Distributed Authentication Service--
A Campus Guide
In order to read web pages or news services whose content is restricted to UCD students,
faculty, staff, and other affiliates,
you must first prove your association with UCD by correctly entering your
UCD LoginID and Kerberos password. Once you have successfully done this,
you will be able to read any page secured within ucdavis.edu for the
duration of your browser session. If you have run into any problems,
especially with the login step, you may find a solution on this page.
- Distributed Authentication Browser and Account Requirements
A valid name and password, a browser supporting SSL
, and a browser that
accepts cookies are required for distributed authentication.
- name and password:
The authentication process requires a UCD LoginID
and Kerberos Password to identify the campus affiliate requesting access.
- local browser and SSL:
Your local browser must be able to encrypt your password. To do this,
the browser must support SSL, the secure sockets protocol. Netscape
browsers and Microsoft Internet Explorer browsers do meet this criteria.
If you are running a different browser, look at our browser list.
- local browser and cookies:
Your local browser must be able to accept a cookie. (By default, your browser
will accept a cookie, unless you have changed this setting).
Problems
Requesting Further Assistance
Further information
Problems/Solutions
- The browser returns to the "restricted docs" page
If after entering your name and password, the browser displays the "restricted
docs" page rather than the secure document, something didn't work
correctly. One possibility is that your
browser did not accept the cookie. The default behavior with Netscape
and Microsoft browsers is to accept cookies. You can, however, set
an option to alert you when a cookie is being passed to your browser.
If this is the case, be sure to accept the cookie. You will not be able
to access restricted services without doing so.
- You do not have a UCD LoginID and Kerberos password
A UCD LoginID (new-style LoginID) and Kerberos password are required to access secure
UCD pages.
Refer to the Computing Account Services Web
Site
to learn about and or transition to
a UCD LoginID and/or Kerberos password.
- Your Name/Password are not accepted
This problem could be due to typing errors or password problems.
- Passwords
are case sensitive; upper and lower case keys must be entered precisely.
- Another tip for those who are using systems with the same LoginID: Your DaFIS,
BANNER, and ISUN accounts may have the same LoginID, but they do not
necessarily have the same password.
- You may have set up
a UCD LoginID but
may not have a "ticket" for Kerberos services, nor a valid Kerberos password.
- In summary, you need a valid LoginID, an IKRB ticket, and a valid Kerberos
password in order to successfully login.
The easiest way to sort this out is to contact
IT-Express .
If you would like to check this out yourself, go to
Computing Account Services and
"check the status of your LoginID". Look for the service, IKRB in the
list of services currently granted, along with an account type of
"new login".
- If you do not have IKRB
service, you will not have a valid password.
To obtain IKRB service and
select your password, telnet to mothra.ucdavis.edu and login with the
name, services, and select option G.
- If your account type was not "new login", it may still be valid. You can check this by connecting to mothra.ucdavis.edu
via telnet and logging in as "services" and selecting option N. Look for
"is a conversion for LoginID:", meaning you have an account that was
converted to the new-style LoginID successfully.
- Your browser does not support SSL
The following browsers do support SSL, a protocol for encoding login/password
transactions. In order to access a secure web page, your browser must support
SSL. This list is not exhaustive. If your browser is not on this list and
you are successfully reading restricted sites, let us know (email ithelp@ucdavis.edu)
the name of your
browser and we'll add it to this list. In general, you will have trouble
with older browsers.
- Netscape's Navigator (UNIX/Mac version 1.12 and later)
- Netscape's Navigator (Windows version 1.22 and later)
- IBM Internet Connection Secure WebExplorer (version 1.1) for OS/2
- Delrina Cyberjack Web (version 7.00)
- Prodigy Web Browser (version 1.4b)
- InternetMCI (version 1.0)
- Microsoft's Internet Explorer
- America Online (version 3)
- Quarterdeck Mosaic 2.0
- You receive a "forbidden" message
If your computer does not have a valid IP address, service is forbidden
by some UCD web servers.
- Warning Message: Server setting a
cookie
Depending on how your browser security alerts are set,
you may get a message saying "The server secureweb.ucdavis.edu wishes
to set a cookie that will be sent to any server in the domain .ucdavis.edu.
The name and value of the cookie are: xxxx.
Do you wish to allow the cookie to be set?"
In order to access a secure document, you must allow the cookie to be
set. Click OK to continue.
- Warning Message:You have reqeusted an
insecure document
Depending on how your browser security
alerts are set, you may get a message saying "Warning! You have requested
an
insecure document that was originally designatee a secure document. (The
location has been redirected from a secure to an incure document). Any
information lyou send back could be observed by a third party while in
transit."
In negotiating your authentication, your browser is redirected to
the secure server, secureweb. Afterward, your browser is redirected to
the local web server. This is the correct order of events. You can
ignore the warning message.
Comments: ithelp@ucdavis.edu
This page last modified on 03/08/02