You cannot use DSCC to perform this task. Use the command line, as described in this procedure.
Create the default identity mapping for GSSAPI and any custom mappings as described in GSSAPI Identity Mappings.
Create a keytab to store the service keys.
Your LDAP service key is stored in the keytab.
If you modified the SASL configuration entry or one of the GSSAPI identity mapping entries, restart Directory Server.
Note that the DNS must be configured on the host machine.