<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>question Re: Looking for an automated integration of HDP/Ambari with Kerberos and LDAP in Archives of Support Questions (Read Only)</title>
    <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Looking-for-an-automated-integration-of-HDP-Ambari-with/m-p/108826#M16072</link>
    <description>&lt;P&gt;Yes both AD and IPA provide integrated KDC/LDAP experience which is great for most cases. The problem with FreeIPA is that Ambari doesn't natively support it yet (so you have to use manual option in security wizard where you have to manually create principals/distribute keytabs - &lt;A href="https://issues.apache.org/jira/browse/AMBARI-6432"&gt;JIRA&lt;/A&gt; has been logged on this). But every so often there are customers who require some corner case setup which doesn't work. Am guessing &lt;A rel="user" href="https://community.cloudera.com/users/177/pminovic.html" nodeid="177"&gt;@Predrag Minovic&lt;/A&gt; is running into one of those&lt;/P&gt;</description>
    <pubDate>Sat, 23 Jan 2016 09:21:09 GMT</pubDate>
    <dc:creator>abajwa</dc:creator>
    <dc:date>2016-01-23T09:21:09Z</dc:date>
    <item>
      <title>Looking for an automated integration of HDP/Ambari with Kerberos and LDAP</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Looking-for-an-automated-integration-of-HDP-Ambari-with/m-p/108819#M16065</link>
      <description>&lt;P&gt;After upgrade to Ambari-2.1.2.1 (or 2.2.1) and HDP-2.3.x we are going to add Kerberos and LDAP to the cluster and we are looking for the best, automated solution. Both will run on a RHEL box but we can select components freely. What's the best way to go? I'm aware of&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;FreeIPA, exactly what we want except that it's not supported by Ambari. I don't mind using manual Kerberos wizard but in Ambari-2.1.2 there were some issues on clusters with manually installed Kerberos (like CSV files not appearing when adding new services, issues when adding new nodes etc).&lt;/LI&gt;&lt;LI&gt;KDC and OpenLDAP, KDC is fully supported from Ambari, but not aware of full integration of KDC and OpenLDAP, like when adding new users have to add them twice, once to OpenLDAP and then to KDC (possibly can use scripts).&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Any help and ideas will be appreciated.&lt;/P&gt;</description>
      <pubDate>Sat, 23 Jan 2016 08:23:58 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Looking-for-an-automated-integration-of-HDP-Ambari-with/m-p/108819#M16065</guid>
      <dc:creator>pminovic</dc:creator>
      <dc:date>2016-01-23T08:23:58Z</dc:date>
    </item>
    <item>
      <title>Re: Looking for an automated integration of HDP/Ambari with Kerberos and LDAP</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Looking-for-an-automated-integration-of-HDP-Ambari-with/m-p/108820#M16066</link>
      <description>&lt;A rel="user" href="https://community.cloudera.com/users/177/pminovic.html" nodeid="177"&gt;@Predrag Minovic&lt;/A&gt;&lt;P&gt;This is your best shot &lt;A target="_blank" href="https://cwiki.apache.org/confluence/display/AMBARI/Automated+Kerberizaton"&gt;https://cwiki.apache.org/confluence/display/AMBARI/Automated+Kerberizaton&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 23 Jan 2016 08:27:23 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Looking-for-an-automated-integration-of-HDP-Ambari-with/m-p/108820#M16066</guid>
      <dc:creator>nsabharwal</dc:creator>
      <dc:date>2016-01-23T08:27:23Z</dc:date>
    </item>
    <item>
      <title>Re: Looking for an automated integration of HDP/Ambari with Kerberos and LDAP</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Looking-for-an-automated-integration-of-HDP-Ambari-with/m-p/108821#M16067</link>
      <description>&lt;P&gt;&lt;A rel="user" href="https://community.cloudera.com/users/177/pminovic.html" nodeid="177"&gt;@Predrag Minovic&lt;/A&gt;  I am assuming that you are looking for a way to automate the security integration.&lt;/P&gt;&lt;P&gt;This link has really nice content that you can help to meet the requirement ...Thanks to &lt;A rel="user" href="https://community.cloudera.com/users/132/abajwa.html" nodeid="132"&gt;@Ali Bajwa&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A target="_blank" href="https://github.com/abajwa-hw/ambari-workshops/blob/master/blueprints-demo-security.md"&gt;https://github.com/abajwa-hw/ambari-workshops/blob/master/blueprints-demo-security.md&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 23 Jan 2016 08:31:25 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Looking-for-an-automated-integration-of-HDP-Ambari-with/m-p/108821#M16067</guid>
      <dc:creator>nsabharwal</dc:creator>
      <dc:date>2016-01-23T08:31:25Z</dc:date>
    </item>
    <item>
      <title>Re: Looking for an automated integration of HDP/Ambari with Kerberos and LDAP</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Looking-for-an-automated-integration-of-HDP-Ambari-with/m-p/108822#M16068</link>
      <description>&lt;P&gt;Yes, we'd like to automate kereberization and provide the customer with an easy-to-use interface to manage users afterwards. I'm in touch and aware of great workshops by &lt;A rel="user" href="https://community.cloudera.com/users/132/abajwa.html" nodeid="132"&gt;@Ali Bajwa&lt;/A&gt; but the KDC/OpenLDAP integration is not complete. Also aware of a &lt;A href="https://community.hortonworks.com/articles/811/manual-keytab-principal-creation-for-ipa-to-suppor.html"&gt;great post about FreeIPA&lt;/A&gt; by &lt;A rel="user" href="https://community.cloudera.com/users/175/dstreever.html" nodeid="175"&gt;@David Streever.&lt;/A&gt; And thanks for your super-express repsonse!&lt;/P&gt;&lt;P&gt;&lt;A rel="user" href="https://community.cloudera.com/users/175/dstreever.html" nodeid="175"&gt;&lt;/A&gt; &lt;/P&gt;&lt;P&gt;&lt;A rel="user" href="https://community.cloudera.com/users/132/abajwa.html" nodeid="132"&gt;&lt;/A&gt; &lt;/P&gt;</description>
      <pubDate>Sat, 23 Jan 2016 08:40:38 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Looking-for-an-automated-integration-of-HDP-Ambari-with/m-p/108822#M16068</guid>
      <dc:creator>pminovic</dc:creator>
      <dc:date>2016-01-23T08:40:38Z</dc:date>
    </item>
    <item>
      <title>Re: Looking for an automated integration of HDP/Ambari with Kerberos and LDAP</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Looking-for-an-automated-integration-of-HDP-Ambari-with/m-p/108823#M16069</link>
      <description>&lt;P&gt;&lt;A rel="user" href="https://community.cloudera.com/users/177/pminovic.html" nodeid="177"&gt;@Predrag Minovic&lt;/A&gt; Both of them are GEMS ...Now, take a look on this&lt;/P&gt;&lt;P&gt;&lt;A href="http://docs.hortonworks.com/HDPDocuments/Ambari-2.2.0.0/bk_releasenotes_ambari_2.2.0.0/content/ambari_relnotes-2.2.0.0-new-features.html"&gt;http://docs.hortonworks.com/HDPDocuments/Ambari-2.2.0.0/bk_releasenotes_ambari_2.2.0.0/content/ambari_relnotes-2.2.0.0-new-features.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Jira.&lt;/P&gt;&lt;P&gt;&lt;A href="https://issues.apache.org/jira/browse/AMBARI-13431"&gt;https://issues.apache.org/jira/browse/AMBARI-13431&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 23 Jan 2016 08:55:07 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Looking-for-an-automated-integration-of-HDP-Ambari-with/m-p/108823#M16069</guid>
      <dc:creator>nsabharwal</dc:creator>
      <dc:date>2016-01-23T08:55:07Z</dc:date>
    </item>
    <item>
      <title>Re: Looking for an automated integration of HDP/Ambari with Kerberos and LDAP</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Looking-for-an-automated-integration-of-HDP-Ambari-with/m-p/108824#M16070</link>
      <description>&lt;P&gt;+ &lt;A rel="user" href="https://community.cloudera.com/users/152/jp.html" nodeid="152"&gt;@Jean-Philippe Player&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Partner team have built some &lt;A href="https://community.hortonworks.com/content/kbentry/1143/cheatsheet-on-configuring-authentication-authoriza.html"&gt;security workshops&lt;/A&gt; that show authentication, authorization, audit, encryption on HDP that might be helpful:&lt;/P&gt;&lt;OL&gt;
&lt;LI&gt;For IPA, see &lt;A href="https://github.com/abajwa-hw/security-workshops#current-release"&gt;here&lt;/A&gt; for prebuilt VM and steps on single node. &lt;A rel="user" href="https://community.cloudera.com/users/175/dstreever.html" nodeid="175"&gt;@David Streever&lt;/A&gt; updated &lt;A href="https://github.com/dstreev/security-workshops/blob/master/Manual-IPA-Keytabs-23.md"&gt;here&lt;/A&gt; for multi-node &lt;/LI&gt;&lt;LI&gt;For OpenLDAP/KDC, we have similar steps &lt;A href="https://github.com/abajwa-hw/security-workshops/blob/master/Security-workshop-HDP%202_2-openLDAP.md"&gt;here&lt;/A&gt; but they are not really integrated. I took another shot at this to better integrate the two and came up with the steps &lt;A href="https://github.com/abajwa-hw/security-workshops/blob/master/Setup-OpenLDAP-KDC-integration.md"&gt;here&lt;/A&gt; but still needed to manually create principal in keytabs. Would be great to get this updated to a more complete solution (any volunteers?)&lt;/LI&gt;&lt;LI&gt;For demo purposes we also have Ambari services for KDC, OpenLDAP which can be installed either on existing cluster or brought up on new cluster (via blueprints). Steps for those provided &lt;A href="https://github.com/abajwa-hw/security-workshops/blob/master/Security-workshop-HDP%202_2-openLDAP.md"&gt;here&lt;/A&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;Also note that in Ambari 2.2.0.0 onwards there is a feature to enable kerberos via blueprints (tech preview feature)&lt;/P&gt;</description>
      <pubDate>Sat, 23 Jan 2016 09:02:32 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Looking-for-an-automated-integration-of-HDP-Ambari-with/m-p/108824#M16070</guid>
      <dc:creator>abajwa</dc:creator>
      <dc:date>2016-01-23T09:02:32Z</dc:date>
    </item>
    <item>
      <title>Re: Looking for an automated integration of HDP/Ambari with Kerberos and LDAP</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Looking-for-an-automated-integration-of-HDP-Ambari-with/m-p/108825#M16071</link>
      <description>&lt;P&gt;&lt;A rel="user" href="https://community.cloudera.com/users/132/abajwa.html" nodeid="132"&gt;@Ali Bajwa&lt;/A&gt; &lt;/P&gt;&lt;P&gt;Doesnt Active Directory provide this full-integrated-and-automated way? &lt;/P&gt;</description>
      <pubDate>Sat, 23 Jan 2016 09:08:10 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Looking-for-an-automated-integration-of-HDP-Ambari-with/m-p/108825#M16071</guid>
      <dc:creator>gbraccialli3</dc:creator>
      <dc:date>2016-01-23T09:08:10Z</dc:date>
    </item>
    <item>
      <title>Re: Looking for an automated integration of HDP/Ambari with Kerberos and LDAP</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Looking-for-an-automated-integration-of-HDP-Ambari-with/m-p/108826#M16072</link>
      <description>&lt;P&gt;Yes both AD and IPA provide integrated KDC/LDAP experience which is great for most cases. The problem with FreeIPA is that Ambari doesn't natively support it yet (so you have to use manual option in security wizard where you have to manually create principals/distribute keytabs - &lt;A href="https://issues.apache.org/jira/browse/AMBARI-6432"&gt;JIRA&lt;/A&gt; has been logged on this). But every so often there are customers who require some corner case setup which doesn't work. Am guessing &lt;A rel="user" href="https://community.cloudera.com/users/177/pminovic.html" nodeid="177"&gt;@Predrag Minovic&lt;/A&gt; is running into one of those&lt;/P&gt;</description>
      <pubDate>Sat, 23 Jan 2016 09:21:09 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Looking-for-an-automated-integration-of-HDP-Ambari-with/m-p/108826#M16072</guid>
      <dc:creator>abajwa</dc:creator>
      <dc:date>2016-01-23T09:21:09Z</dc:date>
    </item>
    <item>
      <title>Re: Looking for an automated integration of HDP/Ambari with Kerberos and LDAP</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Looking-for-an-automated-integration-of-HDP-Ambari-with/m-p/108827#M16073</link>
      <description>&lt;P&gt;Hi &lt;A rel="user" href="https://community.cloudera.com/users/132/abajwa.html" nodeid="132"&gt;@Ali Bajwa&lt;/A&gt;, thanks for chiming in. No special requirements except that KDC/LDAP run on RHEL Linux. Also, I don't mind wasting more time to install the solution but would like to provide sysadmin with easy-to-use UI to manage users and groups.&lt;/P&gt;</description>
      <pubDate>Mon, 25 Jan 2016 22:26:59 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Looking-for-an-automated-integration-of-HDP-Ambari-with/m-p/108827#M16073</guid>
      <dc:creator>pminovic</dc:creator>
      <dc:date>2016-01-25T22:26:59Z</dc:date>
    </item>
    <item>
      <title>Re: Looking for an automated integration of HDP/Ambari with Kerberos and LDAP</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Looking-for-an-automated-integration-of-HDP-Ambari-with/m-p/108828#M16074</link>
      <description>&lt;P&gt;&lt;A rel="user" href="https://community.cloudera.com/users/177/pminovic.html" nodeid="177"&gt;@Predrag Minovic&lt;/A&gt; has this been resolved? Please accept best answer or provide your own solution.&lt;/P&gt;</description>
      <pubDate>Wed, 03 Feb 2016 02:09:20 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Looking-for-an-automated-integration-of-HDP-Ambari-with/m-p/108828#M16074</guid>
      <dc:creator>aervits</dc:creator>
      <dc:date>2016-02-03T02:09:20Z</dc:date>
    </item>
    <item>
      <title>Re: Looking for an automated integration of HDP/Ambari with Kerberos and LDAP</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Looking-for-an-automated-integration-of-HDP-Ambari-with/m-p/108829#M16075</link>
      <description>&lt;P&gt;AD is most definitely the easiest answer, unless you're morally opposed to it ;). You get integrated LDAP and KRB with nice user management tools. IPA does have some nice ootb features, though, around self service, etc.&lt;/P&gt;</description>
      <pubDate>Wed, 22 Jun 2016 01:53:32 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Looking-for-an-automated-integration-of-HDP-Ambari-with/m-p/108829#M16075</guid>
      <dc:creator>ewalk</dc:creator>
      <dc:date>2016-06-22T01:53:32Z</dc:date>
    </item>
  </channel>
</rss>

