Enabling Kerberos Authentication Using the Wizard
Required Role: Cluster Administrator or Full Administrator
Cloudera Manager provides a wizard for integrating your organization's Kerberos instance with your cluster to provide authentication services.
Kerberos must already be deployed in your organization and the Kerberos key distribution center (KDC) must be ready to use, with a realm established. For Hue and Oozie, the Kerberos realm must support renewable tickets.

- See MIT Kerberos home and MIT Kerberos 5 Release 1.8.6 documentation for more information about MIT Kerberos.
- See Direct to Active Directory and Microsoft Active Directory documentation for more information about using Active Directory as a KDC.
For Active Directory, you must have administrative privileges to the Active Directory instance for initial setup and for on-going management, or you will need to have the help of your AD administrator prior to and during the integration process. For example, administrative access is needed to access the Active Directory KDC, create principals, and troubleshoot Kerberos TGT/TGS-ticket-renewal and take care of any other issues that may arise.
OS | Packages Required |
---|---|
RHEL/CentOS 7, RHEL/CentOS 6, RHEL/CentOS 5 |
|
SLES |
|
Ubuntu or Debian |
|
Windows |
|
Support
- krb5-1.6.1 on Red Hat Enterprise Linux 5 and CentOS 5
- krb5-1.6.3 on SLES 11 Service Pack 1
- krb5-1.8.1 on Ubuntu
- krb5-1.8.2 on Red Hat Enterprise Linux 6 and CentOS 6
- krb5-1.9 on Red Hat Enterprise Linux 6.1
In addition, Cloudera supports the Kerberos version that ships with each supported operating system listed in CDH and Cloudera Manager Supported Operating Systems.
Continue reading:
- Step 1: Install Cloudera Manager and CDH
- Step 2: If You are Using AES-256 Encryption, Install the JCE Policy File
- Step 3: Get or Create a Kerberos Principal for the Cloudera Manager Server
- Step 4: Enabling Kerberos Using the Wizard
- Step 5: Create the HDFS Superuser
- Step 6: Get or Create a Kerberos Principal for Each User Account
- Step 7: Prepare the Cluster for Each User
- Step 8: Verify that Kerberos Security is Working
- Step 9: (Optional) Enable Authentication for HTTP Web Consoles for Hadoop Roles
<< Kerberos Concepts - Principals, Keytabs and Delegation Tokens | ©2016 Cloudera, Inc. All rights reserved | Step 1: Install Cloudera Manager and CDH >> |
Terms and Conditions Privacy Policy |