Created 03-29-2017 06:45 AM
Setup
- Active Directory with LDAPs
- HDP 2.5 (HDFS, Ranger, KMS, Enabled Kerberos )
I've created user called "test" on AD and it's showing in Ranger Users list then created policy in Ranger to test user to allow /user/, then in KMS created key called test.
Question
1. Do I need to add Linux client machine in domain or create local OS user to access the /user via test user ?
2. Do I need to create keytab on AD and share with test user ?
3. How does this KMS works ?
Created 03-29-2017 07:58 AM
Hortonworks University has a really great Tutorial on Ranger + KMS setup with step by step details. I am sure you will clear your many doubts. Please have a look. Specially Lab-6
https://github.com/HortonworksUniversity/Security_Labs#lab-6a
Similarly Lab 2 & 3 talks about the basic setup with AD & LDAPs