Add a one-way cross-realm trust between the FreeIPA of your Cloudera environment and
your corporate Active Directory.
- Your Cloudera on cloud environment status must be
Available with FreeIPA running.
- Network connectivity must exist between the FreeIPA instances in your cloud
environment and the Active Directory Domain Controller (KDC). Specifically:
- FreeIPA must be able to reach the Active Directory Domain Controller on
the required Kerberos and LDAP ports.
- DNS resolution must be functional between both environments.
- You must have access to the following details about your Active Directory
environment:
- KDC IP address: The IP address of the Domain
Controller responsible for authentication and directory services.
- KDC FQDN: The Fully Qualified Domain Name of your
KDC (for example, dc.corp.example.com).
- KDC Realm: The Kerberos realm of your Active
Directory, typically your domain name in uppercase (for example,
CORP.EXAMPLE.COM).
- DNS server IP address: The IP address of the DNS
server that can resolve your Active Directory domain endpoints.
-
Go to the Cloudera Management Console.
-
Select Environments.
-
Select your existing public cloud environment.
-
Select the FreeIPA tab.
-
Navigate to the Trust section and click Add
Trust.
-
Enter the required information:
- Select the on-premises environment, which automatically completes the
required fields.
- Enter the required information manually.
-
Select the cluster from On-premises cluster to
automatically populate Active Directory Settings, or enter the following
optional information:
| Field |
Description |
| KDC IP address |
The IP address of the Domain Controller
responsible for authentication and other directory services.
You can run the nslookup command on your
KDC FQDN to locate this information. |
| KDC FQDN |
The Fully Qualified Domain Name for your KDC,
such as dc.corp.example.com. It uniquely identifies your
domain controller on the network. |
| KDC Realm |
The Kerberos realm, typically your domain name
in uppercase (for example,
CORP.EXAMPLE.COM). |
| DNS server IP
address |
The IP address of the DNS server that can
resolve the Active Directory domain endpoints and the KDC
server. |
-
Click Add Trust +.
When the trust setup process completes, follow the instructions in the blue
information panel to activate the trust.
Cloudera performs the following validation and configuration steps:
- Validates that FreeIPA has a load balancer configured.
- Validates that the required trust packages are available
(ipa-server-trust-ad).
- Validates DNS forward and reverse lookup between FreeIPA and
the Active Directory Domain Controller.
- Prepares the FreeIPA server for AD trust.
- Configures a DNS forward zone on FreeIPA for the Active
Directory domain.
- Establishes the one-way cross-realm trust.
-
Click the Show Instructions button or the
Active Directory Commands link.
-
Select One-Way Trust or Two-Way
Trust in the panel on the right.
-
Copy the commands from the window or click the Download
button.
-
Run the commands.
In case of Two-Way Trust, after running the commands, click the
Convert button.
When the setup completes successfully, the trust status changes to
Active (one-way). The environment status remains
Available. At this point, FreeIPA can authenticate
against your Active Directory using the one-way trust.
To enable full bidirectional trust -- allowing both FreeIPA and Active Directory to
authenticate users from each other's realm -- proceed to Converting to two-way trust.