Details
-
Task
-
Status: Resolved
-
Major
-
Resolution: Fixed
-
2.5.0
Description
Add the followng Ambari configuration options to support Kerberos token authentication
- authentication.kerberos.enabled
- Determines whether to use Kerberos (SPNEGO) authentication when connecting Ambari: true to enable this feature; false, otherwise
- authentication.kerberos.spnego.principal
- The Kerberos principal name to use when verifying user-supplied Kerberos tokens for authentication via SPNEGO
- authentication.kerberos.spnego.keytab.file
- The Kerberos keytab file to use when verifying user-supplied Kerberos tokens for authentication via SPNEGO
- authentication.kerberos.user.types
- A comma-delimited (ordered) list of preferred user types to use when finding the Ambari user account for the user-supplied Kerberos identity during authentication via SPNEGO
- authentication.kerberos.auth_to_local.rules
- The auth-to-local rules set to use when translating a user's principal name to a local user name during authentication via SPNEGO.
NOTE: These properties are in the ambari.properties file since this feature may be enabled whether the rest of the cluster has Kerberos enabled or not.
Attachments
Attachments
Issue Links
- links to