Checklist: Installing and Configuring the KDC
Ambari is able to configure Kerberos in the cluster to work with an existing MIT KDC, or existing Active Directory installation. This section describes the steps necessary to prepare for this integration.
You can choose to have Ambari connect to the KDC and automatically create the necessary Service and Ambari principals, generate and distribute the keytabs (“Automated Kerberos Setup”). Ambari also provides an advanced option to manually configure Kerberos. If you choose this option, you must create the principals, generate and distribute the keytabs. Ambari will not do this automatically (“Manual Kerberos Setup”).
- Microsoft Active Directory 2008 and above
- MIT Kerberos v5
- FreeIPA 4.x and above
- Using an existing MIT KDC
- Install a new MIT KDC (See "Optional: Install a new MIT KDC")
- Using an existing IPA
- Using an existing AD
- Using manual Kerberos setup
Option | Checklist |
---|---|
Using an existing MIT KDC |
|
Install a new MIT KDC | See “Optional: Install a new MIT KDC” |
Using an existing IPA | See “Optional: Use an Existing IPA” |
Using an existing AD |
|
Using manual Kerberos setup |
|