Generate the KCD keytab script
To generate the KCD keytab script by using the configuration utility
-
Navigate to Security > AAA - Application Traffic.
-
In the details pane, under Kerberos Constrained Delegation, click Batch file to generate keytab.
-
In the Generate KCD (Kerberos Constrained Delegation) Keytab Script dialog box, fill out the fields as described below.
-
Domain User Name: The name of the domain user.
-
Domain Password: The password for the domain user.
-
Service Principal: The service principal.
-
Output File Name: A filename for the KCD script file.
-
Create Domain User Account: Select this check box to create the specified domain user account.
-
-
Click Generate Script to generate the script. The script is generated, and appears in the Generated Script text box below the Generate Script button.
-
Copy the script, and save it as a file on your AD domain controller. You must now run this script on the domain controller to generate the keytab file, and then copy the keytab file to the /nsconfig/krb/ directory on the NetScaler appliance.
-
Click OK.