Skip to main content
  • Place orders quickly and easily
  • View orders and track your shipping status
  • Create and access a list of your products
  • Manage your Dell EMC sites, products, and product-level contacts using Company Administration.

Dell Chassis Management Controller Version 3.10 for Dell EMC PowerEdge VRTX User's Guide

Generating Kerberos Keytab File

To support the SSO and smart card login authentication, CMC supports Windows Kerberos network. The ktpass tool (available from Microsoft as part of the server installation CD/DVD) is used to create the Service Principal Name (SPN) bindings to a user account and export the trust information into a MIT-style Kerberos keytab file. For more information about the ktpass utility, see the Microsoft Website.

Before generating a keytab file, you must create an Active Directory user account for use with the -mapuser option of the ktpass command. You must use the same name as the CMC DNS name to which you upload the generated keytab file.

To generate a keytab file using the ktpass tool:

  1. Run the ktpass utility on the domain controller (Active Directory server), where you want to map CMC to a user account in Active Directory.
  2. Use the following ktpass command to create the Kerberos keytab file:
    ktpass -princ HTTP/cmcname.domainname.com@DOMAINNAME.COM -mapuser keytabuser -crypto DES-CBC-MD5 -ptype KRB5_NT_PRINCIPAL
                                        -pass * -out c:\krbkeytab
                                     
    • NOTE: The cmcname.domainname.com must be in lower case as required by RFC and the @REALM_NAME must be in uppercase. In addition, CMC supports the DES-CBC-MD5 and AES256–SHA1 types of cryptography for Kerberos authentication.

    A keytab file is generated that must be uploaded to CMC.

    • NOTE: The keytab contains an encryption key and must be kept secure. For more information about the ktpass utility, see the Microsoft Website.

Rate this content

Accurate
Useful
Easy to understand
Was this article helpful?
0/3000 characters
  Please provide ratings (1-5 stars).
  Please provide ratings (1-5 stars).
  Please provide ratings (1-5 stars).
  Please select whether the article was helpful or not.
  Comments cannot contain these special characters: <>()\