Uploaded image for project: 'Ambari'
  1. Ambari
  2. AMBARI-5011

Security Wizard: enable Kerberos setup for Falcon

    XMLWordPrintableJSON

Details

    • Bug
    • Status: Resolved
    • Major
    • Resolution: Fixed
    • 1.5.0
    • 1.5.0
    • ambari-web
    • None

    Description

      To enable security we need add following properties to falcon-startup.properties:

      "*.falcon.http.authentication.kerberos.principal":"HTTP/_HOST@EXAMPLE.COM"
      "*.falcon.http.authentication.kerberos.keytab":"/etc/security/keytabs/spnego.service.keytab"
      "*.falcon.service.authentication.kerberos.principal":"falcon/_HOST@EXAMPLE.COM"
      "*.falcon.service.authentication.kerberos.keytab":"/etc/security/keytabs/falcon.service.keytab"
      "*.dfs.namenode.kerberos.principal":"nn/_HOST@EXAMPLE.COM"
      "*.falcon.http.authentication.type":"kerberos"
      "*.falcon.authentication.type":"kerberos"
      

      Also, we need to add

      <properties>
      	<property name="dfs.namenode.kerberos.principal" value="nn/_HOST@EXAMPLE.COM" />
      </properties>
      

      in cluster definition to make it works in secured mode.

      Attachments

        1. AMBARI-5011.patch
          65 kB
          Jaimin Jetly
        2. AMBARI-5011_2.patch
          0.7 kB
          Jaimin Jetly

        Issue Links

          Activity

            People

              jaimin Jaimin Jetly
              jaimin Jaimin Jetly
              Votes:
              0 Vote for this issue
              Watchers:
              2 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved: