28726
DISCUSSIONS
101724
MEMBERS
3157
ARTICLES
Created 08-09-2016 11:43 AM
Hello,
We currently have an 10-node Cloudera instance up and running. We would like to secure it with an already-existing FreeIPA instance we have, but are uncomfortable with giving Cloudera a service principal account with account creation and changepw features (especially since the OS on the nodes is already secured via FreeIPA).
Is there a way to enable Kerberos (via FreeIPA) with Cloudera Express without having to grant the service principal those permissions?