Archives of Support Questions (Read Only)

This is an archived board for historical reference. Information and links may no longer be available or relevant
Announcements
This board is archived and read-only for historical reference. To ask a new question, please post a new topic on the appropriate active board.

Integrating HDP with A/D without writing anything to A/D? How?

avatar
Expert Contributor

Hi Guys,

I am trying to Kerberizing the cluster and want to integrate with A/D for user authentication. Earlier I've done it using MIT KDC in the HDP cluster and setting bi-directional trust with A/D. But as I remember, the previous step adds couple of entries in the A/D. However, customer does not want to give write access to the A/D. How to proceed in this scenario?

Thanks,

SS.

1 ACCEPTED SOLUTION

avatar
Master Mentor
@Smart Solutions

You can have KDC in HDP cluster and build one way trust as you mentioned. You still need access to enterprise KDC as you have mentioned it already

https://docs.hortonworks.com/HDPDocuments/HDP2/HDP-2.3.0/bk_installing_manually_book/content/ref-cdb...

View solution in original post

1 REPLY 1

avatar
Master Mentor
@Smart Solutions

You can have KDC in HDP cluster and build one way trust as you mentioned. You still need access to enterprise KDC as you have mentioned it already

https://docs.hortonworks.com/HDPDocuments/HDP2/HDP-2.3.0/bk_installing_manually_book/content/ref-cdb...