<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>question Re: HDP 2.3/Ambari integration with AD managed by Centrify in Archives of Support Questions (Read Only)</title>
    <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/HDP-2-3-Ambari-integration-with-AD-managed-by-Centrify/m-p/96667#M10199</link>
    <description>&lt;P&gt;Thanks Pardeep !&lt;/P&gt;</description>
    <pubDate>Sun, 08 Nov 2015 05:35:21 GMT</pubDate>
    <dc:creator>hrongali</dc:creator>
    <dc:date>2015-11-08T05:35:21Z</dc:date>
    <item>
      <title>HDP 2.3/Ambari integration with AD managed by Centrify</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/HDP-2-3-Ambari-integration-with-AD-managed-by-Centrify/m-p/96662#M10194</link>
      <description>&lt;P&gt;We need to install a Non-Kerberized HDP 2.3 cluster and below are the requirements:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;There is an existing Active directory maintained by Centrify and all authentication should be done thru that.&lt;/LI&gt;&lt;LI&gt;The service users with custom names are already created in AD under custome group name. &lt;/LI&gt;&lt;LI&gt;We DON'T want ambari to create any local service accounts during HDP installation and want ambari to refer to AD accounts. The main concern is If ambari creates the service accounts locally, then that might mess up group permissions for the files when tried to login with the AD accounts.&lt;/LI&gt;&lt;LI&gt;The requirement is NOT to work with any local accounts and all authentication needs to be done from AD managed by Centrify.&lt;/LI&gt;&lt;LI&gt;From install perspective, what needs to be done to achieve this ?&lt;/LI&gt;&lt;/OL&gt;</description>
      <pubDate>Fri, 06 Nov 2015 22:28:09 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/HDP-2-3-Ambari-integration-with-AD-managed-by-Centrify/m-p/96662#M10194</guid>
      <dc:creator>hrongali</dc:creator>
      <dc:date>2015-11-06T22:28:09Z</dc:date>
    </item>
    <item>
      <title>Re: HDP 2.3/Ambari integration with AD managed by Centrify</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/HDP-2-3-Ambari-integration-with-AD-managed-by-Centrify/m-p/96663#M10195</link>
      <description>&lt;P&gt;@&lt;A href="http://community.hortonworks.com/users/267/hrongali.html"&gt;hrongali@hortonworks.com&lt;/A&gt;&lt;/P&gt;&lt;P&gt;This document will save you lot of headache.  &lt;A target="_blank" href="http://hhttp://community.centrify.com/centrify/attachments/centrify/techblog/37/2/centrify.hortonworks.pdf"&gt;Link&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A target="_blank" href="http://community.centrify.com/centrify/attachments/centrify/Centrify_Server_Suite/20/3/Centrify%20Identity%20and%20Access%20Management%20for%20Hortonworks.pdf"&gt;&lt;/A&gt;Page 12 is the most important. Please feel free to reach out to me anytime.&lt;/P&gt;&lt;P&gt;Adding important information regarding service account&lt;/P&gt;&lt;P&gt;&lt;A target="_blank" href="http://docs.hortonworks.com/HDPDocuments/Ambari-2.1.2.0/bk_ambari_reference_guide/content/_defining_service_users_and_groups_for_a_hdp_2x_stack.html"&gt;link&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Use the &lt;CODE&gt;Skip Group Modifications&lt;/CODE&gt; option to not modify the Linux groups in the cluster. Choosing this option is typically required if your environment manages groups using LDAP and not on the local Linux machines.&lt;/P&gt;</description>
      <pubDate>Fri, 06 Nov 2015 22:34:50 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/HDP-2-3-Ambari-integration-with-AD-managed-by-Centrify/m-p/96663#M10195</guid>
      <dc:creator>nsabharwal</dc:creator>
      <dc:date>2015-11-06T22:34:50Z</dc:date>
    </item>
    <item>
      <title>Re: HDP 2.3/Ambari integration with AD managed by Centrify</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/HDP-2-3-Ambari-integration-with-AD-managed-by-Centrify/m-p/96664#M10196</link>
      <description>&lt;P&gt;&lt;A rel="user" href="https://community.cloudera.com/users/267/hrongali.html" nodeid="267"&gt;@hrongali@hortonworks.com&lt;/A&gt;&lt;/P&gt;&lt;P&gt;I recently did the same. Below are quick notes and pointers to do that.&lt;/P&gt;&lt;P&gt; To use existing the Centrify Active Directory to configure security on an HDP cluster, please refer the the following document reference below covering the Centrify configuration to work with a Hortonwork environment.&lt;/P&gt;&lt;P&gt;&lt;A target="_blank" href="http://community.centrify.com/centrify/attachments/centrify/techblog/37/2/centrify.hortonworks.pdf"&gt;Centrify for Hortonworks (Ambari 2.x)&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A target="_blank" href="http://community.centrify.com/centrify/attachments/centrify/techblog/22/3/Centrify%20Identity%20and%20Access%20Management%20for%20Hortonworks.pdf"&gt;Centrify for Hortonworks (Ambari 1.x)&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://community.centrify.com/centrify/attachments/centrify/Centrify_Server_Suite/38/2/centrify.hortonworks.pdf"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Note:&lt;/STRONG&gt; To enable Centrify to work correctly with Hortonworks, please make the following changes. (A few notes captured from earlier engagements including some gotchas)&lt;/P&gt;&lt;P&gt;1. Add ksh link (other wise AD profiles with ksh will fail login)&lt;/P&gt;&lt;P&gt;ln -s /bin/ksh93 /usr/bin/ksh&lt;/P&gt;&lt;P&gt;2. Edit /etc/krb5.conf file with these settings:&lt;/P&gt;&lt;P&gt;Forwarding=true&lt;/P&gt;&lt;P&gt;Renew=7d&lt;/P&gt;&lt;P&gt;3. Remove HTTP principle from SPN attribute of compute object in Active Directory:&lt;/P&gt;&lt;UL&gt;
&lt;LI&gt;1. On each node: &lt;/LI&gt;&lt;LI&gt;a. Edit /etc/centrifydc/centrifydc.conf and on line 1092, delete the "# " from the front of line and remove "http" from the list so that it looks like this: &lt;/LI&gt;&lt;LI&gt;
&lt;/LI&gt;&lt;LI&gt;adclient.krb5.service.principals: ftp cifs nfs &lt;/LI&gt;&lt;LI&gt;Changed by (remove nfs also) &lt;A rel="user" href="https://community.cloudera.com/users/369/amcbarnett.html" nodeid="369"&gt;@Ancil McBarnett&lt;/A&gt; &lt;/LI&gt;
&lt;LI&gt;&lt;PRE&gt;adclient.krb5.service.principals: ftp cifs &lt;/PRE&gt;
&lt;/LI&gt;&lt;LI&gt;b. Save the file and restart the Centrify Agent. &lt;/LI&gt;
&lt;LI&gt;&lt;PRE&gt;adreload
service centrifydc restart&lt;/PRE&gt;
&lt;/LI&gt;&lt;LI&gt;2. In Active Directory Users and Computers,do a ADSI Edit (Active Directory® Service Interfaces Editor (&lt;EM&gt;ADSI Edit&lt;/EM&gt;) ) then navigate to the container where the computer objects for the cluster's nodes have been created. &lt;/LI&gt;&lt;LI&gt;3. In each computer object, remove the HTTP principal from SPN attribute. &lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;4. Make sure you have AD account existing for Ambari server if you want to use non-root user existing in AD for Ambari Server. &lt;/P&gt;&lt;P&gt;To configure Ambari
for a non-root based user, please refer to the following link.&lt;/P&gt;&lt;P&gt;&lt;A href="http://docs.hortonworks.com/HDPDocuments/Ambari-2.1.2.0/bk_Ambari_Security_Guide/content/_configuring_ambari_for_non-root.html"&gt;http://docs.hortonworks.com/HDPDocuments/Ambari-2.1.2.0/bk_Ambari_Security_Guide/content/_configuring_ambari_for_non-root.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Note:&lt;/STRONG&gt; Add ulimit
command to the list of sudo commands besides those mentioned in Hortonworks
documents as Ambari tries to modify ulimits during the HDP services installation
using an Ambari user, otherwise it just keeps complaining about the same.&lt;/P&gt;&lt;P&gt;5. For customizing or using services users from AD, make sure all accounts are already created in AD. Make sure all machines are added to AD. And as &lt;A rel="user" href="https://community.cloudera.com/users/140/nsabharwal.html" nodeid="140"&gt;@Neeraj&lt;/A&gt; mentioned in above answer, Use the &lt;CODE&gt;Skip Group Modifications&lt;/CODE&gt; option to not modify the Linux users/groups in the cluster. Choosing this option is typically required if your environment manages groups using LDAP and not on the local Linux machines or already existing ones. &lt;/P&gt;&lt;P&gt;6. Make sure to change all the user's (Users for Ambari and HDP services) password policy in Active Directory from "User must change password at next logon" to "Password never expires"&lt;/P&gt;&lt;P&gt;7. Then refer to the following site to setup Kerberos in an HDP
Cluster.&lt;/P&gt;&lt;P&gt;&lt;A href="http://docs.hortonworks.com/HDPDocuments/Ambari-2.1.2.0/bk_Ambari_Security_Guide/content/ch_configuring_amb_hdp_for_kerberos.html"&gt;http://docs.hortonworks.com/HDPDocuments/Ambari-2.1.2.0/bk_Ambari_Security_Guide/content/ch_configuring_amb_hdp_for_kerberos.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Note: &lt;/STRONG&gt;Ensure Unlimited JCE policy is installed if using Oracle JDK else Test KD connection will fail on Enable Kerberos Wizard. &lt;/P&gt;&lt;P&gt;Reach out to me for any further detail.&lt;/P&gt;</description>
      <pubDate>Sat, 07 Nov 2015 10:10:38 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/HDP-2-3-Ambari-integration-with-AD-managed-by-Centrify/m-p/96664#M10196</guid>
      <dc:creator>pardeep_kumar</dc:creator>
      <dc:date>2015-11-07T10:10:38Z</dc:date>
    </item>
    <item>
      <title>Re: HDP 2.3/Ambari integration with AD managed by Centrify</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/HDP-2-3-Ambari-integration-with-AD-managed-by-Centrify/m-p/96665#M10197</link>
      <description>&lt;P&gt;&lt;A rel="user" href="https://community.cloudera.com/users/139/pardeepkumar.html" nodeid="139"&gt;@Pardeep&lt;/A&gt; thanks for sharing!&lt;/P&gt;</description>
      <pubDate>Sat, 07 Nov 2015 10:55:12 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/HDP-2-3-Ambari-integration-with-AD-managed-by-Centrify/m-p/96665#M10197</guid>
      <dc:creator>nsabharwal</dc:creator>
      <dc:date>2015-11-07T10:55:12Z</dc:date>
    </item>
    <item>
      <title>Re: HDP 2.3/Ambari integration with AD managed by Centrify</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/HDP-2-3-Ambari-integration-with-AD-managed-by-Centrify/m-p/96666#M10198</link>
      <description>&lt;P&gt;Pardeep, thanks for detailed notes, helpful.&lt;/P&gt;</description>
      <pubDate>Sat, 07 Nov 2015 13:36:28 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/HDP-2-3-Ambari-integration-with-AD-managed-by-Centrify/m-p/96666#M10198</guid>
      <dc:creator>skonduru</dc:creator>
      <dc:date>2015-11-07T13:36:28Z</dc:date>
    </item>
    <item>
      <title>Re: HDP 2.3/Ambari integration with AD managed by Centrify</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/HDP-2-3-Ambari-integration-with-AD-managed-by-Centrify/m-p/96667#M10199</link>
      <description>&lt;P&gt;Thanks Pardeep !&lt;/P&gt;</description>
      <pubDate>Sun, 08 Nov 2015 05:35:21 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/HDP-2-3-Ambari-integration-with-AD-managed-by-Centrify/m-p/96667#M10199</guid>
      <dc:creator>hrongali</dc:creator>
      <dc:date>2015-11-08T05:35:21Z</dc:date>
    </item>
    <item>
      <title>Re: HDP 2.3/Ambari integration with AD managed by Centrify</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/HDP-2-3-Ambari-integration-with-AD-managed-by-Centrify/m-p/96668#M10200</link>
      <description>&lt;P&gt;&lt;A rel="user" href="https://community.cloudera.com/users/267/hrongali.html" nodeid="267"&gt;@hrongali@hortonworks.com&lt;/A&gt;  Please do update the thread in case you find anything new &lt;/P&gt;</description>
      <pubDate>Sun, 08 Nov 2015 05:44:42 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/HDP-2-3-Ambari-integration-with-AD-managed-by-Centrify/m-p/96668#M10200</guid>
      <dc:creator>nsabharwal</dc:creator>
      <dc:date>2015-11-08T05:44:42Z</dc:date>
    </item>
  </channel>
</rss>

