<def-group>
  <definition class="compliance" id="kerberos_disable_no_keytab" version="1">
    {{{ oval_metadata("Check that there is no Kerberos keytab file present in /etc", rule_title=rule_title) }}}
    <criteria>
      <criterion test_ref="test_kerberos_disable_no_keytab"
        comment="Restrict Kerberos operation by removing keytab files" />
    </criteria>
  </definition>

  <unix:file_object id="obj_kerberos_disable_no_keytab" version="1" comment="Default Kerberos keytab file">
    <unix:filepath operation="pattern match">^/etc/.+\.keytab$</unix:filepath>
  </unix:file_object>
  <unix:file_test id="test_kerberos_disable_no_keytab" check="all" check_existence="none_exist" version="1"
    comment="Ensure keytab file does not exist">
    <unix:object object_ref="obj_kerberos_disable_no_keytab"/>
  </unix:file_test>
</def-group>
