explicit proxy with ldap and kerberos authentication. Creating the keytab file.
Hi Good morning
We have a Fortigate 301E running V 6.2.3
I have setup explicit proxy and ldap user groups and the last thing i have to configure is the kerberos authentication scheme, i have tried to generate keytab file string as part of the config krb-keytab command but i get the error
The keytab is not valid for the principal:???. ( principal redacted ) object check operator error, -651, discard the setting Command fail. Return code -651
I am assuming i have to get the keytab file then encode it, do i do this on the LDAP server ?
So create the keytab file on the ldap server
Base 64 encode it
download it into the fortigate
create the keytab file using the previously downloaded keytab file.
is that correct or can someone explain how i can generate this keytab file on the fortigate FW ?
Thanks for all your valud help
kind regards
mac
