Create a keytab for the LDAP bind user account that is used to access and search Active Directory during LDAP synchronization.
Structure the value for the -princ option as <principal name>@<KERBEROS REALM>. Include the name of the LDAP configuration for the Active Directory server in the keytab file name. Structure the keytab file name as follows: <Active Directory LDAP configuration_name>.keytab.
The following example creates a keytab file for a service principal user account named ldapuser: