samba4 keytab management

srikumar108 at srikumar108 at
Wed Aug 25 14:05:37 MDT 2010


How do I get this done? I am trying to get ssh working with GSSAPI. Reading previous messages here, I added a krb5Keytab attribute 
to the host/xyz at REALM entry in secrets.ldb. This created a /etc/krb5.keytab file. However the principal listed there is in the form:

HOST at REALM, rather than host/hostname at REALM.

I have tried renaming HOST at REALM to host/hostname at REALM with ktutil but it does not produce any result. And sshd is still prompting for 
password. From the sshd logs:

debug1: Unspecified GSS failure.  Minor code may provide more information
Key table entry not found

Is there a procedure for generating new principals like imap/xyz at REALM, and putting it into a keytab file?


