17.10 - Replacing Existing Kerberos Keys Compared to Merging Keys - Advanced SQL Engine - Teradata Database

Teradata Vantage™ - Advanced SQL Engine Security Administration

Product
Advanced SQL Engine
Teradata Database
Release Number
17.10
Published
July 2021
Language
English (United States)
Last Update
2022-02-15
dita:mapPath
ppz1593203596223.ditamap
dita:ditavalPath
wrg1590696035526.ditaval
dita:id
zuy1472246340572

If you need to replace existing Kerberos keys with new keys, for example, when site security policy requires periodic key updates, you can overwrite the existing keys during installation.

  1. Install new keys for the first KDC as shown in Initial Installation of Kerberos Keys for the First KDC.
  2. The installation overwrites all key sets in the file for all nodes to which you distribute the keys.
If you have new keys for additional KDCs, install the remaining key sets as shown in Installing Kerberos Keys for Additional KDCs (Merging Keys) to merge the additional key sets with the first replacement set installed in step 1 above.