This is always the case for plain DCE servers.
这常用于普通的DCE服务器中。
Authentication flag: this flag shows whether this PAC was authenticated by DCE security.
身份验证标志:此标志显示此PAC是否经过了DCE安全机制的身份验证。
DCE security service use PACs that describe a client「s security attributes.
DCE安全服务使用pac来描述客户端的安全属性。
Together with these three services in place, DCE enforces a very effective security mechanism in distributed environment.
将这三种服务相结合,DCE在分布式环境中实现了一种非常有效的安全机制。
Here, the privilege service of DCE enhances the authentication service by adding the concept of privilege attribute certificates (PAC).
在这里,DCE的特权服务通过加入特权属性证书(PAC),增强了身份验证服务。
Once the security server confirms the identity of the user via secret key, the login process of the user into the DCE is completed.
一旦安全服务器通过秘密密钥确认了用户的身份,用户登录到DCE的过程就完成了。
From Session 2, the user again sends a resource request to the DCE app server, which again pulls in the user」s completed PAC structure.
在会话2中,该用户再次发送一个对DCE应用服务器的资源请求,这会再次获取该用户完整的PAC结构。
The responsibility to initiate an authenticated RPC to the target server (through an appropriate DCE API call) lies with the client applications.
(通过一个适当的DCEAPI调用)向目标服务器发起一个已认证的RPC的职责在于客户机程序。
Use this method to set the DCE security level for this RPC call.
使用该方法为这个RPC调用设置dce安全级别。
Figure 2 illustrates the DCE security system.
图2阐述了DCE的安全系统。
The user then passes the certificate to the server which is hosting the DCE service required by the user.
用户然后将凭证传送给承载用户所需DCE服务的服务器。
In DCE privilege service, the server determines whether a given client is authorized to perform a specific operation with the help of information obtained from PACs.
在DCE特权服务中,服务器借助从PAC获得的信息,判断给定客户端是否有权执行特定操作。
This may also be able to confirm that DCE is not invalidating your results.
这还可以确认DCE没有歪曲测试结果。
This similarity is a result of the fact that DCE authentication service was built upon the source code for Kerberos V5.
这种相似性源于这样一个事实:DCE身份验证服务建立在KerberosV5的源代码之上。
As seen from the previous details, the authentication service being implemented by the DCE is very similar to the process followed in Kerberos protocol.
从前面的细节可以看到,DCE实现的身份验证服务非常类似于Kerberos协议中所遵循的过程。
To know what DCE security level and delegation constants are available, refer to Appendix a.
参阅附录a来了解dce安全级别和授权常量。
It is also responsible to support network-wide single login, which means that logging into DCE account automatically logs the user into all the associated local accounts too.
它还负责支持网络范围的单点登录,这意味着登录到DCE帐户也会自动将用户登录到所有相关联的本地帐户。
For example, in case of MAS and DCE servers, users are either given execute permission on all the methods in the interface or none at all.
例如,假设在MAS和DCE服务器上,对于接口中的所有方法用户可能被给予执行许可也可能不给予任何许可。
Account Information: DCE accounts are just like any other local account on the OS.
帐户信息:DCE帐户就像操作系统上任何其他本地帐户一样。
Other information like DCE security level and transaction timeout can also be specified using this class. For example.
其它的信息(如dce安全级别及事务超时)也会通过使用该类来指定。
From Session 1, the user sends a resource request to the DCE application server.
在会话1中,用户发送一个对DCE应用服务器的资源请求。
The following section describes the working of the privilege service in DCE with the help of the figure 7.
下一节通过图7介绍DCE中的特权服务的工作原理。