Forum Discussion
Kerberos Authentication with End-User Logons KeyTab files
Greetings,
When configuring APM for Kerberos Auth with End-User logons a keytab file must be generated and uploaded to the Big IP. Does a keytab file need to be created for each application? My first instinct is that it should indeed be created for each app. Can anyone validate or invalidate that? Thanks.
2 Replies
You can add multiple principal's to the same keytab file.
Or you could have one SAML IdP virtual server with Kerberos Auth and all you app's behind SAML SP virtual servers. You would only need a keytab file for the IdP Virtual server and you can add as many SP virtual servers as needed (so there is no need to create a new keytab or modify the keytab fill if you add extra applications that need authentication.
Cheers,
Kees
- Angel_Montero
Nimbostratus
Thanks, I appreciate the response. Multiple principals to the same keytab is music to my ears. In addition, I will be moving to the SAML IDP eventually. However, that is a bit down the road.
Angel
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com