Show Table of Contents
29.3. Protecting Keytabs
To protect Kerberos keytabs from other users with access to the server, restrict access to the keytab to only the keytab owner. It is recommended to protect the keytabs right after they are retrieved.
For example, to protect the Apache keytab at
/etc/httpd/conf/ipa.keytab:
- Set the owner of the file to
apache.#
chown apache /etc/httpd/conf/ipa.keytab - Set the permissions for the file to
0600. This grants read, write, and execute permissions to the owner.#
chmod 0600 /etc/httpd/conf/ipa.keytab

Where did the comment section go?
Red Hat's documentation publication system recently went through an upgrade to enable speedier, more mobile-friendly content. We decided to re-evaluate our commenting platform to ensure that it meets your expectations and serves as an optimal feedback mechanism. During this redesign, we invite your input on providing feedback on Red Hat documentation via the discussion platform.