Host Principal for PAM
Some references that without it, PAM can’t
verify Kerberos server
Support
Red Hat’s pam_krb5 supports it
keytab and required_tgs config options
No evidence that RH does anything different when
configured to use it
No evidence that SEAM support it