Managing Kerberos Credentials Using Cloudera Manager
Minimum Required Role: Full Administrator
When Kerberos authentication is enabled for HDFS and MapReduce service instances, Cloudera Manager starts creating Kerberos principals for each role instance on the cluster at the end of the configuration process. Depending on the number of hosts and the number of HDFS and MapReduce role instances in the cluster, the process may take anywhere from a few seconds to several minutes.
After the process completes, view the list of Kerberos principals created for the cluster by using the Cloudera Manager Admin Console. Every host with HDFS and MapReduce role instances should have Kerberos principals.
If no principals have been created after 10 minutes, there may be an issue with the process. See Kerberos Credential-Generation Issues to troubleshoot.
Updating Kerberos Credentials in Cloudera Manager
If you change the user name or the password (or both) in the Active Directory KDC for the account used by Cloudera Manager for Kerberos authentication, you must also change it in Cloudera Manager. These credentials were stored during the Kerberos integration process (see Step 3: Add the Credentials for the Principal to the Cluster).
- Log in to Cloudera Manager Admin Console.
- Select .
- Click the Kerberos Credentials tab.
- Click the Import Kerberos Account Manager Credentials button.
- Enter the new user and password for the principal added to the Kerberos KDC in Step 2. Create Principal
for Cloudera Manager Server in the Kerberos KDC.
If you are using Red Hat IdM/FreeIPA, enter the IPA admin credentials here. These admin credentials are not stored, and are used only to create a new user and role (named cmadin-<random_id> and cmadminrole, respectively) and retrieve its keytab. Cloudera Manager stores this keytab for future Kerberos operations, such as regenerating the credentials of the CDH service accounts.
Managing Active Directory Account Properties
If you are using an Active Directory KDC, Cloudera Manager lets you configure Active Directory accounts and customize the credential regeneration process using the Cloudera Manager Admin Console. You can also use Cloudera Manager to configure the encryption types to be used by your Active Directory account. Once you modify any Active Directory account properties, you must regenerate Kerberos credentials to reflect those changes. The credential regeneration process requires you to delete existing accounts before new ones are created.
By default, Cloudera Manager does not delete accounts in Active Directory, which means that to regenerate Kerberos principals contained in Active Directory, you need to manually delete the existing Active Directory accounts. You can either delete and regenerate all existing Active Directory accounts, or only delete those with the userPrincipalName (or login name) that you will later manually select for regeneration. If the accounts haven't already been deleted manually, the regeneration process will throw an error message saying that deletion of accounts is required before you proceed.
Modifying Active Directory Account Properties Using Cloudera Manager
If you are using an Active Directory KDC, you can configure Active Directory account properties such as objectClass and accountExpires directly from the Cloudera Manager Admin Console. Any changes to these properties will be reflected in the regenerated Kerberos credentials.
- Go to the Cloudera Manager Admin Console and click the Administration tab.
- Select .
- Click the Kerberos category.
- Locate the Active Directory Account Properties and edit as required. By default, the property will be set to:
accountExpires=0,objectClass=top,objectClass=person,objectClass=organizationalPerson,objectClass=user
- Locate the Active Directory Password Properties and edit the field as needed. By default, the property will be set to:
length=12,minLowerCaseLetters=2,minUpperCaseLetters=2,minDigits=2,minSpaces=0,minSpecialChars=0,specialChars=?.!$%^*()-_+=~
- Click Save Changes.
- Regenerate new credentials with the new properties.
Enabling Credential Regeneration for Active Directory Accounts Using Cloudera Manager
To avoid having to delete accounts manually, enable the Active Directory Delete Accounts on Credential Regeneration property. By default, this property is disabled. After enabling this feature, Cloudera Manager will delete existing Active Directory accounts automatically when new ones are created during regeneration.
- Go to the Cloudera Manager Admin Console and click the Administration tab.
- Select .
- Click the Kerberos category.
- Locate the Active Directory Delete Accounts on Credential Regeneration and check the property to activate this capability.
- Click Save Changes.
Configuring Encryption Types for Active Directory KDC Using Cloudera Manager
- rc4-hmac
- aes128-cts
- aes256-cts
- des-cbc-crc
- des-cbc-md5
- Go to the Cloudera Manager Admin Console and click the Administration tab.
- Select .
- Click the Kerberos category.
- Locate the Kerberos Encryption Types and click to add the encryption types you want Active Directory to use (see the list above for supported encryption types enctypes).
- Check the checkbox for the Active Directory Set Encryption Types property. This will automatically set the Cloudera Manager AD account to use the encryption types configured in the previous step.
- Click Save Changes.
Moving Kerberos Principals to Another OU Within Active Directory
- Create the new OU on the Active Directory Server.
- Use AD's Delegate Control wizard to set the permissions on the new OU such that the configured Cloudera Manager admin account has the ability to Create, Delete and Manage User Accounts within this OU.
- Stop the cluster.
- Stop the Cloudera Management Service.
- In Active Directory, move all the Cloudera Manager and CDH components' user accounts to the new OU.
- Go to Cloudera Manager and go to .
- Go to the Kerberos Credentials tab and click Configuration.
- Select .
- Select .
- Locate the Active Directory Suffix property and edit the value to reflect the new OU name.
- Click Save Changes.
Viewing or Regenerating Kerberos Credentials Using Cloudera Manager
- Log in to Cloudera Manager Admin Console.
- Select .
- Click the Kerberos Credentials tab. The currently configured Kerberos principals for services running on the cluster display, such as:
- For HDFS, principals hdfs/hostname and host/hostname
- For MapReduce, principals mapred/hostname and host/hostname
- Select the principal from the list.
- Click Regenerate.
Running the Security Inspector
- Select .
- Click Security Inspector. Cloudera Manager begins several tasks to inspect the managed hosts.
- After the inspection completes, click Download Result Data or Show Inspector Results to review the results.