Oracle Advanced Security Administrator's Guide Release 8.1.7 Part Number A85430-01 |
|
This chapter describes how to configure the Distributed Computing Environment (DCE) to use Oracle DCE Integration--after Oracle DCE Integration has been installed.
The following tasks, performed by the DCE cell administrator, assume that a DCE cell has been configured and the systems being used are part of that cell:
Use the following procedure model to add server principals:
% dce_login cell_admin password
% rgy_edit
Current site is:
registry server at /.../cell1/subsys/dce/sec/master
rgy_edit=>
do p
Domain changed to: principal
rgy_edit=>
add oracle
rgy_edit=>
do a
Domain changed to: account
rgy_edit=>
add oracle -g none -o none -pw oracle_password -mp cell_admin_ password
rgy_edit=>
quit
bye
In this example, a DCE principal named oracle
is created. The principal has a corresponding account with a password set to password. The account does not belong to any DCE group or DCE profile.
Install the key of the server into a keytab file, dcepa.key. This file contains the password of the principal under which the Net8 listener starts. The Net8 listener reads this file to authenticate itself to DCE. To generate the keytab file, enter the following:
% dce_login cell_admin password
% rgy_edit
Current site is: registry server at /.../cell1/subsys/dce/sec/master
rgy_edit=>
ktadd -p oracle -pw Oracle_password -f
$ORACLE_HOME/dcepa/admin/dcepa.key
rgy_edit=>quit
bye
Enter the following after installing DCE Integration for the first time in a cell; create directories on all CDS replicas:
% dce_login cell_admin
Enter Password:(password not displayed)
$
cdscp
cdscp>
create dir /.:/subsys/oracle
cdscp>
create dir /.:/subsys/oracle/names
cdscp>
create dir /.:/subsys/oracle/service_registry
cdscp>
exit
Enter the following to add the principal oracle
to the CDS-server group:
$
dce_login cell_admin
Enter Password: (password not displayed)
$
rgy_edit
rgy_edit=>
domain group
Domain changed to: group
rgy_edit=>
member subsys/dce/cds-server -a oracle
rgy_edit=> exit
Load Oracle service names into the Cell Directory Service, as described in Chapter 14, Configuring Oracle8i for Oracle DCE Integration.
|
![]() Copyright © 1996-2000, Oracle Corporation. All Rights Reserved. |
|