Exporting service and user principal's to keytab file on KDC
The Authentication Server needs a keytab file and validate a user when refreshing session credentials.
This section describes how to export and copy a keytab file.
- Create oracle service principal.
# kadmin.local addprinc -randkey <oracle SID>/<oracle server host name>@<domain realm name>
For example: addprinc -randkey scdb/abc.example.com@EXAMPLE.COM
- Extract oracle service principal to keytab file
# kadmin.local ktadd -k <keytab file path> <oracle SID>/<oracle server host name>@<domain realm name>
For example: ktadd -k /tmp/keytab scdb/abc.example.com@EXAMPLE.COM
- Create Kerberos user principal
# kadmin.local addprinc <kerberos user name>
For example: addprinc k1portal
- Extract Kerberos user principal to keytab file.
# kadmin.local ktadd -k <keytab file path> <kerberos user name>
For example:ktadd -k /tmp/keytab k1portal