Support Questions

Find answers, ask questions, and share your expertise

Kerberos Install on HDP cluster after Ranger/Ranger KMS setup

avatar
Rising Star

I have installed Ranger/Ranger KMS on HDP 2.5 cluster using Ambari.Just wanted to check if we can setup kerberos on HDP 2.5 after Ranger/Ranger KMS have been installed on cluster? Or do we need to delete Ranger/Ranger KMS first for installation of kerberos?

Thanks

1 ACCEPTED SOLUTION

avatar
Guru

Hello @rahul gulati,

There is no need to remove Ranger / Ranger KMS before enabling Kerberos on your cluster. I'd recommend to use Ambari Kerberos Wizard to enable Kerberos (just as you do normally) and Ambari should be able to handle all the installed components.

Hope this helps !

View solution in original post

3 REPLIES 3

avatar
Guru

Hello @rahul gulati,

There is no need to remove Ranger / Ranger KMS before enabling Kerberos on your cluster. I'd recommend to use Ambari Kerberos Wizard to enable Kerberos (just as you do normally) and Ambari should be able to handle all the installed components.

Hope this helps !

avatar
Rising Star

Hello @Vipin Rathor

That's great. I have a 6 node cluster(1 Edge Node, 1 Primary NN, 1 Secondary NN and 2 Slave Nodes). Just wanted to confirm that Shall i setup up new MIT KDC on my Ambari Server Node(Master Node1) and then go for Ambari Automated Kerberos Security setup?

I assume above mentioned approach should be the best in my case as i need to setup MIT KDC as well.

I am following below mentioned Hortonworks docs for kerberos setup.

http://docs.hortonworks.com/HDPDocuments/HDF2/HDF-2.1.2/bk_dataflow-security/content/_optional_insta...

Thanks in Advance!!

avatar
Guru

@rahul gulati Yes, it's okay to install MIT KDC on Ambari server node. But in the real production cluster, we should clearly separate these two roles on two different nodes.

Hope this helps !