, , Windows Active Directory? , "ktpass", , Windows. , , Active Directory - abc.com, Kerberos - ABC.COM.
- keytab, SPN (, Kerberos), SPN , SPNs.
- Kerberos keytab. , . SSB Kerberos . Kerberos "/mapUser". , .
- , DES. . , , .
- "setspn -a" SPN , "setspn -s", "-s" SPN, "-a" - (. "setspn -s" vs. "setspn -a" ).
- , - SPN (.. dummy.abc.com, ). , NTLM Kerberos, .
- , DNS Kerberos, Kerberos DNS ( /etc/krb 5.conf, UNIX/Linux Windows , C:\Windows\krb5.ini, ), Kerberos SPN "setspn -a" "setspn -s", Kerberos.
, , , , :
setspn -a CS/dummy dummyuser
:
setspn -s CS/dummy.abc.com dummyuser
keytab, DES, .
ktpass +rndPass -out dummy.1.keytab -princ CS/dummy.abc.com@ABC.COM -crypto DES-CBC-MD5 +DumpSalt -ptype KRB5_NT_PRINCIPAL +desOnly /mapOp set /mapUser dummyuser@ABC.COM