Enabling Knox SSO for Cloudera Data Visualization
You can configure Cloudera Data Visualization to use Knox Single Sign-On (SSO) if Knox is available in your cluster. The setup requires a Kerberized environment and includes configuring both Cloudera Data Visualization and Knox.
-
The cluster must be Kerberized.
-
Cloudera Data Visualization must be installed and Knox must be available on your cluster.
-
Kerberos authentication must be enabled for Cloudera Data Visualization.
If not already configured, enable Kerberos authentication for Cloudera Data Visualization.-
In Cloudera Manager, go to Clusters and select the Dataviz service.
-
Click the Configuration tab.
-
In the Search bar, type kerberos to filter the relevant settings.
-
Find the Enable Kerberos Authentication property.
-
Check the Dataviz (Service-Wide) box next to Enable Kerberos Authentication.
-
For Kerberos Principal, enter the Kerberos username (principal short name) the Cloudera Data Visualization service should use.
-
Click Save Changes.
-
Restart the Dataviz service for the changes to take effect.
-
-
Configure Cloudera Data Visualization for Knox SSO.
-
Make the Dataviz service definition available to Knox.
-
Update the Knox cdp-proxy topology.
Once configuration is complete, Cloudera Data Visualization will be accessible through Knox at: https://[***knox-host**]:[***port***]/gateway/cdp-proxy/dataviz/
Alternatively, you can also access Cloudera Data Visualization using the Knox Gateway home page.

Access will be granted based on the identity authenticated by Knox.