centralized user authentication in kerberos

In LDAP we create users and sync them with cluster, Ambari and Ranger, so same user can be used everywhere.

I have configured my cluster for kerberos. How can i achieve centralized user authentication in kerberos enabled cluster as i mentioned above we can do in LDAP ?

I do not have LDAP server. I want to do Authentication and Authorization both using Kerberos only.




I am not too sure about Ranger or the other services, but Ambari requires that the users are already known. So syncing with an LDAP server is helpful in your case. Else if you attempt to authenticate using Kerberos, the attempt will fail since the user will not be found in the Ambari database.

