Authentication method compatible with MIT Kerberos

The Kerberos server in the EMR cluster is started at the master node on Alibaba Cloud E-MapReduce, I performed some management operations with the root account of the master node (emr-header-1).

I test accessing to HDFS service to introduce the relevant procedure as follows:

Executed hadoop fs -ls / on the Gateway

Configure krb5.conf

  Use root account on the Gateway
  scp root@emr-header-1:/etc/krb5.conf /etc/

How can I add principal and export the keytab file using admin tool in Kerberos

I appreciate any assistance with this.