<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>question Re: Failed to enable Kerberos using Direct Active Directory using CDH 5.9.0 in Support Questions</title>
    <link>https://community.cloudera.com/t5/Support-Questions/Failed-to-enable-Kerberos-using-Direct-Active-Directory/m-p/48784#M44039</link>
    <description>&lt;P&gt;Found this useful link:&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.cloudera.com/documentation/enterprise/latest/topics/cm_sg_s3_cm_principal.html" target="_blank"&gt;https://www.cloudera.com/documentation/enterprise/latest/topics/cm_sg_s3_cm_principal.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you are using Active Directory:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Create an Organizational Unit (OU) in your AD setup where all the principals used by your CDH cluster will reside.&lt;/LI&gt;&lt;LI&gt;Add a new user account to Active Directory, for example, &amp;lt;username&amp;gt;@YOUR-REALM.COM. The password for this user should be set to never expire.&lt;/LI&gt;&lt;LI&gt;Use AD's Delegate Control wizard to allow this new user to &lt;STRONG&gt;Create, Delete and Manage User Accounts&lt;/STRONG&gt;.&lt;/LI&gt;&lt;/OL&gt;</description>
    <pubDate>Fri, 23 Dec 2016 20:07:32 GMT</pubDate>
    <dc:creator>zhuw.bigdata</dc:creator>
    <dc:date>2016-12-23T20:07:32Z</dc:date>
    <item>
      <title>Failed to enable Kerberos using Direct Active Directory using CDH 5.9.0</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Failed-to-enable-Kerberos-using-Direct-Active-Directory/m-p/48332#M44038</link>
      <description>&lt;P&gt;Reference:&lt;/P&gt;&lt;DIV&gt;&lt;FONT color="#323333" face="Helvetica Neue"&gt;&lt;SPAN&gt;&lt;A href="http://www.cloudera.com/documentation/enterprise/latest/topics/sg_auth_overview.html#concept_zkr_5h2_bt" target="_blank"&gt;&lt;FONT&gt;http://www.cloudera.com/documentation/enterprise/latest/topics/sg_auth_overview.html#concept_zkr_5h2_bt&lt;/FONT&gt;&lt;/A&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;A href="http://www.cloudera.com/documentation/enterprise/latest/topics/cm_sg_intro_kerb.html" target="_blank"&gt;&lt;FONT&gt;http://www.cloudera.com/documentation/enterprise/latest/topics/cm_sg_intro_kerb.html&lt;/FONT&gt;&lt;/A&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;A href="http://blog.cloudera.com/blog/2014/07/new-in-cloudera-manager-5-1-direct-active-directory-integration-for-kerberos-authentication/" target="_blank"&gt;http://blog.cloudera.com/blog/2014/07/new-in-cloudera-manager-5-1-direct-active-directory-integration-for-kerberos-authentication/&lt;/A&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;My question is how to configure AD OU admin user. This user has to have permissions to modify LDAP also. I just can't find anything on this. I got permission denied on ldapadd when generating the keytabs. Could someone help me on how to set this user up in both AD domain&amp;nbsp; and AD LDAP?&lt;/DIV&gt;</description>
      <pubDate>Tue, 06 Dec 2016 04:05:37 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Failed-to-enable-Kerberos-using-Direct-Active-Directory/m-p/48332#M44038</guid>
      <dc:creator>zhuw.bigdata</dc:creator>
      <dc:date>2016-12-06T04:05:37Z</dc:date>
    </item>
    <item>
      <title>Re: Failed to enable Kerberos using Direct Active Directory using CDH 5.9.0</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Failed-to-enable-Kerberos-using-Direct-Active-Directory/m-p/48784#M44039</link>
      <description>&lt;P&gt;Found this useful link:&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.cloudera.com/documentation/enterprise/latest/topics/cm_sg_s3_cm_principal.html" target="_blank"&gt;https://www.cloudera.com/documentation/enterprise/latest/topics/cm_sg_s3_cm_principal.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you are using Active Directory:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Create an Organizational Unit (OU) in your AD setup where all the principals used by your CDH cluster will reside.&lt;/LI&gt;&lt;LI&gt;Add a new user account to Active Directory, for example, &amp;lt;username&amp;gt;@YOUR-REALM.COM. The password for this user should be set to never expire.&lt;/LI&gt;&lt;LI&gt;Use AD's Delegate Control wizard to allow this new user to &lt;STRONG&gt;Create, Delete and Manage User Accounts&lt;/STRONG&gt;.&lt;/LI&gt;&lt;/OL&gt;</description>
      <pubDate>Fri, 23 Dec 2016 20:07:32 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Failed-to-enable-Kerberos-using-Direct-Active-Directory/m-p/48784#M44039</guid>
      <dc:creator>zhuw.bigdata</dc:creator>
      <dc:date>2016-12-23T20:07:32Z</dc:date>
    </item>
  </channel>
</rss>

