3 kdb - Displays log or privileged actions performed by the Authentication Server
7 B<kdb> [-dbmfile <I<dbmfile to use (default /usr/afs/logs/AuthLog)>>]
8 [B<-key> <I<extract entries that match specified key>>] [B<-help>]
12 The kdb command displays the contents of the
13 B<AuthLog.dir> and B<AuthLog.pag> files
14 associated with the B<AuthLog> file that resides on the local disk, by
15 default in the B</usr/afs/logs> directory. The files must exist
16 in that directory, which normally implies that the Authentication Server is
17 running on the machine. The files contain information on privileged
18 actions performed by the Authentication Server.
22 It is possible that on some operating systems that AFS otherwise supports,
23 the Authentication Server cannot create the
24 B</usr/afs/logs/AuthLog.dir> and
25 B</usr/afs/logs/AuthLog.pag> files, making this command
26 inoperative. See the I<IBM AFS Release Notes> for
35 Specifies the pathname of the file to display. Provide either a
36 complete pathname, a pathname relative to the B</usr/afs/logs>
37 directory, or a filename only, in which case the file must reside in the
38 B</usr/afs/logs> directory. Omit this argument to display
39 information from the B<AuthLog.dir> and
40 B<AuthLog.pag> files in the B</usr/afs/logs>
45 Specifies each entry to be displayed from the indicated file.
49 Prints the online help for this command. All other valid options
56 The first line of output indicates the location of the files from which the
57 subsequent information is derived:
59 Printing all entries found in I<file_location>
61 Each entry then includes the following two fields, separated by a
69 Identifies the user requesting the corresponding service and the server
70 that performed that service. In cases where no user is directly
71 involved, only the server appears; in cases where no server is directly
72 involved, only the user appears.
77 Identifies one of the following actions or services performed by the user
84 C<auth>: Obtained a ticket-granting ticket
89 C<chp>: Changed a user password
94 C<cruser>: Created a user entry in the Authentication
100 C<delu>: Deleted a user entry from the Authentication
106 C<gtck>: Obtained a ticket other than a ticket-granting
112 C<setf>: Set fields in an Authentication Database entry
117 C<unlok>: Unlocked an Authentication Database entry
124 The final line of output sums the number of entries.
128 The following example shows the output of the kdb command in the
129 ABC Corporation cell (B<abc.com>):
132 Printing all entries found in /usr/afs/logs/AuthLog
133 admin,krbtgt.ABC.COM:auth
139 =head1 PRIVILEGE REQUIRED
141 The issuer must be logged in as the local superuser root.
145 L<AuthLog.dir,_AuthLog.pag(1)>,
151 IBM Corporation 2000. <http://www.ibm.com/> All Rights Reserved.
153 This documentation is covered by the IBM Public License Version 1.0. It was
154 converted from HTML to POD by software written by Chas Williams and Russ
155 Allbery, based on work by Alf Wachsmann and Elizabeth Cassell.