This document employs MIT's Kerberos as the KDC service. Presuming the KDC service has been installed and initiated, the utilization of Kerberos initially necessitates the creation of a realm, followed by the addition of pertinent principals for various roles, inclusive of server and client, culminating in the generation of a keytab file.
Create Database
Utilize the
kdb5_util command to establish a database, designated for the storage of information pertinent to the principal.kdb5_util -r EXAMPLE.COM create -sInitializing database '/var/krb5/principal' for realm 'EXAMPLE.COM'master key name 'K/M@EXAMPLE.COM'You will be prompted for the database Master Password.It is important that you NOT FORGET this password.Enter KDC database master key: <Type the key>Re-enter KDC database master key to verify: <Type it again>
Incorporate Principal
kadmin.localkadmin.local: add_principal -pw testpassword test/host@EXAMPLE.COMWARNING: no policy specified fortest/host@EXAMPLE.COM; defaulting to no policyPrincipal "test/host@EXAMPLE.COM" created.
Generate Keytab File
kadmin.localkadmin.local: ktadd -k /var/krb5kdc/test.keytab test/host@EXAMPLE.COMEntry for principal test/host@EXAMPLE.COM with kvno 2, encryption type des3-cbc-sha1 added to keytab WRFILE:/var/krb5kdc/test.keytab.
Herein, we have established a new user: test/host@EXAMPLE.COM, and have positioned this user's key within the
/var/krb5kdc/test.keytab file. Please modify the relevant paths in the example code to reflect the actual paths within your project.Initiate KDC
service krb5-kdc start* Starting Kerberos KDC krb5kdc
Kinit Authentication
kinit -k -t /etc/krb5.keytab test-client/host@EXAMPLE.COM
Kinit corresponds to the step of acquiring TGT from KDC. It will send a request to the KDC server specified in
/etc/krb5.conf. If the TGT request is successful, it can be viewed using klist.klistTicket cache: FILE:/tmp/krb5cc_1000Default principal: test-client/host@EXAMPLE.COMValid starting Expires Service principal2019-01-15T17:50:25 2019-01-16T17:50:25 krbtgt/EXAMPLE.COM@EXAMPLE.COMrenew until 2019-01-16T00:00:25
Utilization within the Project
Upon successful Kinit authentication, the keytab file can be duplicated onto the server and client servers that require its use, and the corresponding principal can be configured for utilization.