<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Marek Mahut &#187; kerberos</title>
	<atom:link href="http://marek.mahut.sk/blog/tag/kerberos/feed/" rel="self" type="application/rss+xml" />
	<link>http://marek.mahut.sk/blog</link>
	<description></description>
	<lastBuildDate>Tue, 19 Oct 2010 07:56:00 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Multiple host names in a single kerberos key tab</title>
		<link>http://marek.mahut.sk/blog/2008/11/19/multiple-host-names-in-a-single-kerberos-key-tab/</link>
		<comments>http://marek.mahut.sk/blog/2008/11/19/multiple-host-names-in-a-single-kerberos-key-tab/#comments</comments>
		<pubDate>Wed, 19 Nov 2008 12:33:55 +0000</pubDate>
		<dc:creator>marek</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[cluster]]></category>
		<category><![CDATA[fedora]]></category>
		<category><![CDATA[howto]]></category>
		<category><![CDATA[kerberos]]></category>
		<category><![CDATA[linux]]></category>
		<category><![CDATA[rhel]]></category>
		<category><![CDATA[sysadmin]]></category>

		<guid isPermaLink="false">http://marek.mahut.sk/blog/?p=253</guid>
		<description><![CDATA[If you are using clustered service with kerberos, you may want to merge hostnames keytab files to one for simple distribution.

Create host and service principals.

kadmin:  addprinc -randkey host/node1.corp.intranet.lan
kadmin:  addprinc -randkey host/node2.corp.intranet.lan
kadmin:  addprinc -randkey host/node3.corp.intranet.lan
kadmin:  addprinc -randkey host/node4.corp.intranet.lan
kadmin:  addprinc -randkey host/node5.corp.intranet.lan
kadmin:  addprinc -randkey host/node6.corp.intranet.lan
kadmin:  addprinc -randkey host/node7.corp.intranet.lan
kadmin:  addprinc [...]]]></description>
			<content:encoded><![CDATA[<p>If you are using clustered service with kerberos, you may want to merge hostnames keytab files to one for simple distribution.</p>
<ul>
<li>Create host and service principals.</li>
</ul>
<pre style="padding-left: 60px;">kadmin:  addprinc -randkey host/node1.corp.intranet.lan
kadmin:  addprinc -randkey host/node2.corp.intranet.lan
kadmin:  addprinc -randkey host/node3.corp.intranet.lan
kadmin:  addprinc -randkey host/node4.corp.intranet.lan
kadmin:  addprinc -randkey host/node5.corp.intranet.lan
kadmin:  addprinc -randkey host/node6.corp.intranet.lan
kadmin:  addprinc -randkey host/node7.corp.intranet.lan
kadmin:  addprinc -randkey host/node8.corp.intranet.lan
kadmin:  addprinc -randkey HTTP/node1.corp.intranet.lan
kadmin:  addprinc -randkey HTTP/node2.corp.intranet.lan
kadmin:  addprinc -randkey HTTP/node3.corp.intranet.lan
kadmin:  addprinc -randkey HTTP/node4.corp.intranet.lan
kadmin:  addprinc -randkey HTTP/node5.corp.intranet.lan
kadmin:  addprinc -randkey HTTP/node6.corp.intranet.lan
kadmin:  addprinc -randkey HTTP/node7.corp.intranet.lan
kadmin:  addprinc -randkey HTTP/node8.corp.intranet.lan</pre>
<p></p>
<ul>
<li>Save them to only one file (cluster.keytab).</li>
</ul>
<pre style="padding-left: 60px;">kadmin:  ktadd -k /etc/httpd/cluster.keytab host/node1.corp.intranet.lan
kadmin:  ktadd -k /etc/httpd/cluster.keytab host/node2.corp.intranet.lan
kadmin:  ktadd -k /etc/httpd/cluster.keytab host/node3.corp.intranet.lan
kadmin:  ktadd -k /etc/httpd/cluster.keytab host/node4.corp.intranet.lan
kadmin:  ktadd -k /etc/httpd/cluster.keytab host/node5.corp.intranet.lan
kadmin:  ktadd -k /etc/httpd/cluster.keytab host/node6.corp.intranet.lan
kadmin:  ktadd -k /etc/httpd/cluster.keytab host/node7.corp.intranet.lan
kadmin:  ktadd -k /etc/httpd/cluster.keytab host/node8.corp.intranet.lan
kadmin:  ktadd -k /etc/httpd/cluster.keytab HTTP/node1.corp.intranet.lan
kadmin:  ktadd -k /etc/httpd/cluster.keytab HTTP/node2.corp.intranet.lan
kadmin:  ktadd -k /etc/httpd/cluster.keytab HTTP/node3.corp.intranet.lan
kadmin:  ktadd -k /etc/httpd/cluster.keytab HTTP/node4.corp.intranet.lan
kadmin:  ktadd -k /etc/httpd/cluster.keytab HTTP/node5.corp.intranet.lan
kadmin:  ktadd -k /etc/httpd/cluster.keytab HTTP/node6.corp.intranet.lan
kadmin:  ktadd -k /etc/httpd/cluster.keytab HTTP/node7.corp.intranet.lan
kadmin:  ktadd -k /etc/httpd/cluster.keytab HTTP/node8.corp.intranet.lan</pre>
<p></p>
<ul>
<li>As alternative, you can use command ktutil if you already have a bunch of keytab files.</li>
</ul>
<pre style="padding-left: 60px;">ktutil:  rkt /etc/krb5/node1.corp.intranet.lan.keytab
ktutil:  rkt /etc/krb5/node2.corp.intranet.lan.keytab
ktutil:  rkt /etc/krb5/node3.corp.intranet.lan.keytab
ktutil:  rkt /etc/krb5/node4.corp.intranet.lan.keytab
ktutil:  rkt /etc/krb5/node5.corp.intranet.lan.keytab
ktutil:  rkt /etc/krb5/node6.corp.intranet.lan.keytab
ktutil:  rkt /etc/krb5/node7.corp.intranet.lan.keytab
ktutil:  wkt /etc/cluster.keytab</pre>
<p>Voila.</p>
]]></content:encoded>
			<wfw:commentRss>http://marek.mahut.sk/blog/2008/11/19/multiple-host-names-in-a-single-kerberos-key-tab/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>

