{"id":"idm-kerberos-gated-administration","text":"All IdM administration — both API and CLI — requires prior Kerberos authentication: kinit to obtain tickets, klist to verify, kdestroy to remove, with the API consuming credentials via ipalib.","truth_value":"IN","source":"","source_url":"","source_hash":"","justifications":[],"dependents":[],"metadata":{},"explanation":{"steps":[{"node":"idm-kerberos-gated-administration","truth_value":"IN","reason":"premise"}]}}