12.2. Delegating Host Management
Hosts are delegated authority over other hosts through the
host-add-managedby
command. This creates a managedby
entry. Once the managedby
entry is created, then the host can retrieve a keytab for the host it has delegated authority over.
- Log in as the admin user.
# kinit admin
- Add the
managedby
entry. For example, this delegates authority over client2 to client1.# ipa host-add-managedby client2.example.com --hosts=client1.example.com
- Obtain a ticket as the host
client1
and then retrieve a keytab forclient2
:# kinit -kt /etc/krb5.keytab host/`hostname` # ipa-getkeytab -s `hostname` -k /tmp/client2.keytab -p host/client2.example.com Keytab successfully retrieved and stored in: /tmp/client2.keytab