There are two tools that can check the consistency of the Kerberos configuration file and the Kerberos database.
The Kerberos configuration file is checked using verify_krb5_conf. The tool checks for common errors, but commonly there are several uncommon configuration entries that are never added to the tool and thus generates “unknown entry” warnings. This is usually nothing to worry about.
The database check is built into the kadmin tool. It will check for common configuration error that will cause problems later. Common check are for existence and flags on important principals. The database check by run by the following command :
kadmin -l check REALM.EXAMPLE.ORG