime
password, minimum length
password, not to be sent remotely
password, policy restriction
password, requested at login
password, valid
password, version number
password-changing program
Password-to-Key
password-to-key mapping, registered
password_generation
passwords
passwords_per_cycle
path
path, transit
paths
PC1
PC1, PC2
PC2
PCS
PCS, in printstring
PDU
PDU, verifier and body bgcolor="#FFFFFF"
pepper
per-cell PGO UUID
per-end-principal, in RS information
per-foreign-KDS, in RS information
performance
permission
permission set
permission, and common ACL manager
permission, bit position
permission, common
permission, display format
permission, exceeding maximum number
permission, in ACLE
permission, list
permission, maximum number
permission, semantics unspecified
permissions
permissions, not supported in name-based
permutation
permutation mapping
permuted
permuted choices
PGO
PGO item, attribute (data type)
PGO item, data type
PGO item, definitive identifier
PGO name, mapping into components
PGO name, short and long
PGO UUID
PGO, global name
PGO, protected with ACLs
pgo-ID
PGO-name,
physical security
pickle
pickle,
pickle, data type
pickle, in extended ACLE
pickle, type (data type)
pickled
pickled PAC
pickled PAC, in privilege-ticket
pickles
piggy-back
pkl_length_hi
pkl_length_low
pkl_syntax
pkl_type
pkl_version
plaintext
plaintext, operated on by DES
plaintext, pre-encrypted
pointer, opaque, login context as
pointer, to ACL
policies
policy
policy attribute
policy item
policy item,
policy,
policy, ACL manager permission
policy, ACL manager type
policy, ACL manager type UUID
policy, authentication
policy, examples
policy, in policy item
policy, in registry property
policy, of organisation
policy, organisation
policy, protected with ACLs
policy, restriction on password
policy, supported ACLE types
polymorphic, no registry item is
polymorphism
polynomial, definition of CRC
poor cryptographic characteristic
port 88
portability, seat
portable character set
portable character set, in printstring
posited trust
position indicator
POSIX, and MASK_OBJ
POSIX, draft rule for common ACL
POSIX, extent of semantics
POSIX, group
POSIX, home directory
POSIX, login shell
POSIX, owner
possibly
possibly-weak keys,
postdatable, in AS response
postdatable, in RS information
postdatable, in TGS request
postdatable, initialisation
postdatable, KDS request flag
postdatable, ticket flag
power, of polynomial defining CRC
Pre-Aauthentication
Pre-Authentication
pre-authentication data
Pre-Authentication, Overview
Pre-authentication, protocol
pre-encrypted plaintext
pre-installation
pre_auth_req
preface
prefixed name type
primary group, in account item
principal
principal domain
principal domain, and aliases
principal name, data type
principal name, not a parameter in sec_acl
principal stringname, conceptual part of login context
principal UUID,
principal, ACL manager permission
principal, ACL manager type
principal, ACL manager type UUID
principal, cell,
principal, equal vs. distinct across cells
principal, identity (data type)
Principal, input to CADA
principal, KDS server must be
principal, separate namespace
principal, supported ACLE types
principal-ID
principal-name
printable stringname (data type
printstring
printstring, and common ACL manager
printstring, common
printstring, data type
printstring, permission
printstrings
priori
privacy
privilege
privilege attribute
privilege attribute certificate (PAC),
privilege attribute certificate, data type
privilege authentication header, client sends
privilege authentication header, data type
privilege authentication/RA header
privilege RA header, data type
privilege service (PS),
privilege service,
privilege service, PAC-based
privilege ticket
privilege ticket granting service
privilege ticket, not used in name-based authorisation
privilege ticket, use in PS
privilege, infinite
privilege, service
privilege-ticket,
privilege-ticket, data type
privilege-ticket-granting-ticket
Privilege-Tickets
probability
process, context at start-up
process, no correspondence with login context
processing
processing, AS request/response
processing, header/RA header
processing, privilege authentication/RA header
processing, TGS request/response
product
profile
programming
programming model
prompt, login
propagation
proper use of resources
properties
property, chaining
property, in policy item
property, of RS server (data type)
protected
protected communication, start of
protected handle, obtain
protected object
protected password
protected password, data type
protected RPC,
protecting security attribute
protection ACL,
protection of ticket
protection, of AS response
protection_level
protocol
protocol data unit
protocol message type, data type
protocol message type, registered
protocol tower
protocol version number, data type
protocol version number, registered
protocol, Kerberos
protocol, RPC (list)
protocol, trusted
protocols
provability
proxiable, in AS response
proxiable, in RS information
proxiable, in TGS request
proxiable, initialisation
proxiable, KDS request flag
proxiable, ticket flag
proximity and trust
proxy, combined with forward
PS
PS error, no special data type
PS request
PS response
PS,
PS, as registry client
PS, at least one per cell
PS, error processing
PS, no direct API
PS, not visited in name-based authorisation
PS, use of protected RPC
ps_app_tkt_result_t
ps_attr_request_t
ps_attr_result_t
ps_message_t
ps_request_become_delegate
ps_request_become_delegate(), overview
ps_request_become_impersonator
ps_request_become_impersonator(), overview
ps_request_eptgt
ps_request_eptgt(), overview
ps_request_ptgt
ps_request_ptgt(), overview
pseudocode
PTGS
PTGS request, client sends
PTGS request, data type
PTGS request, lost information
PTGS request, PS server receives
PTGS response, client receives
PTGS response, data type
PTGS service
PTGS, request/response processing
PTGT
public-key certificate
publications
pwd_mgmt_binding
pwd_val_type
Q[]
quadratic vector Q[]
quadword,
qualification, partial
quality, of nonce generator
quality, of random number generator
query
query key, data type
query key, type
Query Triggers
query, result
queue
quota
quota,
RA header processing
RA header, client receives
RA header, sent by server
RA, header, client receives
random
random number, data type
rationale, for extended ACLE
raw UDP
rdacl
rdacl,
rdacl, enumeration of functions
rdacl_get_*(), basis of sec_acl_get_*()
rdacl_get_access
rdacl_get_access(), overview
rdacl_get_manager_types
rdacl_get_manager_types(), overview
rdacl_get_mgr_types_semantics
rdacl_get_mgr_types_semantics(), overview
rdacl_get_printstring
rdacl_get_printstring(), overview
rdacl_get_referral
rdacl_get_referral(), overview
rdacl_lookup
rdacl_lookup(), and EXTENDED ACLE type
rdacl_lookup(), overview
rdacl_place_holder_1
rdacl_place_holder_1(), overview
rdacl_replace
rdacl_replace(), may modify RS data
rdacl_replace(), overview
rdacl_replace(), replacing old ACL
rdacl_test_access
rdacl_test_access(), overview
rdacl_test_access_on_behalf(), overview
read permission
read, protection against
read-only, RS site
readable server
realm
realm name,
realm,
realm, usage in RFC 1510
receives
receiving
reduction
redundancy
redundant UUIDs
reference
reference monitor
reference monitor, RS
referenced
referent, of ACLE
referent, of UUID
referral ticket
regarding
registered
registered authentication data type
registered authentication service
registered authorisation data type
registered authorisation service
registered cell name syntax
registered checksum type
registered CRC
registered encryption key type
registered encryption type
registered error status code
registered host address type
registered last request
registered password-to-key mapping
registered protocol message type
registered protocol version number
registered RS name
registered transit path type
registration
registration service,
registration, cross-
registration, cross-cell
registration, of RS
registry
Registry Attributes
registry editor
registry information
registry name, data type
registry policy, conceptual part of login context
registry property
registry,
registry, ACL manager types supported
registry, editor
rejection, of PAC without authentication
relative infallibility
relatively well-formed ACL,
reliability
remainder
remote
Remote Interfaces, Delegation
renew, in TGS request
renewable lifetime
renewable, in AS response
renewable, in RS information
renewable, in TGS request
renewable, initialisation
renewable, KDS request flag
replay
replay attack
replay attack, detecting via nonce
replay cache, in RS information
replay cache, server checks timestamp against
replica
replica overview
replica state, data type
replica, synonymous with server
replicas
replication
replication model, protocol is future work
replication, of network TCB
replication, of RS service
replist, ACL manager permission
replist, ACL manager type UUID
replist, supported ACLE types
representations
repudiation
request
request processing, TGS
request, AS
request, AS, receipt of
request, KDS
request, processing by AS
request, PTGS (data type)
request, PTGS processing
request, PTGS, received
request, service
request, TGS
request, TGS, receipt of
Request/Response
requestor
requests
required
required item
requirements
reserved name
resolution-with-residual support
resource, proper/improper use
response
response processing, TGS
response, AS
response, AS, received by client
response, AS, sending of
response, processing by AS
response, PTGS (data type)
response, PTGS processing
response, PTGS,
response, PTGS, received
response, service
response, TGS
response, TGS, construction of
response, TGS, receiving
response, TGS, sending
responses
responsibility, of server
restriction
restrictions, data type
Restrictions, Delegate
Restrictions, Optional
Restrictions, Required
Restrictions, Target
reverse authentication, client receives header
reverse authentication, header (data type)
reverse authentication, header omitted
reverse authentication, header processing
reverse authentication, server sends header
reverse authenticator
REVERSE transformation
Reverse-)Authentication
Reverse-Authentication
revocation, in RS information
revoke, implicit when key is deleted
revoke, ticket
RFC 1320
RFC 1321
RFC 1510
RFC 1510, expire time
RFC 1510, in CL security
rights
rights, implementation variability
rigour
ritual, login
root, global
rotation
rotation,
rotations
rounds
routines
RPC
RPC binding handle
RPC interface
RPC PDU
RPC server
RPC, binding model
RPC, integration with security
RPC, profile node
RPC, protected,
RPC, transfer syntax, in pickle
RPC, used by all security servers
rpc_biding_set_auth_info(), in login facility
rpc_binding_inq_auth_caller(), overview
rpc_binding_inq_auth_client(), overview
rpc_binding_inq_auth_info(), overview
rpc_binding_set_auth_info()
rpc_binding_set_auth_info(), overview
rpc_c_authz_name
rpc_c_protect_level constants
rpc_mgmt_inq_server_princ_name(), overview
rpc_mgmt_set_authorization_fcn(), overview
rpc_ns_binding_import_*(), binding to security
rpc_ns_entry_inq_resolution(), with residual operation
rpc_server_register_auth_info(), overview
rpc_syntax_id_t,
rpriv
rpriv identity, element of cell-profile node
rpriv, metadata explicit in
RS
RS binding
RS datastore, data type
RS datastore, lookup by local ID
RS datastore, lookup by UUID
RS datastore, management of keys in
RS datastore, query (lookup) key
RS datastore, quota
RS datastore, user-level information
RS editor
RS editor RPC interface, future work
RS information
RS name, data type
RS name, registered
RS namespace, data type
RS server, properties (data type)
RS,
RS, ACL manager types supported
RS, as reference monitor
RS, at least one per cell
RS, information (data type)
RS, must be registered
RS, policy attribute
rs_acct
rs_acct RPC interface
rs_acct_add
rs_acct_add(), limited by quota
rs_acct_add(), may modify RS data
rs_acct_add(), overview
rs_acct_add(), use of rs_acct_key_transmit_t
rs_acct_delete
rs_acct_delete(), may modify RS data
rs_acct_delete(), overview
rs_acct_get_projlist
rs_acct_get_projlist(), overview
rs_acct_get_projlist(), part of rs_login_get_info()
rs_acct_info_t
rs_acct_key_transmit_t
rs_acct_key_transmit_t, data type
rs_acct_lookup
rs_acct_lookup(), honours sec_rgy_prop_shadow_password
rs_acct_lookup(), overview
rs_acct_lookup(), part of rs_login_get_info()
rs_acct_parts_t
rs_acct_parts_t, data type
rs_acct_rename
rs_acct_rename(), may modify RS data
rs_acct_rename(), overview
rs_acct_replace
rs_acct_replace(), may modify RS data
rs_acct_replace(), overview
rs_acct_replace(), use of rs_acct_key_transmit_t
rs_attr
rs_attr RPC interface
rs_attr_cursor_init
rs_attr_cursor_init(), overview
rs_attr_cursor_t
rs_attr_cursor_t, data type
rs_attr_delete
rs_attr_delete(), overview
rs_attr_get_effective
rs_attr_get_effective(), overview
rs_attr_get_referral
rs_attr_get_referral(), overview
rs_attr_lookup_by_id
rs_attr_lookup_by_id(), overview
rs_attr_lookup_by_name
rs_attr_lookup_by_name(), overview
rs_attr_lookup_no_expand
rs_attr_lookup_no_expand(), overview
rs_attr_schema
rs_attr_schema RPC interface
rs_attr_schema_aclmgr_strings
rs_attr_schema_aclmgr_strings(), overview
rs_attr_schema_create_entry
rs_attr_schema_create_entry(), overview
rs_attr_schema_cursor_init
rs_attr_schema_cursor_init(), overview
rs_attr_schema_delete_entry
rs_attr_schema_delete_entry(), overview
rs_attr_schema_get_acl_mgrs
rs_attr_schema_get_acl_mgrs(), overview
rs_attr_schema_get_referral
rs_attr_schema_get_referral(), overview
rs_attr_schema_lookup_by_id
rs_attr_schema_lookup_by_id(), overview
rs_attr_schema_lookup_by_name
rs_attr_schema_lookup_by_name(), overview
rs_attr_schema_scan
rs_attr_schema_scan(), overview
rs_attr_schema_update_entry
rs_attr_schema_update_entry(), overview
rs_attr_test_and_update
rs_attr_test_and_update(), overview
rs_attr_update
rs_attr_update(), overview
rs_auth_policy_get_effective
rs_auth_policy_get_effective(), overview
rs_auth_policy_get_info
rs_auth_policy_get_info(), overview
rs_auth_policy_set_info
rs_auth_policy_set_info(), may modify RS data
rs_auth_policy_set_info(), overview
rs_bind
rs_bind identity, element of cell-profile node
rs_bind interface
rs_bind RPC interface
rs_bind_get_update_site
rs_bind_get_update_site(), overview
rs_cache_data_t
rs_cache_data_t, data type
rs_check_consistency
rs_check_consistency(), overview
rs_encrypted_pickle_t
rs_encrypted_pickle_t, data type
rs_login_get_info
rs_login_get_info(), honours sec_rgy_prop_shadow_password
rs_login_get_info(), overview
rs_login_info_t
rs_login_info_t, data type
rs_misc
rs_misc interface
rs_misc RPC interface
rs_ns_entry_validate
rs_pgo
rs_pgo RPC interface
rs_pgo_add
rs_pgo_add(), limited by quota
rs_pgo_add(), may modify RS data
rs_pgo_add(), overview
rs_pgo_add_member
rs_pgo_add_member(), may modify RS data
rs_pgo_add_member(), overview
rs_pgo_delete
rs_pgo_delete(), may modify RS data
rs_pgo_delete(), overview
rs_pgo_delete_member
rs_pgo_delete_member(), may modify RS data
rs_pgo_delete_member(), overview
rs_pgo_get
rs_pgo_get(), overview
rs_pgo_get_members
rs_pgo_get_members(), overview
rs_pgo_id_key_t
rs_pgo_id_key_t, data type
rs_pgo_is_member
rs_pgo_is_member(), overview
rs_pgo_key_transfer
rs_pgo_key_transfer(), overview
rs_pgo_query_key_t
rs_pgo_query_key_t, data type
rs_pgo_query_result_t
rs_pgo_query_result_t, data type
rs_pgo_query_t
rs_pgo_query_t, data type
rs_pgo_rename
rs_pgo_rename(), may modify RS data
rs_pgo_rename(), overview
rs_pgo_replace
rs_pgo_replace(), may modify RS data
rs_pgo_replace(), overview
rs_pgo_result_t
rs_pgo_result_t, data type
rs_pgo_unix_num_key_t
rs_pgo_unix_num_key_t, data type
rs_policy
rs_policy RPC interface
rs_policy_get_effective
rs_policy_get_effective(), overview
rs_policy_get_info
rs_policy_get_info(), overview
rs_policy_get_info(), part of rs_login_get_info()
rs_policy_set_info
rs_policy_set_info(), may modify RS data
rs_policy_set_info(), overview
rs_prop_acct
rs_prop_acct RPC interface
rs_prop_acct_add
rs_prop_acct_add(), overview
rs_prop_acct_add_data_t
rs_prop_acct_add_data_t, data type
rs_prop_acct_add_key_version
rs_prop_acct_add_key_version(), overview
rs_prop_acct_delete
rs_prop_acct_delete(), overview
rs_prop_acct_key_data_t
rs_prop_acct_key_data_t, data type
rs_prop_acct_rename
rs_prop_acct_rename(), overview
rs_prop_acct_replace
rs_prop_acct_replace(), overview
rs_prop_acl
rs_prop_acl RPC interface
rs_prop_acl_data_t
rs_prop_acl_data_t, data type
rs_prop_acl_replace
rs_prop_acl_replace(), overview
rs_prop_attr
rs_prop_attr RPC interface
rs_prop_attr_data_t
rs_prop_attr_data_t, data type
rs_prop_attr_delete
rs_prop_attr_delete(), overview
rs_prop_attr_list_t
rs_prop_attr_list_t, data type
rs_prop_attr_sch_create_data_t
rs_prop_attr_sch_create_data_t, data type
rs_prop_attr_schema
rs_prop_attr_schema RPC interface
rs_prop_attr_schema_create
rs_prop_attr_schema_create(), overview
rs_prop_attr_schema_delete
rs_prop_attr_schema_delete(), overview
rs_prop_attr_schema_update
rs_prop_attr_schema_update(), overview
rs_prop_attr_update
rs_prop_attr_update(), overview
rs_prop_auth_plcy_set_info
rs_prop_auth_plcy_set_info(), overview
rs_prop_pgo
rs_prop_pgo RPC interface
rs_prop_pgo_add
rs_prop_pgo_add(), overview
rs_prop_pgo_add_data_t
rs_prop_pgo_add_data_t, data type
rs_prop_pgo_add_member
rs_prop_pgo_add_member(), overview
rs_prop_pgo_delete
rs_prop_pgo_delete(), overview
rs_prop_pgo_delete_member
rs_prop_pgo_delete_member(), overview
rs_prop_pgo_rename
rs_prop_pgo_rename(), overview
rs_prop_pgo_replace
rs_prop_pgo_replace(), overview
rs_prop_plcy
rs_prop_plcy RPC interface
rs_prop_plcy_set_dom_cache_info
rs_prop_plcy_set_dom_cache_info(), overview
rs_prop_plcy_set_info
rs_prop_plcy_set_info(), overview
rs_prop_properties_set_info
rs_prop_properties_set_info(), overview
rs_prop_replist
rs_prop_replist RPC interface
rs_prop_replist_add_replica
rs_prop_replist_add_replica(), overview
rs_prop_replist_del_replica
rs_prop_replist_del_replica(), overview
rs_properties_get_info
rs_properties_get_info(), overview
rs_properties_get_info(), part of rs_login_get_info()
rs_properties_set_info
rs_properties_set_info(), may modify RS data
rs_properties_set_info(), overview
rs_pwd_mgmt
rs_pwd_mgmt RPC interface
rs_pwd_mgmt_plcy_t
rs_pwd_mgmt_plcy_t, data type
rs_pwd_mgmt_setup
rs_pwd_mgmt_setup(), overview
rs_qry
rs_qry RPC interface
rs_query_are_you_there
rs_query_are_you_there(), overview
rs_rep_admin_become_master
rs_rep_admin_become_master(), overview
rs_rep_admin_become_slave
rs_rep_admin_become_slave(), overview
rs_rep_admin_change_master
rs_rep_admin_change_master(), overview
rs_rep_admin_destroy
rs_rep_admin_destroy(), overview
rs_rep_admin_info
rs_rep_admin_info(), overview
rs_rep_admin_info_full
rs_rep_admin_info_full(), overview
rs_rep_admin_init_replica
rs_rep_admin_init_replica(), overview
rs_rep_admin_maint
rs_rep_admin_maint(), overview
rs_rep_admin_mkey
rs_rep_admin_mkey(), overview
rs_rep_admin_stop
rs_rep_admin_stop(), overview
rs_rep_mgr_become_master
rs_rep_mgr_become_master(), overview
rs_rep_mgr_copy_all
rs_rep_mgr_copy_all(), overview
rs_rep_mgr_copy_propq
rs_rep_mgr_copy_propq(), overview
rs_rep_mgr_get_info_and_creds
rs_rep_mgr_get_info_and_creds(), overview
rs_rep_mgr_i_am_master
rs_rep_mgr_i_am_master(), overview
rs_rep_mgr_i_am_slave
rs_rep_mgr_i_am_slave(), overview
rs_rep_mgr_init
rs_rep_mgr_init(), overview
rs_rep_mgr_init_done
rs_rep_mgr_init_done(), overview
rs_rep_mgr_stop_until_compat_sw
rs_rep_mgr_stop_until_compat_sw(), overview
rs_repadm
rs_repadm RPC interface
rs_replica_auth_p_t
rs_replica_auth_p_t, data type
rs_replica_auth_t
rs_replica_auth_t, data type
rs_replica_comm_info_t
rs_replica_comm_info_t, data type
rs_replica_comm_t
rs_replica_comm_t, data type
rs_replica_info_t
rs_replica_info_t, data type
rs_replica_item_full_t
rs_replica_item_full_t, data type
rs_replica_item_p_t
rs_replica_item_p_t, data type
rs_replica_item_t
rs_replica_item_t, data type
rs_replica_master_info_p_t
rs_replica_master_info_p_t, data type
rs_replica_master_info_t
rs_replica_master_info_t, data type
rs_replica_name_p_t
rs_replica_name_p_t, data type
rs_replica_prop_info_t
rs_replica_prop_info_t, data type
rs_replica_prop_t
rs_replica_prop_t, data type
rs_replica_twr_vec_p_t
rs_replica_twr_vec_p_t, data type
rs_replist
rs_replist RPC interface
rs_replist_add_replica
rs_replist_add_replica(), overview
rs_replist_delete_replica
rs_replist_delete_replica(), overview
rs_replist_read
rs_replist_read(), overview
rs_replist_read_full
rs_replist_read_full(), overview
rs_replist_replace_replica
rs_replist_replace_replica(), overview
rs_repmgr
rs_repmgr RPC interface
rs_rpladmn
rs_rpladmn RPC interface
rs_sw_version_t
rs_sw_version_t, data type
rs_unix
rs_unix RPC interface
rs_unix_getmemberents
rs_unix_getmemberents(), overview
rs_unix_getpwents
rs_unix_getpwents(), overview
rs_unix_query_key_t
rs_unix_query_key_t, data type
rs_unix_query_t
rs_unix_query_t, data type
rs_update
rs_update RPC interface
rs_update_seqno_t
rs_update_seqno_t, data type
rs_wait_until_consistent
rs_wait_until_consistent(), overview
rsec_id_gen_name
rsec_id_gen_name(), overview
rsec_id_gen_name_cache
rsec_id_gen_name_cache(), overview
rsec_id_output_selector_t
rsec_id_output_selector_t, data type
rsec_id_parse_name
rsec_id_parse_name(), overview
rsec_id_parse_name_cache
rsec_id_parse_name_cache(), overview
rule-based policy
rules for inheritance of ACLs,
s
S-boxes
salt
salt, in RS information
salt, zero-length
same cell, PTGS processing
sample
SCD
scd RPC interface
scd_protected_noop
scd_protected_noop(), overview
scenario
schedule
schema
Schemas, Well-known Attributes
scientific notation, in example
scope
scramble
seal
Seal, List of
seals
seat portability
sec-junction
sec-rgy_handle_t
sec_acl
sec_acl, enumeration of functions
sec_acl, one-way authentication
sec_acl_bind
sec_acl_bind(), overview
sec_acl_bind_to_addr
sec_acl_bind_to_addr(), overview
sec_acl_calc_mask
sec_acl_calc_mask(), and POSIX
sec_acl_calc_mask(), overview
sec_acl_component_name_t
sec_acl_component_name_t,
sec_acl_entry_t,
sec_acl_entry_type_t,
sec_acl_get_access
sec_acl_get_access(), overview
sec_acl_get_error_info
sec_acl_get_error_info(), overview
sec_acl_get_manager_types
sec_acl_get_manager_types(), overview
sec_acl_get_mgr_types_semantics
sec_acl_get_mgr_types_semantics(), overview
sec_acl_get_printstring
sec_acl_get_printstring(), overview
sec_acl_list_t
sec_acl_list_t,
sec_acl_lookup
sec_acl_lookup(), overview
sec_acl_p_t
sec_acl_p_t,
sec_acl_perm_ bits,
sec_acl_permset_t,
sec_acl_posix_semantics_t
sec_acl_posix_semantics_t,
sec_acl_printstring_t,
sec_acl_release
sec_acl_release(), overview
sec_acl_release_handle
sec_acl_release_handle(), overview
sec_acl_replace
sec_acl_replace(), overview
sec_acl_result_t
sec_acl_result_t,
sec_acl_t,
sec_acl_test_access
sec_acl_test_access(), overview
sec_acl_test_access_on_behalf
sec_acl_test_access_on_behalf(), overview
sec_acl_tower_set_t
sec_acl_tower_set_t,
sec_acl_twr_ref_t
sec_acl_twr_ref_t,
sec_acl_type_t,
sec_attr_acl_mgr_info_p_t, data type
sec_attr_acl_mgr_info_set_t
sec_attr_acl_mgr_info_set_t, data type
sec_attr_acl_mgr_info_t
sec_attr_acl_mgr_info_t, data type
sec_attr_bind_auth_info_t
sec_attr_bind_auth_info_t, data type
sec_attr_bind_auth_info_type_t
sec_attr_bind_auth_info_type_t, data type
sec_attr_bind_info_t
sec_attr_bind_info_t, data type
sec_attr_bind_svrname
sec_attr_bind_svrname, data type
sec_attr_bind_type_t
sec_attr_bind_type_t, data type
sec_attr_binding_t
sec_attr_binding_t, data type
sec_attr_component_name_t
sec_attr_component_name_t, data type
sec_attr_enc_attr_set_t
sec_attr_enc_attr_set_t, data type
sec_attr_enc_bytes_t
sec_attr_enc_bytes_t, data type
sec_attr_enc_printstring_p_t
sec_attr_enc_printstring_p_t, data type
sec_attr_enc_str_array_t
sec_attr_enc_str_array_t, data type
sec_attr_encoding_t
sec_attr_encoding_t, data type
sec_attr_i18n_data_t
sec_attr_i18n_data_t, data type
sec_attr_intercell_action_t
sec_attr_intercell_action_t, data type
sec_attr_sch_entry_flags_t
sec_attr_sch_entry_flags_t, data type
sec_attr_schema_entry_parts_t
sec_attr_schema_entry_parts_t, data type
sec_attr_schema_entry_t
sec_attr_schema_entry_t, data type
sec_attr_t
sec_attr_t, data type
sec_attr_trig_type_flags_t
sec_attr_trig_type_flags_t, data type
sec_attr_twr_ref_t
sec_attr_twr_ref_t, data type
sec_attr_twr_set_p_t, data type
sec_attr_twr_set_t
sec_attr_twr_set_t, data type
sec_attr_value_t
sec_attr_value_t, data type
sec_attr_vec_t
sec_attr_vec_t, data type
sec_bytes_t
sec_bytes_t, data type
sec_chksum_t
sec_chksum_t, data type
sec_chksum_type_t
sec_chksum_type_t, data type
sec_cred
sec_cred_free_attr_cursor
sec_cred_free_cursor
sec_cred_free_pa_handle
sec_cred_get_authz_session_info
sec_cred_get_client_princ_name
sec_cred_get_deleg_restrictions
sec_cred_get_delegate
sec_cred_get_delegation_type
sec_cred_get_extended_attrs
sec_cred_get_initiator
sec_cred_get_opt_restrictions
sec_cred_get_pa_data
sec_cred_get_req_restrictions
sec_cred_get_tgt_restrictions
sec_cred_get_v1_pac
sec_cred_initialize_attr_cursor
sec_cred_initialize_cursor
sec_cred_is_authenticated
sec_encrypted_bytes_t
sec_encrypted_bytes_t, data type
sec_etype_t
sec_etype_t, data type
sec_id API
sec_id_gen_group
sec_id_gen_group(), overview
sec_id_gen_name
sec_id_gen_name(), overview
sec_id_parse_group
sec_id_parse_group(), overview
sec_id_parse_name
sec_id_parse_name(), overview
sec_key_mgmt API
sec_key_mgmt_change_key
sec_key_mgmt_change_key(), overview
sec_key_mgmt_delete_key
sec_key_mgmt_delete_key(), overview
sec_key_mgmt_delete_key_type
sec_key_mgmt_delete_key_type(), overview
sec_key_mgmt_free_key
sec_key_mgmt_free_key(), overview
sec_key_mgmt_garbage_collect
sec_key_mgmt_garbage_collect(), overview
sec_key_mgmt_gen_rand_key
sec_key_mgmt_gen_rand_key(), overview
sec_key_mgmt_get_key
sec_key_mgmt_get_key(), overview
sec_key_mgmt_get_next_key
sec_key_mgmt_get_next_key(), overview
sec_key_mgmt_get_next_kvno
sec_key_mgmt_get_next_kvno(), overview
sec_key_mgmt_initialize_cursor
sec_key_mgmt_initialize_cursor(), overview
sec_key_mgmt_manage_key
sec_key_mgmt_manage_key(), overview
sec_key_mgmt_release_cursor
sec_key_mgmt_release_cursor(), overview
sec_key_mgmt_set_key
sec_key_mgmt_set_key(), overview
sec_key_version_t
sec_key_version_t, data type
sec_login API
sec_login API, used during login
sec_login Extensions
sec_login_become_delegate
sec_login_become_delegate(), overview
sec_login_become_impersonator
sec_login_become_impersonator(), overview
sec_login_become_initiator
sec_login_become_initiator(), overview
sec_login_certify_identity
sec_login_certify_identity(), and process privilege
sec_login_certify_identity(), overview
sec_login_cred_get_delegate
sec_login_cred_get_delegate(), overview
sec_login_cred_get_initiator
sec_login_cred_get_initiator(), overview
sec_login_cred_init_cursor
sec_login_cred_init_cursor(), overview
sec_login_disable_delegation
sec_login_disable_delegation(), overview
sec_login_export_context
sec_login_export_context(), overview
sec_login_free_net_info
sec_login_free_net_info(), overview
sec_login_get_current_context
sec_login_get_current_context(), overview
sec_login_get_expiration
sec_login_get_expiration(), overview
sec_login_get_groups
sec_login_get_groups(), overview
sec_login_get_pwent
sec_login_get_pwent(), overview
sec_login_import_context
sec_login_import_context(), overview
sec_login_init_first
sec_login_init_first(), overview
sec_login_inquire_net_info
sec_login_inquire_net_info(), overview
sec_login_newgroups
sec_login_newgroups(), overview
sec_login_purge_context
sec_login_purge_context(), overview
sec_login_purge_context_exp
sec_login_purge_context_exp(), overview
sec_login_refresh_identity
sec_login_refresh_identity(), overview
sec_login_release_context
sec_login_release_context(), overview
sec_login_set_context
sec_login_set_context(), overview
sec_login_set_extended_attrs
sec_login_set_extended_attrs(), overview
sec_login_setup_first
sec_login_setup_first(), overview
sec_login_setup_identity
sec_login_setup_identity(), overview
sec_login_tkt_request_options
sec_login_tkt_request_options(), overview
sec_login_valid_and_cert_ident
sec_login_valid_and_cert_ident(), overview
sec_login_valid_and_cert_ident(), reason for being privileged
sec_login_validate_first
sec_login_validate_first(), overview
sec_login_validate_identity
sec_login_validate_identity(), overview
sec_passwd_des_key_t
sec_passwd_des_key_t, data type
sec_passwd_rec_t
sec_passwd_rec_t, data type
sec_passwd_type_t
sec_passwd_type_t, data type
sec_passwd_version_t
sec_passwd_version_t, data type
sec_rgy_acct_add
sec_rgy_acct_admin_flags_t
sec_rgy_acct_admin_flags_t, data type
sec_rgy_acct_admin_replace
sec_rgy_acct_admin_t
sec_rgy_acct_admin_t, data type
sec_rgy_acct_auth_flags_t
sec_rgy_acct_auth_flags_t, data type
sec_rgy_acct_delete
sec_rgy_acct_get_projlist
sec_rgy_acct_key_t
sec_rgy_acct_key_t, data type
sec_rgy_acct_lookup
sec_rgy_acct_passwd
sec_rgy_acct_rename
sec_rgy_acct_replace_all
sec_rgy_acct_user_flags_t
sec_rgy_acct_user_flags_t, data type
sec_rgy_acct_user_replace
sec_rgy_acct_user_t
sec_rgy_acct_user_t, data type
sec_rgy_attr_cursor_alloc
sec_rgy_attr_cursor_init
sec_rgy_attr_cursor_release
sec_rgy_attr_cursor_reset
sec_rgy_attr_delete
sec_rgy_attr_get_effective
sec_rgy_attr_lookup_by_id
sec_rgy_attr_lookup_by_name
sec_rgy_attr_lookup_no_expand
sec_rgy_attr_sch_aclmgr_strings
sec_rgy_attr_sch_create_entry
sec_rgy_attr_sch_cursor_alloc
sec_rgy_attr_sch_cursor_init
sec_rgy_attr_sch_cursor_release
sec_rgy_attr_sch_cursor_reset
sec_rgy_attr_sch_delete_entry
sec_rgy_attr_sch_get_acl_mgrs
sec_rgy_attr_sch_lookup_by_id
sec_rgy_attr_sch_lookup_by_name
sec_rgy_attr_sch_scan
sec_rgy_attr_sch_update_entry
sec_rgy_attr_test_and_update
sec_rgy_attr_update
sec_rgy_auth_plcy_get_effective
sec_rgy_auth_plcy_get_info
sec_rgy_auth_plcy_set_info
sec_rgy_bind
sec_rgy_bind interface
sec_rgy_cell_bind
sec_rgy_cell_bind(), overview
sec_rgy_cursor_reset
sec_rgy_cursor_t
sec_rgy_cursor_t, data type
sec_rgy_domain_t
sec_rgy_domain_t, data type
sec_rgy_foreign_id_t
sec_rgy_foreign_id_t, data type
sec_rgy_handle_t
sec_rgy_login_get_effective
sec_rgy_login_get_info
sec_rgy_login_name_t
sec_rgy_login_name_t, data type
sec_rgy_member_buf_t
sec_rgy_member_buf_t, data type
sec_rgy_member_t
sec_rgy_member_t, data type
sec_rgy_name_t, data type
sec_rgy_name_t-Short
sec_rgy_pgo_add
sec_rgy_pgo_add_member
sec_rgy_pgo_delete
sec_rgy_pgo_delete_member
sec_rgy_pgo_flags_t
sec_rgy_pgo_flags_t, data type
sec_rgy_pgo_get_by_eff_unix_num
sec_rgy_pgo_get_by_id
sec_rgy_pgo_get_by_name
sec_rgy_pgo_get_by_unix_num
sec_rgy_pgo_get_members
sec_rgy_pgo_get_next
sec_rgy_pgo_id_to_name
sec_rgy_pgo_id_to_unix_num
sec_rgy_pgo_is_member
sec_rgy_pgo_item_t
sec_rgy_pgo_item_t, data type
sec_rgy_pgo_name_to_id
sec_rgy_pgo_name_to_unix_num
sec_rgy_pgo_rename
sec_rgy_pgo_replace
sec_rgy_pgo_unix_num_to_id
sec_rgy_pgo_unix_num_to_name
sec_rgy_plcy_auth_t
sec_rgy_plcy_auth_t, data type
sec_rgy_plcy_get_effective
sec_rgy_plcy_get_info
sec_rgy_plcy_pwd_flags_t
sec_rgy_plcy_pwd_flags_t, data type
sec_rgy_plcy_set_info
sec_rgy_plcy_t
sec_rgy_plcy_t, data type
sec_rgy_pname_t
sec_rgy_pname_t, data type
sec_rgy_properties_flags_t
sec_rgy_properties_flags_t, data type
sec_rgy_properties_get_info
sec_rgy_properties_set_info
sec_rgy_properties_t
sec_rgy_properties_t, data type
sec_rgy_sid_t
sec_rgy_sid_t, data type
sec_rgy_site_bind
sec_rgy_site_bind(), overview
sec_rgy_site_bind_update
sec_rgy_site_bind_update(), overview
sec_rgy_site_binding_get_info
sec_rgy_site_binding_get_info(), overview
sec_rgy_site_close
sec_rgy_site_close(), overview
sec_rgy_site_get
sec_rgy_site_is_readonly
sec_rgy_site_is_readonly(), overview
sec_rgy_site_open
sec_rgy_site_open(), overview
sec_rgy_site_open_query
sec_rgy_site_open_update
sec_rgy_site_open_update(), overview
sec_rgy_unix_gecos_t
sec_rgy_unix_gecos_t, data type
sec_rgy_unix_getgrgid
sec_rgy_unix_getgrnam
sec_rgy_unix_getpwnam
sec_rgy_unix_getpwuid
sec_rgy_unix_group_t
sec_rgy_unix_group_t, data type
sec_rgy_unix_login_name_t
sec_rgy_unix_login_name_t, data type
sec_rgy_unix_passwd_buf_t
sec_rgy_unix_passwd_buf_t, data type
sec_rgy_unix_passwd_t
sec_rgy_unix_passwd_t, data type
sec_rgy_unix_sid_t
sec_rgy_unix_sid_t, data type
sec_rgy_wait_until_consistent
sec_timeval_period_t
sec_timeval_period_t, data type
sec_timeval_sec_t
sec_timeval_sec_t, data type
sec_timeval_t
secidmap
secidmap RPC interface
second
secondary group UUID,
secondary group, in account item
secrecy
secret
secret,
secret, role in building trust chain
secret-key certificate
secrets
secure
security
security client daemon (SCD),
security context
security junction RPC group
security services, introduction
security, attribute
security, based on time
security, distributed
security, generalities
security, integration with naming services
security, integration with RPC
security, level provided by DES
security, logical
security, model
security, of cross-cell authentication step
security, of non-memorisable password
security, of time source
security, physical
security, verifier (PDU)
security, versus performance
Security-Related
Security-The
Security-Version
security-version UUID
seed
seed, DES
seed, of CRC
Selection/Substitution
selector, in secidmap interface
self, trust in
semantic information, in ID map facility
semantic representation (encoding)
semantics of permission
semantics, of permission
Semi-Weak
semi-weak keys,
sends
separator, in cell name
sequence
sequence number, checked by KDS server
sequence number, data type
sequence,
sequence, and endianness
SEQUENCE, denoting field element
sequences
server
server cell, in TGS response
server name, checked by KDS server
server name, in TGS response
server name, not a parameter in sec_acl
server name, versus CDS-registered service name
server, in CL context
server, in KDS Error message
server, in transit path
server, readable/writable
server, receives authentication header
server, receives PA header
server, receives PTGS request
server, security
server, targeted
servers
service
service name, RPC
service request, failed
service request/response
service ticket,
service,
service, assured
service, examples
service, PTGS
service, request/response
service-ticket
serviceability permission
services
session
session key
session key,
session key, distributed by KDS
session key, generation
session key, in AS response
session key, in Kerberos protocol
session key, in TGS response
session key, use (authentication header flag)
session,
set
set, ACLE permission
sets
shadow
shadow password
shape model, trusted
shared state
shell
shift
shift schedule
short PGO name
short-term key
shortword,
side
signature
signature,
simple
simple object,
site
site, synonymous with server
skew
skew,
skew, in RS information
slave
slave RS server
so
some
space character, prohibited in password
space, in transit path
special
specific
specification
specificity, of ACLEs
specified
spoof
standard
start time
start time, initialisation
state
state information, conceptual part of login context
states
static method, none for decomposing PGO names
status
status code, ACL editor
status code, in KDS Error message
status code, in rpriv
status code, key management
status code, RS editor interfaces
status code, scd interface
status code, secidmap
status text, in KDS Error message
step
storage, of data type as pickle
strategy, next-hop
strength
strength of algorithm,
string
stringname
stringname, guaranteed unique
stringname, in PGO item
stringname, name of PGO
stringname, on server, identifies object
stringname, printable (data type)
strong
stx_id
stx_version
sub_type
subalgorithm
subalgorithm, CADA
subalgorithms
subject
subject,
subject-side access information
subjects
subkey to halfblock mapping
submapping
subscript
subtracting rights
success, in received response
supported
surrogate
surrogate cell principal
suspicion, of PAC without authentication
symbol
symmetric trust peers
synchronisation
syntactic method, none for decomposing PGO names
syntactic representation (encryption)
syntax identifier
syntaxes
t
T[]
table
tag UUID field
target
targeted server
targeted ticket,
taxonomy, of ACLE types
TCB
TCB,
TCB, issuing cell
technology, versus human issues
terminology
terminology,
terminology, academic
test permission
TGS
TGS request
TGS request, client sends
TGS request/response
TGS response
TGS response, construction
TGS response, receiving
TGS,
TGS, request received
TGS, request/response processingn
TGS, response (data type)
TGT
the CRC,
their
theory, formal
third
third party, trusted
Third-Party
Third-Party, Client Protocol
Third-Party, Protocol
Third-Party, Server Protocol
this
threat analysis
ticket
ticket flag, data type
ticket,
ticket, and authenticator
ticket, basis for denying service
ticket, data type
ticket, differences between types
ticket, distributed by KDS
ticket, effect when key is changed
ticket, encrypted part
ticket, genuineness of received
ticket, granting service
ticket, in AS response
ticket, in Kerberos protocol
ticket, in service request
ticket, in TGS response
ticket, interpretability
ticket, Kerberos
ticket, lifetime
ticket, lifetime in registry property
ticket, lifetime, in RS information
ticket, manipulated old
ticket, newly issued
ticket, obtained from KDS at login
ticket, privilege
ticket, privilege-
ticket, privilege- (data type)
ticket, referral
ticket, request
ticket, request for new
ticket, targeted
ticket, ticket-granting
ticket, timestamps in
ticket-granting service (TGS),
ticket-granting service,
ticket-granting ticket
tickets
time
time interval, data type
time services
time, basis for security
time, end of
time, start/expiration
time, UTC
time-out
time-out, password
timeliness
timestamp, checked by KDS server
timestamp, comparison and arithmetic
timestamp, compromise of
timestamp, data type
timestamp, in KDS Error message
timestamp, in Kerberos protocol
timestamp, lifetime
timestamp, microsecond
timestamp, usage in Kerberos
timestamps
Timestamps, Protocol
token
tolerance for malformed ACL
tower, protocol
traced
Traced Delegation
trademarks
transaction, semantics not specified
transferred trust
transit
transit path,
transit path, checked by KDS server
transit path, data type
transit path, empty
transit path, in AS response
transit path, in privilege ticket
transit path, in RS information
transit path, level of trust in
transitive trust
transmitting
trigger
Trigger Binding,
triggers
trigonometric
trigonometric vector T[]
trivial encryption
trivial, encryption
true session key
trust
trust chain,
trust chain, extend to multi-cell case
trust chain, indirect
trust chain, link
trust chain, multi-hop
trust,
trust, and authentication flag
trust, and cross-registration
trust, evaluating the path
trust, in transit path
trust, in UUIDs
trust, of login context
trust, varies between cells
trusted
trusted computing base (TCB)
trusted computing base (TCB),
trusted shape model
twisted CRC
type
type UUID, of ACL manager
type UUID, pre-encrypted pickle
type, ACL
type, ACL, data type
type, checksum
type, for encrypting byte strings (data type)
type, for uninterpreted byte strings (data type)
type, of ACL manager supported by RS
type, of ACLE
type, of checksum (data type)
type, of encryption (data type)
type, of key
type, of query key
type, polymorphic
type, UUID, ACL managers
types
types of protected object, multiple
Types, Supported for Delegation
Types, Supported Seal Identifiers
typographic
typographic conventions
UDP
unambiguous account reference
unambiguous, guarantee of stringname
UNAUTHENTICATED
unauthenticated ACL entry
UNAUTHENTICATED, at most one
UNAUTHENTICATED, optional in common ACL manager
underlying object
unencrypted
unilateral trust mediation
uninterpreted, cell name
unique, guarantee of stringname
uniqueness, of object identification
uniqueness, of pgo-UUID
uniqueness, of security-version UUID
uniqueness, of UUID in PGO item
universal ACLE type
universal delegation ACLE type
unknown
Unknown Intercell Action, Attribute
unprotected RPC
unregisterable authorisation data
unspecified bit
untrusted
unused bit
unvalidated login
up-over-down algorithm
update
Update Triggers
US ASCII
use
use session key, authentication header flag
use-session-key
use-session-key, checked by KDS server
use-session-key, in TGS request
use_defaults
use_defaults, Algorithm
USER
user information permission
user interfaces for ACL manipulation, not specified
User Interfaces, ACLEs
USER, algorithm
user, attribute (data type)
USER, limitation in common ACL
USER, supported by common ACL manager
user-friendly, common ACL manager
user-level information
user-to-user authentication
USER/FOREIGN_USER
USER_DEL, algorithm
USER_DEL/FOREIGN_USER_DEL
USER_DELEG
USER_OBJ
USER_OBJ, algorithm
USER_OBJ, at most one
USER_OBJ, optional in common ACL manager
USER_OBJ_DEL
USER_OBJ_DEL, algorithm
USER_OBJ_DELEG
UTC time
UTC, difference from (skew)
UUID
UUID, account (data type)
UUID, ACL manager type
UUID, ACL managers
UUID, ACLs
UUID, conceptual part of login context
UUID, default cell
UUID, element of cell-profile node
UUID, group
UUID, in authorisation identity
UUID, in PGO item
UUID, in registry property
UUID, local cell
UUID, local secondary group
UUID, lookup by
UUID, mapping by ID map facility
UUID, pairs
UUID, pre-encrypted pickle
UUID, principal
UUID, rdacl interface
UUID, rs_acct interface
UUID, rs_attr interface
UUID, rs_attr_schema interface
UUID, rs_bind interface
UUID, rs_misc interface
UUID, rs_pgo interface
UUID, rs_policy interface
UUID, rs_prop_acct interface
UUID, rs_prop_acl interface
UUID, rs_prop_attr interface
UUID, rs_prop_attr_schema interface
UUID, rs_prop_pgo interface
UUID, rs_prop_plcy interface
UUID, rs_prop_replist interface
UUID, rs_pwd_mgmt interface
UUID, rs_qry interface
UUID, rs_repadm interface
UUID, rs_replist interface
UUID, rs_repmgr interface
UUID, rs_rpladmn interface
UUID, rs_unix interface
UUID, rs_update interface
UUID, scd interface
UUID, secidmap interface
UUID, security-version
UUID, stored in ticket at login
uuid_create(), not part of TCB
UUIDs
validate, in TGS request
validated
validated login
validation of ticket, by login facility
validation state, conceptual part of login context
validation, as certification
validity of key, limit on time
validity, password
value
variability
variability, in header processing
vector
verifier
verifier, of PDU
verifier, PDU
verifier, RPC, availability
verifiers
version
Version 0 Token Flags, Data Type
version 2 UUID
version number, checked by KDS server
version number, element of cell-profile node
version number, in CL security
version number, in KDS Error message
version number, in registry property
version number, in RS information
version number, of cryptographic key
version number, of key
version number, of pickle header
version number, of RPC transfer syntax
version number, of version 2 UUID
version number, presence/absence of
version number, protocol (data type)
version number, rdacl interface
version number, rs_acct
version number, rs_bind interface
version number, rs_misc
version number, rs_pgo
version number, rs_policy interface
version number, rs_prop_acct interface
version number, rs_prop_acl interface
version number, rs_prop_attr interface
version number, rs_prop_attr_schema interface
version number, rs_prop_pgo interface
version number, rs_prop_plcy interface
version number, rs_prop_replist interface
version number, rs_pwd_mgmt interface
version number, rs_qry interface
version number, rs_repadm interface
version number, rs_replist interface
version number, rs_repmgr interface
version number, rs_rpladmn interface
version number, rs_unix interface
version number, rs_update interface
version number, scd interface
version number, secidmap
versions
versus
vetting, cross-cell
vetting, in RS information
visibility, password
vouch,
vouching, by PS
vouching, by PS server
warning
weak
weak keys,
Well Known, Attribute Types
well-formed ACL
Well-Known
what
wildcard
wiretapping
word
word of mouth
word operations
word,
words
wrap-around
writability, in registry property
writable server
write permission
write, protection against
write-ACL permission
X.208
X.209
X.500, name type
X.509
X3.106
X3.92, no mention of weak keys
xattrschema
XNS, registered address type
XOR,
zero-length salt
Zulu time