Connecting to kadmin
You do not need any special privileges on the client machine to use kadmin; all you need is the password to a principal that has privileges enabled in the kadmin ACL file.
% /usr/local/sbin/kadmin Authenticating as principal jgarman/admin@WEDGIE.ORG with password. Enter password: kadmin:
Inside of kadmin, a list of available commands is always available through the “?” command.
The fail-safe copy of kadmin, kadmin.local, requires root privileges to run. You have to be root on the master KDC to run kadmin.local because it modifies the Kerberos database directly. As such, running kadmin.local does not require any Kerberos daemons to be running, and in fact it is most commonly used to set up the initial Kerberos principals when establishing a new realm. Starting kadmin.local is very similar to starting kadmin:
# /usr/local/sbin/kadmin.local Authenticating as principal jgarman/admin@WEDGIE.ORG with password. kadmin.local:
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access