Description
SPNEGO based Web Authentication uses HTTP/fqdn@REALM as the kerberos principal for each host.
Since it is difficult to modify the config for each host, a substitution feature where _HOST gets replaced by fqdn is implemented.
The task is to provide similar feature for the kerberos principals used for SPNEGO principals