Integrating Hadoop Security with Active Directory
TLS Setup Notes
- Set -keypass to the same value as -storepass. Cloudera Manager assumes that the same password is used to access both the key and the keystore, and therefore, does not support separate values for -keypass and -storepass.
- Run an MIT Kerberos KDC and realm local to the cluster and create all service principals in this realm.
- Set up one-way cross-realm trust from this realm to the Active Directory realm. Using this method, there is no need to create service principals in Active Directory, but Active Directory principals (users) can be authenticated to Hadoop. See Configuring a Local MIT Kerberos Realm to Trust Active Directory.
Configuring a Local MIT Kerberos Realm to Trust Active Directory
On the Active Directory Server
- Add the local realm trust to Active Directory with this command:
netdom trust YOUR-LOCAL-REALM.COMPANY.COM /Domain:AD-REALM.COMPANY.COM /add /realm /passwordt:<TrustPassword>
- Set the proper encryption type with this command:
On Windows 2003 RC2:
ktpass /MITRealmName YOUR-LOCAL-REALM.COMPANY.COM /TrustEncryp <enc_type>
On Windows 2008:
ksetup /SetEncTypeAttr YOUR-LOCAL-REALM.COMPANY.COM <enc_type>
The <enc_type> parameter specifies AES, DES, or RC4 encryption. Refer to the documentation for your version of Windows Active Directory to find the <enc_type> parameter string to use.
- Get and verify the list of encryption types set with this command:
On Windows 2008:
ksetup /GetEncTypeAttr YOUR-LOCAL-REALM.COMPANY.COM
Important: Make sure the encryption type you specify is supported on both your version of Windows Active Directory and your version of MIT Kerberos.
On the MIT KDC Server
Type the following command in the kadmin.local or kadmin shell to add the cross-realm krbtgt principal. Use the same password you used in the netdom command on the Active Directory Server.
kadmin: addprinc -e "<enc_type_list>" krbtgt/YOUR-LOCAL-REALM.COMPANY.COM@AD-REALM.COMPANY.COM
where the <enc_type_list> parameter specifies the types of encryption this cross-realm krbtgt principal will support: either AES, DES, or RC4 encryption. You can specify multiple encryption types using the parameter in the command above, what's important is that at least one of the encryption types corresponds to the encryption type found in the tickets granted by the KDC in the remote realm. For example:
kadmin: addprinc -e "rc4-hmac:normal des3-hmac-sha1:normal" krbtgt/YOUR-LOCAL-REALM.COMPANY.COM@AD-REALM.COMPANY.COM
On All of the Cluster Hosts
- Verify that both Kerberos realms are configured on all of the cluster hosts. Note that the default realm and the domain realm should remain set as the MIT Kerberos realm which is local
to the cluster.
[realms] AD-REALM.CORP.FOO.COM = { kdc = ad.corp.foo.com:88 admin_server = ad.corp.foo.com:749 default_domain = foo.com } CLUSTER-REALM.CORP.FOO.COM = { kdc = cluster01.corp.foo.com:88 admin_server = cluster01.corp.foo.com:749 default_domain = foo.com }
- To properly translate principal names from the Active Directory realm into local names within Hadoop, you must configure the hadoop.security.auth_to_local setting in the core-site.xml file on all of the cluster machines. The following example translates all principal names
with the realm AD-REALM.CORP.FOO.COM into the first component of the principal name only. It also preserves the standard translation for the default realm (the cluster
realm).
<property> <name>hadoop.security.auth_to_local</name> <value> RULE:[1:$1@$0](^.*@AD-REALM\.CORP\.FOO\.COM$)s/^(.*)@AD-REALM\.CORP\.FOO\.COM$/$1/g RULE:[2:$1@$0](^.*@AD-REALM\.CORP\.FOO\.COM$)s/^(.*)@AD-REALM\.CORP\.FOO\.COM$/$1/g DEFAULT </value> </property>
For more information about name mapping rules, see Configuring the Mapping from Kerberos Principals to Short Names.
<< Configuring a Cluster-dedicated MIT KDC with Cross-Realm Trust | ©2016 Cloudera, Inc. All rights reserved | Integrating Hadoop Security with Alternate Authentication >> |
Terms and Conditions Privacy Policy |