Search

5.2. Exporting Keytab

download PDF
Once you have created the user account for the application server, use the Ktpass utility to map the SPN account as a trusted host and export the keytab for the server:
  1. Issue the ktpass command to map the created user as a trusted host and generate the keytab file. The -princ option defines the service principal that is being mapped to and the -mapuser option defines the user account being mapped to.
     ktpass -princ <service principal mapping> -out <target keytab file> -pass * -mapuser <user mapping> 

    Example 5.1. ktpass command

     ktpass -princ host/testserver@kerberos.jboss.org -out C:\testeserver.host.keytab -pass * -mapuser KERBEROS\testserver 
  2. When prompted, enter the user password.
  3. Issue the following command to display the available mappings and check if the new mapping is enlisted:
     setspn.exe -l <user mapping> 

    Example 5.2. setspn command

     setspn.exe -l testserver 
Red Hat logoGithubRedditYoutubeTwitter

Learn

Try, buy, & sell

Communities

About Red Hat Documentation

We help Red Hat users innovate and achieve their goals with our products and services with content they can trust.

Making open source more inclusive

Red Hat is committed to replacing problematic language in our code, documentation, and web properties. For more details, see the Red Hat Blog.

About Red Hat

We deliver hardened solutions that make it easier for enterprises to work across platforms and environments, from the core datacenter to the network edge.

© 2024 Red Hat, Inc.