Adding cross-realm trust to a Cloudera on cloud environment

Add a one-way cross-realm trust between the FreeIPA of your Cloudera environment and your corporate Active Directory.

  • Your Cloudera on cloud environment status must be Available with FreeIPA running.
  • Network connectivity must exist between the FreeIPA instances in your cloud environment and the Active Directory Domain Controller (KDC). Specifically:
    • FreeIPA must be able to reach the Active Directory Domain Controller on the required Kerberos and LDAP ports.
    • DNS resolution must be functional between both environments.
  • You must have access to the following details about your Active Directory environment:
    • KDC IP address: The IP address of the Domain Controller responsible for authentication and directory services.
    • KDC FQDN: The Fully Qualified Domain Name of your KDC (for example, dc.corp.example.com).
    • KDC Realm: The Kerberos realm of your Active Directory, typically your domain name in uppercase (for example, CORP.EXAMPLE.COM).
    • DNS server IP address: The IP address of the DNS server that can resolve your Active Directory domain endpoints.
  1. Go to the Cloudera Management Console.
  2. Select Environments.
  3. Select your existing public cloud environment.
  4. Select the FreeIPA tab.
  5. Navigate to the Trust section and click Add Trust.
  6. Enter the required information:
    • Select the on-premises environment, which automatically completes the required fields.
    • Enter the required information manually.
  7. Select the cluster from On-premises cluster to automatically populate Active Directory Settings, or enter the following optional information:
    Field Description
    KDC IP address The IP address of the Domain Controller responsible for authentication and other directory services. You can run the nslookup command on your KDC FQDN to locate this information.
    KDC FQDN The Fully Qualified Domain Name for your KDC, such as dc.corp.example.com. It uniquely identifies your domain controller on the network.
    KDC Realm The Kerberos realm, typically your domain name in uppercase (for example, CORP.EXAMPLE.COM).
    DNS server IP address The IP address of the DNS server that can resolve the Active Directory domain endpoints and the KDC server.
  8. Click Add Trust +.

    When the trust setup process completes, follow the instructions in the blue information panel to activate the trust.

    Cloudera performs the following validation and configuration steps:

    • Validates that FreeIPA has a load balancer configured.
    • Validates that the required trust packages are available (ipa-server-trust-ad).
    • Validates DNS forward and reverse lookup between FreeIPA and the Active Directory Domain Controller.
    • Prepares the FreeIPA server for AD trust.
    • Configures a DNS forward zone on FreeIPA for the Active Directory domain.
    • Establishes the one-way cross-realm trust.
  9. Click the Show Instructions button or the Active Directory Commands link.
  10. Select One-Way Trust or Two-Way Trust in the panel on the right.
  11. Copy the commands from the window or click the Download button.
  12. Run the commands.

    In case of Two-Way Trust, after running the commands, click the Convert button.

When the setup completes successfully, the trust status changes to Active (one-way). The environment status remains Available. At this point, FreeIPA can authenticate against your Active Directory using the one-way trust.

To enable full bidirectional trust -- allowing both FreeIPA and Active Directory to authenticate users from each other's realm -- proceed to Converting to two-way trust.