Support Questions
Find answers, ask questions, and share your expertise
Announcements
Alert: Welcome to the Unified Cloudera Community. Former HCC members be sure to read and learn how to activate your account here.

Cloudera Security kerberos load on Windows AD

Solved Go to solution

Cloudera Security kerberos load on Windows AD

New Contributor

 

Hi there

 

When we implement Cloudera Manager Security with kerberos.

and we connect to our windows AD for as KDC.

 

What will the impact / load be on the windows AD ?

 

can i get some information/numbers about that?

 

Thank you

1 ACCEPTED SOLUTION

Accepted Solutions

Re: Cloudera Security kerberos load on Windows AD

Cloudera Employee

To add to this, Cloudera Manager uses the kadmin interface to generate the service principles. Windows AD does not support the kerberos kadmin interface from my understanding. You will be better off setting up a MIT based Kdc on a linux system and then configuring cross-realm trust with your AD server.

 

-roland

3 REPLIES 3

Re: Cloudera Security kerberos load on Windows AD

Super Collaborator

It can have significant impact.  This is why we do not document or support direct configuration against the AD server as a kerberos KDC.

 

Todd

Re: Cloudera Security kerberos load on Windows AD

Super Collaborator

Make sure you "want" kerberos security configured.  Disable NameNode HA Auto Failover and Jobtracker HA before starting.  If HBASE is in use, you will want to review if you want to keep kerberos enabled.  Once you enable kerberos, disabling kerberos can become a complex process as you have to go into zookeeper and remove ACL's over those znode entries, while kerberos is still enabled.

 

Set up a your cluster KDC, on the CM server for example.  If you are on RHEL, Follow the steps here:

 

https://access.redhat.com/site/documentation/en-US/Red_Hat_Enterprise_Linux/6/html/Managing_Smart_Ca...

 

Make sure to enable ticket renewal in your kdc/krb4 configs right away before starting on the steps laid out in our guide to enabling hadoop security with cloudera manager

 

http://www.cloudera.com/content/cloudera-content/cloudera-docs/CM4Ent/latest/Configuring-Hadoop-Secu...

Re: Cloudera Security kerberos load on Windows AD

Cloudera Employee

To add to this, Cloudera Manager uses the kadmin interface to generate the service principles. Windows AD does not support the kerberos kadmin interface from my understanding. You will be better off setting up a MIT based Kdc on a linux system and then configuring cross-realm trust with your AD server.

 

-roland

Don't have an account?
Coming from Hortonworks? Activate your account here