Kerberos Use Instructions

Last updated: 2023-12-26 14:42:53
This document employs MIT's Kerberos as the KDC service. Presuming the KDC service has been installed and initiated, the utilization of Kerberos initially necessitates the creation of a realm, followed by the addition of pertinent principals for various roles, inclusive of server and client, culminating in the generation of a keytab file.

Create Database

Utilize the kdb5_util command to establish a database, designated for the storage of information pertinent to the principal.
kdb5_util -r EXAMPLE.COM create -s
Initializing database '/var/krb5/principal' for realm 'EXAMPLE.COM'
master key name 'K/M@EXAMPLE.COM'
You will be prompted for the database Master Password.
It is important that you NOT FORGET this password.
Enter KDC database master key: <Type the key>
Re-enter KDC database master key to verify: <Type it again>

Incorporate Principal

kadmin.local
kadmin.local: add_principal -pw testpassword test/host@EXAMPLE.COM

WARNING: no policy specified fortest/host@EXAMPLE.COM; defaulting to no policy
Principal "test/host@EXAMPLE.COM" created.

Generate Keytab File

kadmin.local
kadmin.local: ktadd -k /var/krb5kdc/test.keytab test/host@EXAMPLE.COM

Entry for principal test/host@EXAMPLE.COM with kvno 2, encryption type des3-cbc-sha1 added to keytab WRFILE:/var/krb5kdc/test.keytab.
Herein, we have established a new user: test/host@EXAMPLE.COM, and have positioned this user's key within the /var/krb5kdc/test.keytab file. Please modify the relevant paths in the example code to reflect the actual paths within your project.

Initiate KDC

service krb5-kdc start
* Starting Kerberos KDC krb5kdc

Kinit Authentication

kinit -k -t /etc/krb5.keytab test-client/host@EXAMPLE.COM
Kinit corresponds to the step of acquiring TGT from KDC. It will send a request to the KDC server specified in /etc/krb5.conf. If the TGT request is successful, it can be viewed using klist.
klist
Ticket cache: FILE:/tmp/krb5cc_1000
Default principal: test-client/host@EXAMPLE.COM

Valid starting Expires Service principal
2019-01-15T17:50:25 2019-01-16T17:50:25 krbtgt/EXAMPLE.COM@EXAMPLE.COM
renew until 2019-01-16T00:00:25

Utilization within the Project

Upon successful Kinit authentication, the keytab file can be duplicated onto the server and client servers that require its use, and the corresponding principal can be configured for utilization.