Add the i5/OS™ principals to a Kerberos server in i5/OS PASE or a Windows® 2000 domain.
After you configure network authentication service on your iSeries™, you must add your i5/OS principals to the Kerberos server. Network authentication service provides an i5/OS principal name, krbsvr400 for the server and the i5/OS applications. The name of the principal that represents i5/OS is krbsrv400/iSeries host name@REALM NAME, where iSeries host name is either the fully qualified host name or the short host name for the iSeries server. This principal name needs to be added to the Kerberos server so that Kerberos client applications can request and receive service tickets. For example, in our configuration scenarios, the administrator for MyCo added the service principal krbsvr400/iseriesa.myco.com@MYCO.COM to the company's Kerberos server.
Depending on the operating system on which you have configured a Kerberos server, the steps for adding the i5/OS principal are different. This information provides instructions on adding the i5/OS principals to a Kerberos server in i5/OS PASE or a Windows 2000 domain. If you have optionally created service principals for either IBM® Directory Server for iSeries (LDAP), iSeries NetServer™, or HTTP server you must also add those service principals to the Kerberos server.