Skip to main content
mac987
New Member
November 16, 2020
Question

explicit proxy with ldap and kerberos authentication. Creating the keytab file.

  • November 16, 2020
  • 1 reply
  • 4622 views

Hi Good morning

 

We have a Fortigate 301E running V 6.2.3

 

I have setup explicit proxy and ldap user groups and the last thing i have to configure is the kerberos authentication scheme, i have tried to generate keytab file string as part of the config krb-keytab command but i get the error

 

The keytab is not valid for the principal:???.  ( principal redacted ) object check operator error, -651, discard the setting Command fail. Return code -651

 

I am assuming i have to get the keytab file then encode it, do i do this on the LDAP server ?

 

So create the keytab file on the ldap server

Base 64 encode it

download it into the fortigate

create the keytab file using the previously downloaded keytab file.

 

is that correct or can someone explain how i can generate this keytab file on the fortigate FW ?

 

Thanks for all your valud help

 

kind regards

 

mac

 

 

    1 reply

    Viktor1
    New Member
    November 19, 2020

    Hello. Look at this guide - https://docs.fortinet.com/document/fortigate/6.0.0/handbook/926128/kerberos. Section "1.4 Generate the Kerberos keytab". You can use your domain controlled to do this operation. Then you need to do base64 encoding (using any Unix machine or some online services) and delete all line feeds from it (using a text editor). Then use text from the keytab file as an argument in the keytab command on Fortigate.

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!