Test network authentication service

You should test the network authentication service configuration by requesting a ticket granting ticket for your i5/OS™ principal and other principals within your network.
Note: Be sure you have created a home directory for your i5/OS user profile before performing this test.
To test the network authentication service configuration, follow these steps:
  1. On a command line, enter QSH to start the Qshell Interpreter.
  2. Enter keytab list to display a list of principals registered in the keytab file. The following results should display:
    Principal: krbsvr400/iseriesa.myco.com@MYCO.COM      
      Key version: 2                                                       
      Key type: 56-bit DES using key derivation                            
      Entry timestamp: 200X/05/29-11:02:58                                 
  3. Enter kinit -k krbsvr400/iseriesa.myco.com@MYCO.COM to request a ticket-granting ticket from the Kerberos server. This command verifies that your iSeries™ server has been configured properly and the password in the keytab file matches the password stored on the Kerberos server. If this is successful then the QSH command will display without errors.
  4. Enter klist to verify that the default principal is krbsvr400/iseriesa.myco.com@MYCO.COM. This command displays the contents of a Kerberos credentials cache and verifies that a valid ticket has been created for the i5/OS service principal and placed within the credentials cache on the iSeries system.
     Ticket cache: FILE:/QIBM/USERDATA/OS400/NETWORKAUTHENTICATION/creds/krbcred
                                                                        
     Default principal: krbsvr400/iseriesa.myco.com@MYCO.COM  
                                                                                
    Server: krbtgt/MYCO.COM@MYCO.COM              
      Valid 200X/06/09-12:08:45 to 20XX/11/05-03:08:45                          
    $                                                                           
You have completed the steps required to configure your iSeries server to be a Kerberos server and you can use Kerberos to authenticate the users in the MYCO.COM realm.