<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>question Re: What are the best practises for Unix user mapping ? in Archives of Support Questions (Read Only)</title>
    <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/What-are-the-best-practises-for-Unix-user-mapping/m-p/161196#M41185</link>
    <description>&lt;P&gt;Thanks &lt;A rel="user" href="https://community.cloudera.com/users/174/hkropp.html" nodeid="174"&gt;@hkropp&lt;/A&gt;. I'm looking at the suggested options.&lt;/P&gt;&lt;P&gt;What about plain LDAP login configuration on the nodes, could it be a simple solution too?&lt;/P&gt;</description>
    <pubDate>Tue, 20 Sep 2016 16:47:08 GMT</pubDate>
    <dc:creator>tristan1</dc:creator>
    <dc:date>2016-09-20T16:47:08Z</dc:date>
    <item>
      <title>What are the best practises for Unix user mapping ?</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/What-are-the-best-practises-for-Unix-user-mapping/m-p/161194#M41183</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;We have a working HDP 2.4 Kerberos enabled working, with Hue and from command line too.&lt;/P&gt;&lt;P&gt;Following to the documentation, we have created Unix user mappings between the nodes and Active Directory. Users can login to a utility machine and kinit to login.&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.hortonworks.com/HDPDocuments/HDP2/HDP-2.4.2/bk_Security_Guide/content/create_mappings_betw_principals_and_unix_usernames.html" target="_blank"&gt;https://docs.hortonworks.com/HDPDocuments/HDP2/HDP-2.4.2/bk_Security_Guide/content/create_mappings_betw_principals_and_unix_usernames.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;It's working just fine.&lt;/P&gt;&lt;P&gt;My question is about the management of those users: everytime we want to grand access to a new user, we need to go ahead and create those users on all nodes, which is not very practical.&lt;/P&gt;&lt;P&gt;What are the best practises for that?&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;script user accounts creation?&lt;/LI&gt;&lt;LI&gt;Enrol all node machines as domain machines so that AD users can login?&lt;/LI&gt;&lt;LI&gt;Configure the unix machine to accept login using LDAP against AD?&lt;/LI&gt;&lt;LI&gt;Others?&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Thanks a lot in advance for ideals and experiences.&lt;/P&gt;&lt;P&gt;Tristan&lt;/P&gt;</description>
      <pubDate>Tue, 20 Sep 2016 13:58:41 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/What-are-the-best-practises-for-Unix-user-mapping/m-p/161194#M41183</guid>
      <dc:creator>tristan1</dc:creator>
      <dc:date>2016-09-20T13:58:41Z</dc:date>
    </item>
    <item>
      <title>Re: What are the best practises for Unix user mapping ?</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/What-are-the-best-practises-for-Unix-user-mapping/m-p/161195#M41184</link>
      <description>&lt;P&gt;A list of recommended tools are:&lt;/P&gt;&lt;OL&gt;
&lt;LI&gt;SSSD &lt;A href="https://fedorahosted.org/sssd/" target="_blank"&gt;https://fedorahosted.org/sssd/&lt;/A&gt; / &lt;A href="https://help.ubuntu.com/lts/serverguide/sssd-ad.html" target="_blank"&gt;https://help.ubuntu.com/lts/serverguide/sssd-ad.html&lt;/A&gt;&lt;/LI&gt;&lt;LI&gt;FreeIPA (introduces additional AD and need to establish Trust between the two) &lt;A href="https://www.freeipa.org/page/Main_Page" target="_blank"&gt;https://www.freeipa.org/page/Main_Page&lt;/A&gt;&lt;/LI&gt;&lt;LI&gt;Winutils&lt;/LI&gt;&lt;LI&gt;Centrify (commercial) &lt;A href="https://www.centrify.com/" target="_blank"&gt;https://www.centrify.com/&lt;/A&gt;&lt;/LI&gt;&lt;LI&gt;VAS / Quest (commercial) &lt;A href="https://software.dell.com/products/authentication-services/" target="_blank"&gt;https://software.dell.com/products/authentication-services/&lt;/A&gt;&lt;/LI&gt;&lt;LI&gt;....&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;Please check the material of this workshop for reference: &lt;/P&gt;&lt;P&gt;&lt;A href="https://community.hortonworks.com/articles/1143/cheatsheet-on-configuring-authentication-authoriza.html" target="_blank"&gt;https://community.hortonworks.com/articles/1143/cheatsheet-on-configuring-authentication-authoriza.html&lt;/A&gt;
&lt;A href="https://community.hortonworks.com/repos/4465/workshops-on-how-to-setup-security-on-hadoop-using.html" target="_blank"&gt;https://community.hortonworks.com/repos/4465/workshops-on-how-to-setup-security-on-hadoop-using.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 20 Sep 2016 16:11:45 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/What-are-the-best-practises-for-Unix-user-mapping/m-p/161195#M41184</guid>
      <dc:creator>hkropp</dc:creator>
      <dc:date>2016-09-20T16:11:45Z</dc:date>
    </item>
    <item>
      <title>Re: What are the best practises for Unix user mapping ?</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/What-are-the-best-practises-for-Unix-user-mapping/m-p/161196#M41185</link>
      <description>&lt;P&gt;Thanks &lt;A rel="user" href="https://community.cloudera.com/users/174/hkropp.html" nodeid="174"&gt;@hkropp&lt;/A&gt;. I'm looking at the suggested options.&lt;/P&gt;&lt;P&gt;What about plain LDAP login configuration on the nodes, could it be a simple solution too?&lt;/P&gt;</description>
      <pubDate>Tue, 20 Sep 2016 16:47:08 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/What-are-the-best-practises-for-Unix-user-mapping/m-p/161196#M41185</guid>
      <dc:creator>tristan1</dc:creator>
      <dc:date>2016-09-20T16:47:08Z</dc:date>
    </item>
    <item>
      <title>Re: What are the best practises for Unix user mapping ?</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/What-are-the-best-practises-for-Unix-user-mapping/m-p/161197#M41186</link>
      <description>&lt;P&gt;Yes with pam_ldap integration: &lt;A href="http://www.tldp.org/HOWTO/archived/LDAP-Implementation-HOWTO/pamnss.html" target="_blank"&gt;http://www.tldp.org/HOWTO/archived/LDAP-Implementation-HOWTO/pamnss.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 20 Sep 2016 16:49:21 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/What-are-the-best-practises-for-Unix-user-mapping/m-p/161197#M41186</guid>
      <dc:creator>hkropp</dc:creator>
      <dc:date>2016-09-20T16:49:21Z</dc:date>
    </item>
    <item>
      <title>Re: What are the best practises for Unix user mapping ?</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/What-are-the-best-practises-for-Unix-user-mapping/m-p/161198#M41187</link>
      <description>&lt;P&gt;Well, you would have the login, but not the kerberos init. You would still have two realms with user credentials the KRB5 realm and the LDAP realm depending on your setup.&lt;/P&gt;&lt;P&gt;Actually the KRB5 realm can be included inside LDAP or put differently Kerberos can be configured to use LDAP as it's user DB, that would give you the possibility to combine both. This essential is what FreeIPA is.&lt;/P&gt;</description>
      <pubDate>Tue, 20 Sep 2016 16:52:20 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/What-are-the-best-practises-for-Unix-user-mapping/m-p/161198#M41187</guid>
      <dc:creator>hkropp</dc:creator>
      <dc:date>2016-09-20T16:52:20Z</dc:date>
    </item>
  </channel>
</rss>

