Prerequisite checklist Answers
Is your OS/400 V5R2 (5722-SS1) or later?  
Is Cryptographic Access Provider (5722-AC3) installed on your iSeries systems?  
Is iSeries Access for Windows (5722-XE1) installed on the PC that you will use to configure NAS?  
Is the Security subcomponent of iSeries Navigator installed on the PC that you will use to configure NAS?  
Is the Network subcomponent of iSeries Navigator installed on the PC that you will use to configure NAS?  
Do you have *SECADM, *ALLOBJ, and *IOSYSCFG special authorities?  
Is your system value set to *VERIFY? To change the value, use either the iSeries command line or iSeries Navigator.

Using the iSeries command line, take the following steps:
1. Type the following command:
WRKSYSVAL SYSVAL(QRMTSIGN)
2. Enter the number 5 to display your current system value. If this value is *FRCSIGNON, enter the number 2 and change it to *VERIFY.

To use iSeries Navigator, take the following steps:
1. From your target iSeries server, click Configuration and Service > System Values > Sign-on > Remote.
2. Under 'Use Telnet for remote sign-on', check 'Allow sign-on to be bypassed'.
3. Select 'Use Pass-through for remote sign-on'.
4. Select 'Allow sign-on to be bypassed' and then 'Verify user ID on target system'.

 
Have you confirmed that your iSeries software clock is synchronized with a specified time server? The Simple Network Time Protocol (SNTP) client allows you to do this. You can specify an amount of time that the iSeries software clock must be near the time server before the SNTP client will adjust the time of day on your software clock. This function is particularly important when using Network Authentication Service (NAS).

In iSeries Navigator, you can start and stop your SNTP client. You can also specify the time server to compare the iSeries software clock, and select when you would like SNTP activity to be logged.

To start or stop the SNTP client in iSeries Navigator, follow these steps:

1. Expand your iSeries server > Network > Servers > TCP/IP.
2. Right-click SNTP, and select Start or Stop, as appropriate.

To adjust the SNTP client parameters in iSeries Navigator, follow these steps:
1. Expand your iSeries server > Network > Servers > TCP/IP.
2. Right-click SNTP, and select Properties to display the SNTP Properties pages.
3. Adjust parameters in the General and Additional parameters tabs.
4. For additional information, click the Help button on the General and Additional parameters tabs.
5. Click OK.

Note: The remote time server host must be configured before the SNTP client can start.

 

Do you have one of the following installed on the secure system that will act as the KDC? If so, which one?

  • Windows 2000 Server
  • Windows XP Server
  • AIX Server
  • zSeries
 
For Windows 2000 Server and Windows XP Server, do you have Windows Support Tools, which provides the ktpass tool, installed on the system being used as the key distribution center?  
Are all your PCs in your network configured in a Windows 2000 domain?  
Have you applied the latest program temporary fixes (PTFs)? (The latest PTFs are located on the IBM eServer iSeries support site at http://www.ibm.com/servers/eserver/support/iseries/.)  
Is the iSeries system time within five minutes of the KDC’s system time?  

 

You need this information to configure NAS Answers
What is the name of the Kerberos default realm to which iSeries-A and iSeries-B will belong?  
What is the KDC for this Kerberos default realm?
What is the port on which the KDC listens?
 
Do you want to configure a password server for this default realm? If yes, answer the following questions:
What is name of the password server for this KDC?
What is the port on which the password server listens?
 
What is the host name of the iSeries servers on which you are configuring NAS?  
What is the password for your iSeries service principal(s)?  
What additional realms will your iSeries systems interact with?  
For each realm, what is the host name of the KDC?  

 

You need this information to configure EIM Answers
What is the host name of the iSeries server on which you are configuring EIM?  
What is the LDAP administrator's distinguished name and password?  
What is the name if the Directory Services (LDAP) server?  
What is the port number of the Directory Services (LDAP) server?