Options
- Subscribe to RSS Feed
- Mark Question as New
- Mark Question as Read
- Float this Question for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Solved
Go to solution
Failed to enable Kerberos using Direct Active Directory using CDH 5.9.0
Labels:
- Labels:
-
Kerberos
Expert Contributor
Created ‎12-05-2016 08:05 PM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Reference:
My question is how to configure AD OU admin user. This user has to have permissions to modify LDAP also. I just can't find anything on this. I got permission denied on ldapadd when generating the keytabs. Could someone help me on how to set this user up in both AD domain and AD LDAP?
1 ACCEPTED SOLUTION
Expert Contributor
Created ‎12-23-2016 12:07 PM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Found this useful link:
https://www.cloudera.com/documentation/enterprise/latest/topics/cm_sg_s3_cm_principal.html
If you are using Active Directory:
- Create an Organizational Unit (OU) in your AD setup where all the principals used by your CDH cluster will reside.
- Add a new user account to Active Directory, for example, <username>@YOUR-REALM.COM. The password for this user should be set to never expire.
- Use AD's Delegate Control wizard to allow this new user to Create, Delete and Manage User Accounts.
1 REPLY 1
Expert Contributor
Created ‎12-23-2016 12:07 PM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Found this useful link:
https://www.cloudera.com/documentation/enterprise/latest/topics/cm_sg_s3_cm_principal.html
If you are using Active Directory:
- Create an Organizational Unit (OU) in your AD setup where all the principals used by your CDH cluster will reside.
- Add a new user account to Active Directory, for example, <username>@YOUR-REALM.COM. The password for this user should be set to never expire.
- Use AD's Delegate Control wizard to allow this new user to Create, Delete and Manage User Accounts.
