Server Configuration > Post Install Server Security > Special Considerations for Kerberos and Kerberos Single Sign On > Specifying Keytab for Kerberos SSO
Specifying Keytab for Kerberos SSO
If you are using the Kerberos SSO authentication domain (Windows SSO security policy), the Windchill RV&S server needs to be able to access secret key information in order to authenticate service tickets received from the client. The Windchill RV&S server can derive its secret key from a keytab file that is specified in the following properties in the file.
To support multiple domains, these properties must be repeated for each child domain, for example:
Only multiple domains within a single forest are supported. Multiple forests are not supported.
Do not supply the domain for The domain is appended by the server during authentication. For example,, not
The root or main domain for the forest should be specified in the default settings. The children should be specified in the other settings, for example:
To create a keytab file