Post

Kerberos keytab part-4

Kerberos keytab part-4

Before wiring the keytab into your application, verify it actually works by getting a Kerberos ticket manually with kinit. If kinit fails, there’s no point debugging your application’s Kerberos integration — fix the credentials first. klist confirms the ticket was granted and shows the expiry time.

  • Verify that below details actually generate a kerberos ticket

Domain Name : dummydomain

Service Account Name : myserviceaccount

Service Account Password : afk1K2##$#dlkajsf

  • Get kerberos ticket
1
2
$ kinit  myserviceaccount@dummydomain
Password for myserviceaccount@dummydomain:afk1K2##$#dlkajsf
  • List kerberos ticket
1
2
3
4
5
6
7
$ klist
Ticket cache: KCM:9713847:1
Default principal: myserviceaccount@dummydomain

Valid Starting      Expires       Service principal
<date time>         <date time>   krbtgt/dummydomain@dummydomain
        renew until <date time>
This post is licensed under CC BY 4.0 by the author.