Configure Kerberos principals

This section describes how to add Kerberos principals for the intermediary Kerberos service, and back-end Kerberos service for unconstrained credentials delegation using Policy Studio. For more information on working in Policy Studio, see the API Gateway Policy Developer Guide.

  1. In the node tree, click Environment Configuration > External Connections > Kerberos Principals.
  2. Add a new Kerberos principal for the intermediary Kerberos service account as follows:
    • Name: IntermediaryGateway
    • Principal Name: IntermediaryGateway@AXWAY.COM
    • Principal Type: NT_USER_NAME
  3. Add a new Kerberos principal for the back-end Kerberos service account as follows:
    • Name: <Back-end service name> (for example, Back-end Kerberos Service)
    • Principal Name: <Service Principal Name for the back-end service> (for example, HOST/BackEndService.axway.com@AXWAY.COM)
    • Principal Type: NT_USER_NAME

For more details on the fields and options in this configuration window, see Configure Kerberos principals in the API Gateway Policy Developer Guide.

For the next steps, see Configure API Gateway policy.

Related Links