<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>question Re: Which is better to create Hadoop accounts in LDAP/AD or locally? in Support Questions</title>
    <link>https://community.cloudera.com/t5/Support-Questions/Which-is-better-to-create-Hadoop-accounts-in-LDAP-AD-or/m-p/166386#M128726</link>
    <description>&lt;P&gt;Yes. Thats correct. &lt;/P&gt;</description>
    <pubDate>Thu, 26 May 2016 23:26:22 GMT</pubDate>
    <dc:creator>ravi1</dc:creator>
    <dc:date>2016-05-26T23:26:22Z</dc:date>
    <item>
      <title>Which is better to create Hadoop accounts in LDAP/AD or locally?</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Which-is-better-to-create-Hadoop-accounts-in-LDAP-AD-or/m-p/166379#M128719</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Which is better to create
Hadoop accounts in LDAP/AD or locally?&lt;/P&gt;</description>
      <pubDate>Wed, 25 May 2016 09:36:47 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Which-is-better-to-create-Hadoop-accounts-in-LDAP-AD-or/m-p/166379#M128719</guid>
      <dc:creator>bandarusridhar1</dc:creator>
      <dc:date>2016-05-25T09:36:47Z</dc:date>
    </item>
    <item>
      <title>Re: Which is better to create Hadoop accounts in LDAP/AD or locally?</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Which-is-better-to-create-Hadoop-accounts-in-LDAP-AD-or/m-p/166380#M128720</link>
      <description>&lt;A rel="user" href="https://community.cloudera.com/users/5746/bandarusridhar1.html" nodeid="5746"&gt;@Sri Bandaru&lt;/A&gt;&lt;P&gt;In ref to kerbeors, it is better to create hadoop accounts locally to avoid sending hadoop internal auth requests to AD and add to the AD load. Setting up hadoop accounts locally in a KDC and setting up one way trust between KDC and AD is the way to go. &lt;/P&gt;</description>
      <pubDate>Wed, 25 May 2016 09:39:31 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Which-is-better-to-create-Hadoop-accounts-in-LDAP-AD-or/m-p/166380#M128720</guid>
      <dc:creator>bsaini</dc:creator>
      <dc:date>2016-05-25T09:39:31Z</dc:date>
    </item>
    <item>
      <title>Re: Which is better to create Hadoop accounts in LDAP/AD or locally?</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Which-is-better-to-create-Hadoop-accounts-in-LDAP-AD-or/m-p/166381#M128721</link>
      <description>&lt;P&gt;&lt;A rel="user" href="https://community.cloudera.com/users/191/bsaini.html" nodeid="191"&gt;@bsaini&lt;/A&gt; &lt;/P&gt;&lt;P&gt;Thanks for your response. May I know which is the best practice for security reason.?&lt;/P&gt;</description>
      <pubDate>Wed, 25 May 2016 21:21:38 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Which-is-better-to-create-Hadoop-accounts-in-LDAP-AD-or/m-p/166381#M128721</guid>
      <dc:creator>bandarusridhar1</dc:creator>
      <dc:date>2016-05-25T21:21:38Z</dc:date>
    </item>
    <item>
      <title>Re: Which is better to create Hadoop accounts in LDAP/AD or locally?</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Which-is-better-to-create-Hadoop-accounts-in-LDAP-AD-or/m-p/166382#M128722</link>
      <description>&lt;P&gt;For ease of use, local KDC for hadoop service principals and AD for users is the best way. However, you need to secure your local KDC/Kerberos. If you can secure that, there is no reason not to use local KDC for hadoop service principals. &lt;/P&gt;&lt;P&gt;You may run into security policies that do not allow local kerberos instances. You may also run into policies where you won't get AD credentials that have permissions to create principals in an OU on AD. This will be required if you want ambari to directly create principals for you. &lt;/P&gt;&lt;P&gt;So, which one to go with is entirely dependent on company security policies. &lt;/P&gt;</description>
      <pubDate>Thu, 26 May 2016 00:57:38 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Which-is-better-to-create-Hadoop-accounts-in-LDAP-AD-or/m-p/166382#M128722</guid>
      <dc:creator>ravi1</dc:creator>
      <dc:date>2016-05-26T00:57:38Z</dc:date>
    </item>
    <item>
      <title>Re: Which is better to create Hadoop accounts in LDAP/AD or locally?</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Which-is-better-to-create-Hadoop-accounts-in-LDAP-AD-or/m-p/166383#M128723</link>
      <description>&lt;P&gt;&lt;A rel="user" href="#"&gt;@Ravi Mutyala&lt;/A&gt; &lt;/P&gt;&lt;P&gt;Thanks Ravi, If I got for local accounts like HDFS etc.., will the UID will same for all the machines with respect to that user? If I have to add a new machine how will that UID will effect?&lt;/P&gt;</description>
      <pubDate>Thu, 26 May 2016 03:18:26 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Which-is-better-to-create-Hadoop-accounts-in-LDAP-AD-or/m-p/166383#M128723</guid>
      <dc:creator>bandarusridhar1</dc:creator>
      <dc:date>2016-05-26T03:18:26Z</dc:date>
    </item>
    <item>
      <title>Re: Which is better to create Hadoop accounts in LDAP/AD or locally?</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Which-is-better-to-create-Hadoop-accounts-in-LDAP-AD-or/m-p/166384#M128724</link>
      <description>&lt;P&gt;Its not essential for all local accounts to have the same UID though this will help with easier maintenance. If you let ambari create your local accounts, then you may not get the same UIDs for local users across all nodes. If you want to get same UIDs, its better you manage create local users as part of your server configuration management process (like puppet/chef if you have one). &lt;/P&gt;</description>
      <pubDate>Thu, 26 May 2016 03:53:15 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Which-is-better-to-create-Hadoop-accounts-in-LDAP-AD-or/m-p/166384#M128724</guid>
      <dc:creator>ravi1</dc:creator>
      <dc:date>2016-05-26T03:53:15Z</dc:date>
    </item>
    <item>
      <title>Re: Which is better to create Hadoop accounts in LDAP/AD or locally?</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Which-is-better-to-create-Hadoop-accounts-in-LDAP-AD-or/m-p/166385#M128725</link>
      <description>&lt;P&gt;&lt;A rel="user" href="https://community.cloudera.com/users/216/ravi.html"&gt;@Ravi Mutyala&lt;/A&gt; &lt;/P&gt;&lt;P&gt;Got you, Ravi. Hadoop will run on the name but not on the UID. Whatever that UID it might be Hadoop doesn't care in the processing/operations.&lt;/P&gt;</description>
      <pubDate>Thu, 26 May 2016 23:19:48 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Which-is-better-to-create-Hadoop-accounts-in-LDAP-AD-or/m-p/166385#M128725</guid>
      <dc:creator>bandarusridhar1</dc:creator>
      <dc:date>2016-05-26T23:19:48Z</dc:date>
    </item>
    <item>
      <title>Re: Which is better to create Hadoop accounts in LDAP/AD or locally?</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Which-is-better-to-create-Hadoop-accounts-in-LDAP-AD-or/m-p/166386#M128726</link>
      <description>&lt;P&gt;Yes. Thats correct. &lt;/P&gt;</description>
      <pubDate>Thu, 26 May 2016 23:26:22 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Which-is-better-to-create-Hadoop-accounts-in-LDAP-AD-or/m-p/166386#M128726</guid>
      <dc:creator>ravi1</dc:creator>
      <dc:date>2016-05-26T23:26:22Z</dc:date>
    </item>
    <item>
      <title>Re: Which is better to create Hadoop accounts in LDAP/AD or locally?</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Which-is-better-to-create-Hadoop-accounts-in-LDAP-AD-or/m-p/166387#M128727</link>
      <description>&lt;P&gt;&lt;A rel="user" href="https://community.cloudera.com/users/216/ravi.html" nodeid="216"&gt;@Ravi Mutyala&lt;/A&gt; &lt;A rel="user" href="https://community.cloudera.com/users/5746/bandarusridhar1.html" nodeid="5746"&gt;@Sridhar Reddy&lt;/A&gt;; Can we create no-login service accounts in AD? or, should they be a login accounts? &lt;/P&gt;</description>
      <pubDate>Thu, 04 Apr 2019 10:36:00 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Which-is-better-to-create-Hadoop-accounts-in-LDAP-AD-or/m-p/166387#M128727</guid>
      <dc:creator>bharathk</dc:creator>
      <dc:date>2019-04-04T10:36:00Z</dc:date>
    </item>
    <item>
      <title>Re: Which is better to create Hadoop accounts in LDAP/AD or locally?</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Which-is-better-to-create-Hadoop-accounts-in-LDAP-AD-or/m-p/166388#M128728</link>
      <description>&lt;P&gt;&lt;A rel="user" href="https://community.cloudera.com/users/112462/maildevops.html" nodeid="112462"&gt;@Bharath Kumar&lt;/A&gt;: Yes, you can create no-login them in AD. Technically, they should be login accounts if you are planning to run some service. That may vary based on the senario &lt;/P&gt;</description>
      <pubDate>Thu, 04 Apr 2019 12:10:16 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Which-is-better-to-create-Hadoop-accounts-in-LDAP-AD-or/m-p/166388#M128728</guid>
      <dc:creator>bandarusridhar1</dc:creator>
      <dc:date>2019-04-04T12:10:16Z</dc:date>
    </item>
  </channel>
</rss>

