After defining and creating the necessary configurations in Address Manager such as creating the Kerberos realm, KDC(s) and DHCP service principal, you must associate the principal with a managed DHCP Server for deployment.
- If you already have a DHCP Server under Address Manager control, edit the DHCP Server properties as described below.
- If you haven't yet added a DHCP Server to Address Manager, you can associate the service principal when adding the server.
To associate the service principal with a DHCP Server:
- From the configuration drop-down menu, select a configuration.
- Select the Servers tab. Tabs remember the page you last worked on, so select the tab again to ensure you're on the Configuration information page.
- Under Servers, click the name of a DHCP Server.
- Click the server name menu and select Edit.
- Under Kerberos Service Principal, select the Enable DHCP Service Principal check box to associate the service principal. When configuring GSS-TSIG, if the Enable DHCP Service Principal check box isn't selected, DHCP service may become unavailable.
- From the Realm and Principal drop-down menus, select the realm and principal defined in the Kerberos configuration..
- Click Update.
This completes all the necessary steps in Address Manager.
Now, you need to deploy the configuration to the managed DHCP server. For GSS-TSIG
configuration, select only DHCP under Services. For details on
how to deploy the configuration data, refer to Performing full deployment.