When using Kerberos, the domain controller is the key distribution center (KDC) for the Kerberos Realm. In a pure Windows 2003 environment, a Kerberos Realm is equivalent to a Windows Domain. The domain controller host provides storage for the user, service accounts, credentials, the Kerberos ticketing services, and Windows Domain services.
A keytab file is required for Kerberos authentication, which lets users logged on to the Federation Manager server authenticate with the KDC without being prompted for a password. The keytab file is created with the ktpass utility. The ktpass command tool utility is a Windows support tool. The default encryption type is RC4-HMAC-NT, which can be confirmed by running ktpass /? at the command prompt. Also, be sure to confirm the Kerberos version number.
To deploy the Windows domain controller when using Kerberos
Use the password entered in step 4.
Important! The keytab name with its full path must be specified in the Keytab Location field during the Federation Manager Windows Agent configuration.
The domain controller is deployed for Kerberos on systems running Windows.
| Copyright © 2011 CA. All rights reserved. | Email CA Technologies about this topic |