<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>question Re: Script used to generate AD accounts during kerberos setup in Archives of Support Questions (Read Only)</title>
    <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Script-used-to-generate-AD-accounts-during-kerberos-setup/m-p/199866#M83627</link>
    <description>&lt;A rel="user" href="https://community.cloudera.com/users/44383/coolgags.html" nodeid="44383"&gt;@Gagandeep Singh Chawla&lt;/A&gt;&lt;P&gt;I do not believe that an AD-specific script is provided with Ambari; however some of the Hortonworks support or professional services folks may have something. &lt;/P&gt;&lt;P&gt;The provided script may be out of date and is geared towards the MIT KDC. It will not work with an Active Directory.  Active Directory would prefer that all account creation and keytab export routines be executed on the Windows server, itself.  However, since AD has an LDAP interface that can be used to add new objects to the database, Ambari is able to create principals and set password.  Thus giving it the ability to automate creating principals and keytab files remotely - the keytab files are actually generated by Ambari and not exported from the AD.&lt;/P&gt;&lt;P&gt;If you are looking for steps on how Ambari does this, take a look at the HCC article &lt;A href="https://community.hortonworks.com/content/supportkb/150590/how-to-create-ad-principal-accounts-using-openldap-1.html" target="_blank"&gt;How to create AD principal accounts using OpenLdap utilities and adding it to a keytab&lt;/A&gt;.  This is not exactly what Ambari does, but it is really close.  Using details from that article, I can imagine that a script can be built to read an Ambari-provided CSV file and create the needed principals and keytab files. &lt;/P&gt;</description>
    <pubDate>Tue, 18 Sep 2018 20:23:00 GMT</pubDate>
    <dc:creator>rlevas</dc:creator>
    <dc:date>2018-09-18T20:23:00Z</dc:date>
    <item>
      <title>Script used to generate AD accounts during kerberos setup</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Script-used-to-generate-AD-accounts-during-kerberos-setup/m-p/199865#M83626</link>
      <description>&lt;P&gt;Dear Team,&lt;/P&gt;&lt;P&gt;Can you be so kind to help me with the location of script which creates AD accounts during automated kerberos setup via ambari. (AD team wants to review before giving us write access)&lt;/P&gt;&lt;P&gt;I looked at /var/lib/ambari-server/resources/scripts/kerberos_setup.sh but could not understand where we create and delete AD users.&lt;/P&gt;&lt;P&gt;Thanks and Best Regards,&lt;/P&gt;&lt;P&gt;Gagan&lt;/P&gt;</description>
      <pubDate>Fri, 16 Sep 2022 13:43:19 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Script-used-to-generate-AD-accounts-during-kerberos-setup/m-p/199865#M83626</guid>
      <dc:creator>coolgags</dc:creator>
      <dc:date>2022-09-16T13:43:19Z</dc:date>
    </item>
    <item>
      <title>Re: Script used to generate AD accounts during kerberos setup</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Script-used-to-generate-AD-accounts-during-kerberos-setup/m-p/199866#M83627</link>
      <description>&lt;A rel="user" href="https://community.cloudera.com/users/44383/coolgags.html" nodeid="44383"&gt;@Gagandeep Singh Chawla&lt;/A&gt;&lt;P&gt;I do not believe that an AD-specific script is provided with Ambari; however some of the Hortonworks support or professional services folks may have something. &lt;/P&gt;&lt;P&gt;The provided script may be out of date and is geared towards the MIT KDC. It will not work with an Active Directory.  Active Directory would prefer that all account creation and keytab export routines be executed on the Windows server, itself.  However, since AD has an LDAP interface that can be used to add new objects to the database, Ambari is able to create principals and set password.  Thus giving it the ability to automate creating principals and keytab files remotely - the keytab files are actually generated by Ambari and not exported from the AD.&lt;/P&gt;&lt;P&gt;If you are looking for steps on how Ambari does this, take a look at the HCC article &lt;A href="https://community.hortonworks.com/content/supportkb/150590/how-to-create-ad-principal-accounts-using-openldap-1.html" target="_blank"&gt;How to create AD principal accounts using OpenLdap utilities and adding it to a keytab&lt;/A&gt;.  This is not exactly what Ambari does, but it is really close.  Using details from that article, I can imagine that a script can be built to read an Ambari-provided CSV file and create the needed principals and keytab files. &lt;/P&gt;</description>
      <pubDate>Tue, 18 Sep 2018 20:23:00 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Script-used-to-generate-AD-accounts-during-kerberos-setup/m-p/199866#M83627</guid>
      <dc:creator>rlevas</dc:creator>
      <dc:date>2018-09-18T20:23:00Z</dc:date>
    </item>
    <item>
      <title>Re: Script used to generate AD accounts during kerberos setup</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Script-used-to-generate-AD-accounts-during-kerberos-setup/m-p/199867#M83628</link>
      <description>&lt;P&gt;Thanks for the detailed answer, it is very helpful! BR//Gagan&lt;/P&gt;</description>
      <pubDate>Wed, 19 Sep 2018 15:15:42 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Script-used-to-generate-AD-accounts-during-kerberos-setup/m-p/199867#M83628</guid>
      <dc:creator>coolgags</dc:creator>
      <dc:date>2018-09-19T15:15:42Z</dc:date>
    </item>
  </channel>
</rss>

