2005-12-08 12:14:33 +00:00
|
|
|
=head1 NAME
|
|
|
|
|
|
|
|
kdb - Displays log or privileged actions performed by the Authentication Server
|
|
|
|
|
|
|
|
=head1 SYNOPSIS
|
|
|
|
|
2006-03-01 05:02:29 +00:00
|
|
|
=for html
|
|
|
|
<div class="synopsis">
|
|
|
|
|
|
|
|
B<kdb> S<<< [B<-dbmfile> <I<dbmfile to use (default /usr/afs/logs/AuthLog)>>] >>>
|
|
|
|
S<<< [B<-key> <I<extract entries that match specified key>>] >>> [B<-help>]
|
|
|
|
|
|
|
|
=for html
|
|
|
|
</div>
|
2005-12-08 12:14:33 +00:00
|
|
|
|
|
|
|
=head1 DESCRIPTION
|
|
|
|
|
2005-12-13 19:21:13 +00:00
|
|
|
The B<kdb> command displays the contents of the F<AuthLog.dir> and
|
|
|
|
F<AuthLog.pag> files associated with the F<AuthLog> file that resides on
|
|
|
|
the local disk, by default in the F</usr/afs/logs> directory. The files
|
|
|
|
must exist in that directory, which normally implies that the
|
|
|
|
Authentication Server is running on the machine. The files contain
|
|
|
|
information on privileged actions performed by the Authentication Server.
|
2005-12-08 12:14:33 +00:00
|
|
|
|
2005-12-09 14:48:56 +00:00
|
|
|
=head1 CAUTIONS
|
2005-12-08 12:14:33 +00:00
|
|
|
|
|
|
|
It is possible that on some operating systems that AFS otherwise supports,
|
2005-12-13 19:21:13 +00:00
|
|
|
the Authentication Server cannot create the F</usr/afs/logs/AuthLog.dir>
|
|
|
|
and F</usr/afs/logs/AuthLog.pag> files, making this command
|
|
|
|
inoperative. See the I<IBM AFS Release Notes> for details.
|
2005-12-08 12:14:33 +00:00
|
|
|
|
|
|
|
=head1 OPTIONS
|
|
|
|
|
|
|
|
=over 4
|
|
|
|
|
2005-12-13 19:21:13 +00:00
|
|
|
=item B<-dbmfile> <I<dbmfile to use>>
|
2005-12-08 12:14:33 +00:00
|
|
|
|
2005-12-13 19:21:13 +00:00
|
|
|
Specifies the pathname of the file to display. Provide either a complete
|
|
|
|
pathname, a pathname relative to the F</usr/afs/logs> directory, or a
|
|
|
|
filename only, in which case the file must reside in the F</usr/afs/logs>
|
|
|
|
directory. Omit this argument to display information from the
|
|
|
|
F<AuthLog.dir> and F<AuthLog.pag> files in the F</usr/afs/logs> directory.
|
2005-12-08 12:14:33 +00:00
|
|
|
|
2005-12-13 19:21:13 +00:00
|
|
|
=item B<-key> <I<extract entries that match specified key>>
|
2005-12-08 12:14:33 +00:00
|
|
|
|
|
|
|
Specifies each entry to be displayed from the indicated file.
|
|
|
|
|
2005-12-13 19:21:13 +00:00
|
|
|
=item B<-help>
|
2005-12-08 12:14:33 +00:00
|
|
|
|
2005-12-13 19:21:13 +00:00
|
|
|
Prints the online help for this command. All other valid options are
|
|
|
|
ignored.
|
2005-12-08 12:14:33 +00:00
|
|
|
|
|
|
|
=back
|
|
|
|
|
|
|
|
=head1 OUTPUT
|
|
|
|
|
2005-12-13 19:21:13 +00:00
|
|
|
The first line of output indicates the location of the files from which
|
|
|
|
the subsequent information is derived:
|
2005-12-08 12:14:33 +00:00
|
|
|
|
2005-12-13 19:21:13 +00:00
|
|
|
Printing all entries found in <file_location>
|
2005-12-08 12:14:33 +00:00
|
|
|
|
2005-12-13 19:21:13 +00:00
|
|
|
Each entry then includes the following two fields, separated by a colon:
|
2005-12-08 12:14:33 +00:00
|
|
|
|
|
|
|
=over 4
|
|
|
|
|
2005-12-13 19:21:13 +00:00
|
|
|
=item user/server
|
2005-12-08 12:14:33 +00:00
|
|
|
|
|
|
|
Identifies the user requesting the corresponding service and the server
|
2005-12-13 19:21:13 +00:00
|
|
|
that performed that service. In cases where no user is directly involved,
|
|
|
|
only the server appears; in cases where no server is directly involved,
|
|
|
|
only the user appears.
|
2005-12-08 12:14:33 +00:00
|
|
|
|
2005-12-13 19:21:13 +00:00
|
|
|
=item service
|
2005-12-08 12:14:33 +00:00
|
|
|
|
|
|
|
Identifies one of the following actions or services performed by the user
|
2005-12-13 19:21:13 +00:00
|
|
|
or server process.
|
2005-12-08 12:14:33 +00:00
|
|
|
|
|
|
|
=over 4
|
|
|
|
|
|
|
|
=item *
|
|
|
|
|
2005-12-13 19:21:13 +00:00
|
|
|
C<auth>: Obtained a ticket-granting ticket.
|
2005-12-08 12:14:33 +00:00
|
|
|
|
|
|
|
=item *
|
|
|
|
|
2005-12-13 19:21:13 +00:00
|
|
|
C<chp>: Changed a user password.
|
2005-12-08 12:14:33 +00:00
|
|
|
|
|
|
|
=item *
|
|
|
|
|
2005-12-13 19:21:13 +00:00
|
|
|
C<cruser>: Created a user entry in the Authentication Database.
|
2005-12-08 12:14:33 +00:00
|
|
|
|
|
|
|
=item *
|
|
|
|
|
2005-12-13 19:21:13 +00:00
|
|
|
C<delu>: Deleted a user entry from the Authentication Database.
|
2005-12-08 12:14:33 +00:00
|
|
|
|
|
|
|
=item *
|
|
|
|
|
2005-12-13 19:21:13 +00:00
|
|
|
C<gtck>: Obtained a ticket other than a ticket-granting ticket.
|
2005-12-08 12:14:33 +00:00
|
|
|
|
|
|
|
=item *
|
|
|
|
|
2005-12-13 19:21:13 +00:00
|
|
|
C<setf>: Set fields in an Authentication Database entry.
|
2005-12-08 12:14:33 +00:00
|
|
|
|
|
|
|
=item *
|
|
|
|
|
2005-12-13 19:21:13 +00:00
|
|
|
C<unlok>: Unlocked an Authentication Database entry.
|
2005-12-08 12:14:33 +00:00
|
|
|
|
|
|
|
=back
|
|
|
|
|
|
|
|
=back
|
|
|
|
|
|
|
|
The final line of output sums the number of entries.
|
|
|
|
|
|
|
|
=head1 EXAMPLES
|
|
|
|
|
2005-12-13 19:21:13 +00:00
|
|
|
The following example shows the output of the B<kdb> command in the ABC
|
|
|
|
Corporation cell (C<abc.com>):
|
2005-12-08 12:14:33 +00:00
|
|
|
|
|
|
|
% kdb
|
|
|
|
Printing all entries found in /usr/afs/logs/AuthLog
|
|
|
|
admin,krbtgt.ABC.COM:auth
|
|
|
|
admin,afs:gtck
|
|
|
|
admin:cruser
|
|
|
|
admin:delu
|
|
|
|
4 entries were found
|
|
|
|
|
|
|
|
=head1 PRIVILEGE REQUIRED
|
|
|
|
|
2005-12-13 19:21:13 +00:00
|
|
|
The issuer must be logged in as the local superuser C<root>.
|
2005-12-08 12:14:33 +00:00
|
|
|
|
|
|
|
=head1 SEE ALSO
|
|
|
|
|
2005-12-13 19:21:13 +00:00
|
|
|
L<AuthLog.dir(5)>,
|
|
|
|
L<bos_getlog(8)>,
|
|
|
|
L<kaserver(8)>
|
2005-12-08 12:14:33 +00:00
|
|
|
|
|
|
|
=head1 COPYRIGHT
|
|
|
|
|
|
|
|
IBM Corporation 2000. <http://www.ibm.com/> All Rights Reserved.
|
|
|
|
|
|
|
|
This documentation is covered by the IBM Public License Version 1.0. It was
|
|
|
|
converted from HTML to POD by software written by Chas Williams and Russ
|
|
|
|
Allbery, based on work by Alf Wachsmann and Elizabeth Cassell.
|