<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>question Re: Kerberized Clusters - Can you have multiple keytabs in AD using same principal name on different hosts. in Support Questions</title>
    <link>https://community.cloudera.com/t5/Support-Questions/Kerberized-Clusters-Can-you-have-multiple-keytabs-in-AD/m-p/221213#M183087</link>
    <description>&lt;P&gt;Please provide information on how you are generating and defining your keytabs.&lt;/P&gt;&lt;P&gt;try klist -k nifi-1-service-keytab&lt;/P&gt;&lt;P&gt;If you principals have HOST (machine name or IP) as part of the definition like xxxx/HOST_NAME@domain you will not be able to use the keytab on any other machine.&lt;/P&gt;&lt;P&gt;Renaming the keytab will not work as content of the file still point to a specific host.&lt;/P&gt;&lt;P&gt;It is best practice to have separate keytab for separate machines. Reusing the same keytab is not the most secure option.&lt;/P&gt;&lt;P&gt;Alternatively, if you define a principal in AD as headless that is without HOST attribute. And then create a keytab, that keytab can be used on any host typically this is your hdfs principal. But, not too secure.&lt;/P&gt;</description>
    <pubDate>Fri, 05 May 2017 00:45:12 GMT</pubDate>
    <dc:creator>umair_khan</dc:creator>
    <dc:date>2017-05-05T00:45:12Z</dc:date>
  </channel>
</rss>

