<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>question What is the reason for creating an Active Directory OU User container for principals and Active Directory administrative credentials with delegated control of “Create, delete, and manage user accounts” on the OU User container? in Archives of Support Questions (Read Only)</title>
    <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/What-is-the-reason-for-creating-an-Active-Directory-OU-User/m-p/144077#M52426</link>
    <description>&lt;P&gt;We want to use our existing Active Directory environment for Kerberos User Authentication.
Using the Ambari Kerberos Wizard the following prereequisites needs to be checked to progress ...&lt;/P&gt;&lt;UL&gt;
&lt;LI&gt;Active Directory OU User container for principals has been created, For example "OU=Hadoop-Cluster,OU=People,dc=domain,dc=com"&lt;/LI&gt;&lt;LI&gt;Active Directory administrative credentials with delegated control of “Create, delete, and manage user accounts” on the OU User container are implemented&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;What is the reason for creating an Active Directory OU User container for principals and Active Directory administrative credentials with delegated control of “Create, delete, and manage user accounts” on the OU User container?&lt;/P&gt;</description>
    <pubDate>Fri, 16 Sep 2022 10:56:35 GMT</pubDate>
    <dc:creator>timo_burmeister</dc:creator>
    <dc:date>2022-09-16T10:56:35Z</dc:date>
    <item>
      <title>What is the reason for creating an Active Directory OU User container for principals and Active Directory administrative credentials with delegated control of “Create, delete, and manage user accounts” on the OU User container?</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/What-is-the-reason-for-creating-an-Active-Directory-OU-User/m-p/144077#M52426</link>
      <description>&lt;P&gt;We want to use our existing Active Directory environment for Kerberos User Authentication.
Using the Ambari Kerberos Wizard the following prereequisites needs to be checked to progress ...&lt;/P&gt;&lt;UL&gt;
&lt;LI&gt;Active Directory OU User container for principals has been created, For example "OU=Hadoop-Cluster,OU=People,dc=domain,dc=com"&lt;/LI&gt;&lt;LI&gt;Active Directory administrative credentials with delegated control of “Create, delete, and manage user accounts” on the OU User container are implemented&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;What is the reason for creating an Active Directory OU User container for principals and Active Directory administrative credentials with delegated control of “Create, delete, and manage user accounts” on the OU User container?&lt;/P&gt;</description>
      <pubDate>Fri, 16 Sep 2022 10:56:35 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/What-is-the-reason-for-creating-an-Active-Directory-OU-User/m-p/144077#M52426</guid>
      <dc:creator>timo_burmeister</dc:creator>
      <dc:date>2022-09-16T10:56:35Z</dc:date>
    </item>
    <item>
      <title>Re: What is the reason for creating an Active Directory OU User container for principals and Active Directory administrative credentials with delegated control of “Create, delete, and manage user accounts” on the OU User container?</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/What-is-the-reason-for-creating-an-Active-Directory-OU-User/m-p/144078#M52427</link>
      <description>&lt;A rel="user" href="https://community.cloudera.com/users/2158/timoburmeister.html" nodeid="2158"&gt;@Timo Burmeister&lt;/A&gt;&lt;P&gt;A new container does not need to be created specifically for the Ambari-managed Kerberos identities; however, it would be recommended since there potentially may be a lot of accounts created for service and user principals in the Active Directory. In any case, there needs to be a container available in the Active Directory that Ambari can create and manage accounts within. &lt;/P&gt;&lt;P&gt;The credentials used to access the Active Directory must give access to Ambari so that new accounts can be created for each of the cluster-specific service and user principals. That account must able to able to update the password for each of those accounts.   It is recommended that a special account is given access to the container for security purposes and ease-of-mind.  You may not want to give out a domain administrator's credentials or give Ambari full rein over the Active Directory - not that Ambari will do anything nefarious. &lt;/P&gt;</description>
      <pubDate>Tue, 24 Jan 2017 23:17:40 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/What-is-the-reason-for-creating-an-Active-Directory-OU-User/m-p/144078#M52427</guid>
      <dc:creator>rlevas</dc:creator>
      <dc:date>2017-01-24T23:17:40Z</dc:date>
    </item>
  </channel>
</rss>

