gsscred(1M)

gsscred - Generic Security Service credentials cache utility

Showing IRIX 6.5.30 (default release). Added in IRIX 6.5.30.

NAME
     gsscred - Generic Security Service credentials cache utility

SYNOPSIS
     gsscred [-n user [-o oid] [-u uid]] [-c comment] -m mech -a
     gsscred [-n user [-o oid]] [-u uid] [-m mech] -r
     gsscred [-n user [-o oid]] [-u uid] [-m mech] -l

DESCRIPTION
     gsscred is used to maintain local credentials cache which is used on
     server machines to translate between Generic Security Service (GSS)
     principal's names and the local UNIX user and group IDs.

     When adding entries to the cache (-a) if no user is specified, all
     entries from the password file are added to the cache. To add single
     entry to the cache, use -n option. If the user's name is not in the
     password file, use -u option to specify user ID. For example,

     # gsscred -m kerberos_v5 -a

     adds all users listed in the password file to the cache.

     # gsscred -n mary -m kerberos_v5 -a

     adds mary to the cache and the UID for mary will be the same as it is in
     the password file,

     # gsscred -n foreigner_joe -u 59999 -m kerberos_v5 -a

     adds foreigner_joe to the cache and assigns UID 59999 since there is no
     entry for foreigner_joe in the password file.

     When removing entries from the cache (-r), if no user is specified, all
     entries from the password file will be removed from the cache. To remove
     specific entry from the cache, use -n, -m, -u options. For example, to
     remove all kerberos_v5 entries, use

     # gsscred -m kerberos_v5 -r

     or to remove all entries for mary, use

     # gsscred -n mary -r


     When searching for entries in the cache (-l), if no user is specified,
     all entries for users in password file will be printed.  Similar to the
     addition and removal case, -n, -m and -u options can be used to specify
     search criteria.
OPTIONS
     -a   add names to the local credentials cache

     -c comment
          add comment to the entry

     -l   list content of the local credentials cache

     -m mech
          specify GSS mechanism for which the name is going to be translated

     -n user
          user name as appears in the local password file.

     -o oid
          specify the GSS Object ID for the principal's name. The OID must be
          in dot-separated notation, e.g. 1.2.3.4567.8.9

     -r   remote credentials from the cache

     -u uid
          specify UID for the user if the user is not in the password file.

SEE ALSO
     gssd(1M), passwd(4) and rpcsec_gss(7).

CAVEATS
     Note that while translating principal name to user and group ID, it is
     possible to map multiple principals to the same user and group ID as long
     as the specified user ID is found in the password file. If the specified
     user ID is not found in the password file the principal will be mapped to
     user and and group ID of nobody.