Create composite keytab for Ranger HA
If Kerberos is configured on your cluster, you must create a composite keytab.
- Log in to the Load balancer node
- Run kadmin.local if KDC server and LB node are same. Otherwise, login to the KDC server hosts and run the kadmin.local command
-
Run mkdir -p /etc/security/keytabs
- Add spnego principal entry of the LB node using ktadd -norandkey -kt /etc/security/keytabs/ranger.ha.keytab HTTP/hostname@EXAMPLE.COM
- Add spnego principal entry of the node where RANGER_ADMIN is first installed using ktadd -norandkey -kt /etc/security/keytabs/ranger.ha.keytab HTTP/hostname@EXAMPLE.COM
- Add spnego principal entry of the node where RANGER_ADMIN is next installed using ktadd -norandkey -kt /etc/security/keytabs/ranger.ha.keytab HTTP/hostname@EXAMPLE.COM
- Verify /etc/security/keytabs/ranger.ha.keytab having an entry of all the required spnego principals using klist -kt /etc/security/keytabs/ranger.ha.keytab
- scp /etc/security/keytabs/ranger.ha.keytab file to other nodes where RANGER_ADMIN is installed
- Update permission to chmod 444 /etc/security/keytabs/ranger.ha.keytab
-
Update ownership to chown ranger:hadoop
/etc/security/keytabs/ranger.ha.keytab