openafs/doc/man-pages/pod1/tokens.pod

131 lines
3.2 KiB
Plaintext
Raw Normal View History

=head1 NAME
tokens, tokens.krb - Displays the issuer's tokens
=head1 SYNOPSIS
=for html
<div class="synopsis">
B<tokens> [B<-help>]
B<tokens> [B<-h>]
B<tokens.krb> [B<-help>]
B<tokens.krb> [B<-h>]
=for html
</div>
=head1 DESCRIPTION
The B<tokens> command displays all tokens (tickets) cached on the local
machine for the issuer. AFS server processes require that their clients
present a token as evidence that they have authenticated in the server's
local cell.
The (mostly obsolete) B<tokens.krb> command is the same as B<tokens>
except that it also displays the user's Kerberos v4 ticket cache.
=head1 OPTIONS
=over 4
=item B<-help>
Prints the online help for this command. All other valid options are
ignored.
=back
=head1 OUTPUT
The output lists one token for each cell in which the user is
authenticated. The output indicates the
=over 2
=item *
User's AFS UID, if it is available for display.
=item *
Server for which the token is valid (normally, afs). This includes a cell
specification.
=item *
Day and time the token expires.
=back
The output of the Kerberos version of this command, B<tokens.krb>, also
reports the following about the Kerberos ticket-granting ticket: the
ticket owner, which Kerberos ticket-granting service that issued the
ticket (for example, C<krbtgt.EXAMPLE.COM>), and ticket's expiration date.
The string C<--End of list--> appears at the end of the output. If the
user is not authenticated in any cell, this line is all that appears.
=head1 EXAMPLES
The following example shows the output when the issuer is not
authenticated in any cell.
% tokens
Tokens held by the Cache Manager:
--End of list--
The following example shows the output when the issuer is authenticated in
Example Corporation cell, where he or she has AFS UID 1000.
% tokens
Tokens held by the Cache Manager:
User's (AFS ID 1000) tokens for afs@example.com [Expires Jan 2 10:00]
--End of list--
The following example shows the output when the issuer is authenticated in
the Example Corporation cell, the Example Organization cell, and the Example
Network cell. The user has different AFS UIDs in the three cells. Tokens for
last cell are expired:
% tokens
Tokens held by the Cache Manager:
User's (AFS ID 1000) tokens for afs@example.com [Expires Jan 3 10:00]
User's (AFS ID 4286) tokens for afs@example.org [Expires Jan 3 1:34]
User's (AFS ID 22) tokens for afs@example.net [>>Expired<]
--End of list--
The following example shows the output when the issuer uses the
B<tokens.krb> version of the command after authenticating in the Example
Corporation cell using the B<klog.krb> command.
% tokens.krb
Tokens held by the Cache Manager:
User's (AFS ID 1000) tokens for afs@example.com [Expires Jan 31 00:09]
User smiths tokens for krbtgt.EXAMPLE.COM@example.com [Expires Jan 31 00:09]
--End of list--
=head1 PRIVILEGE REQUIRED
None
=head1 SEE ALSO
L<klog(1)>,
L<unlog(1)>
=head1 COPYRIGHT
IBM Corporation 2000. <http://www.ibm.com/> All Rights Reserved.
This documentation is covered by the IBM Public License Version 1.0. It was
converted from HTML to POD by software written by Chas Williams and Russ
Allbery, based on work by Alf Wachsmann and Elizabeth Cassell.