<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>question Re: Cloudera Manager: enabling kerberos security with Free IPA Server in Archives of Support Questions (Read Only)</title>
    <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Cloudera-Manager-enabling-kerberos-security-with-Free-IPA/m-p/43014#M33585</link>
    <description>The Keytab Retrieval Script method can be used to integrate with IPA since there is no support for direct-to-IPA keytab management.
See the following documentation for information:

&lt;A href="http://www.cloudera.com/documentation/enterprise/latest/topics/sg_keytab_retrieval_script.html" target="_blank"&gt;http://www.cloudera.com/documentation/enterprise/latest/topics/sg_keytab_retrieval_script.html&lt;/A&gt;</description>
    <pubDate>Tue, 19 Jul 2016 22:07:03 GMT</pubDate>
    <dc:creator>ebomarsi</dc:creator>
    <dc:date>2016-07-19T22:07:03Z</dc:date>
    <item>
      <title>Cloudera Manager: enabling kerberos security with Free IPA Server</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Cloudera-Manager-enabling-kerberos-security-with-Free-IPA/m-p/42538#M33582</link>
      <description>&lt;P&gt;I am trying to turn on kerberos security on my Cloudera cluster using Cloudera Manager (CM). I have an existing Kerberos KDC in my network as part of an integrated Free IPA server. I am able to create a cloudera-scm user with admin privs on the CM node, installed the keytab file, and authenticate to the CM. However, I see that when CM tries to create a principal for other Hadoop services, it fails.&lt;/P&gt;&lt;P&gt;I found a similar issue posted with IPA and Ambari. It seems Free IPA does not permit applications to directly access the kadmin tool. Instead the service exposes an equivalent set of ipa commands. (reference:&amp;nbsp;&lt;SPAN&gt;&lt;A href="https://www.redhat.com/archives/freeipa-users/2015-April/msg00560.html" target="_blank"&gt;https://www.redhat.com/archives/freeipa-users/2015-April/msg00560.html&lt;/A&gt;&amp;nbsp;)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Looking at the CM logs, it appears to be the same issue where CM is failing on a kadmin command trying to create a prinicpal for the HDFS user. Is it possible to modify the CM kerberos interface to use the equivalent ipa commands?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 16 Sep 2022 10:28:21 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Cloudera-Manager-enabling-kerberos-security-with-Free-IPA/m-p/42538#M33582</guid>
      <dc:creator>ebomarsi</dc:creator>
      <dc:date>2022-09-16T10:28:21Z</dc:date>
    </item>
    <item>
      <title>Re: Cloudera Manager: enabling kerberos security with Free IPA Server</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Cloudera-Manager-enabling-kerberos-security-with-Free-IPA/m-p/42548#M33583</link>
      <description>&lt;P&gt;Within Cloudera Manage you could use the&amp;nbsp;Custom Kerberos Keytab Retrieval Script, an example script is documented here &lt;A href="http://www.cloudera.com/documentation/enterprise/latest/topics/sg_keytab_retrieval_script.html" target="_blank"&gt;http://www.cloudera.com/documentation/enterprise/latest/topics/sg_keytab_retrieval_script.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 01 Jul 2016 16:40:21 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Cloudera-Manager-enabling-kerberos-security-with-Free-IPA/m-p/42548#M33583</guid>
      <dc:creator>michalis</dc:creator>
      <dc:date>2016-07-01T16:40:21Z</dc:date>
    </item>
    <item>
      <title>Re: Cloudera Manager: enabling kerberos security with Free IPA Server</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Cloudera-Manager-enabling-kerberos-security-with-Free-IPA/m-p/42638#M33584</link>
      <description>The Keytab Retrieval Script method can be used to integrate with IPA since there is no support for direct-to-IPA keytab management.
See the following documentation for information:

&lt;A href="http://www.cloudera.com/documentation/enterprise/latest/topics/sg_keytab_retrieval_script.html" target="_blank"&gt;http://www.cloudera.com/documentation/enterprise/latest/topics/sg_keytab_retrieval_script.html&lt;/A&gt;</description>
      <pubDate>Wed, 06 Jul 2016 15:21:14 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Cloudera-Manager-enabling-kerberos-security-with-Free-IPA/m-p/42638#M33584</guid>
      <dc:creator>bgooley</dc:creator>
      <dc:date>2016-07-06T15:21:14Z</dc:date>
    </item>
    <item>
      <title>Re: Cloudera Manager: enabling kerberos security with Free IPA Server</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Cloudera-Manager-enabling-kerberos-security-with-Free-IPA/m-p/43014#M33585</link>
      <description>The Keytab Retrieval Script method can be used to integrate with IPA since there is no support for direct-to-IPA keytab management.
See the following documentation for information:

&lt;A href="http://www.cloudera.com/documentation/enterprise/latest/topics/sg_keytab_retrieval_script.html" target="_blank"&gt;http://www.cloudera.com/documentation/enterprise/latest/topics/sg_keytab_retrieval_script.html&lt;/A&gt;</description>
      <pubDate>Tue, 19 Jul 2016 22:07:03 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Cloudera-Manager-enabling-kerberos-security-with-Free-IPA/m-p/43014#M33585</guid>
      <dc:creator>ebomarsi</dc:creator>
      <dc:date>2016-07-19T22:07:03Z</dc:date>
    </item>
  </channel>
</rss>

