HP CIFS Server and Kerberos
115
ftp re-tries with the host principal and the authentication succeeds.
9.3 Examining the Merged krb5.keytab File
CIFS/Samba builds a keytab file using 7 different encryption types for every service principal, and
creates multiple entries for each service principal based upon case (see Chapter 5). This results in
many keys residing in krb5.keytab. When merging krb5.keytab files from multiple systems in a
ServiceGuard cluster, the file becomes even larger. For example, the merged keytab file for these 2
test servers has 364 keys. The ktutil tool (see Chapter 8) can be useful to delete unused keys from
the krb5.keytab file.