Support Questions
Find answers, ask questions, and share your expertise
Announcements
Alert: Welcome to the Unified Cloudera Community. Former HCC members be sure to read and learn how to activate your account here.

using Kadmin for connectiong to AD KDC

Solved Go to solution

using Kadmin for connectiong to AD KDC

New Contributor

Have anyone tried kadmin (connecting to AD KDC) after kerberising the hadoop cluster using Ambari?

I am using the same credentials and it is saying “Required KADM5 principal missing while initializing kadmin interface”. What is the recommended best way to AD KDC connection? Thanks for help

1 ACCEPTED SOLUTION

Accepted Solutions

Re: using Kadmin for connectiong to AD KDC

@Vishal Gupta

You cannot use the MIT Kerberos package's kadmin tool to manage an Active Directory - you need to use Active Directory-specific tools, or for creating accounts, a tool that can communicate to the AD using LDAP.

For an LDAP approach, see this article posted by @dvillarreal: How to create AD principal accounts using OpenLdap utilities and adding it to a keytab.

3 REPLIES 3

Re: using Kadmin for connectiong to AD KDC

Contributor

@Vishal Gupta You might not have added principals for kadmin/fqdn@DOMAIN as well as the legacy fallback kadmin/admin@DOMAIN. You can add them using kadmin.local

https://web.mit.edu/kerberos/krb5-1.13/doc/admin/admin_commands/kadmin_local.html

Re: using Kadmin for connectiong to AD KDC

@Vishal Gupta

You cannot use the MIT Kerberos package's kadmin tool to manage an Active Directory - you need to use Active Directory-specific tools, or for creating accounts, a tool that can communicate to the AD using LDAP.

For an LDAP approach, see this article posted by @dvillarreal: How to create AD principal accounts using OpenLdap utilities and adding it to a keytab.

Re: using Kadmin for connectiong to AD KDC

New Contributor

Thanks Robert and bhatt. This is helpful