Converting to two-way trust

Convert an existing one-way trust to a two-way (bidirectional) trust by configuring the trust relationship on the Active Directory side.

After the one-way trust is established, you can convert it to a two-way trust. This requires configuring a DNS conditional forwarder and a domain trust on your Active Directory server. Cloudera provides the specific values you need to complete this configuration.
  1. Go to the Cloudera Management Console.
  2. Select Environments.
  3. Select your public cloud environment.
  4. Select the FreeIPA tab.
  5. Navigate to the Trust section.
  6. Click Convert to Two-Way.
  7. In the instructions panel, note the following Cloudera-generated values:
    • DNS Domain: The FreeIPA domain to configure as a conditional forwarder.
    • IP Address: The FreeIPA IP address for the conditional forwarder.
    • Trust password: The shared secret for the domain trust.
  8. Configure the DNS conditional forwarder on your Active Directory DNS server.
    Add a conditional forwarder for the FreeIPA domain pointing to the provided IP address.
  9. Configure the domain trust on your Active Directory server.
    • For Active Directory (CDP CLI)
      1. Log in with a user who has Domain Administrator, Enterprise Administrator, or equivalent elevated privileges.
      2. Run the commands provided in the instructions panel on the Active Directory instance in a command prompt with administrative rights. You can click the Copy button on the right edge of the commands field, or you can use the Download button to download the commands.
    • For Active Directory (Windows Server 2025 GUI)

      Follow the steps in Setting up trust on Windows Server 2025.

  10. After completing the Active Directory configuration, return to the Clouderea Management Console and confirm that you have completed the steps.
  11. Click Validate and Configure to initiate the two-way trust conversion.
When the conversion is successful, the trust status changes to Active (two-way). Users authenticated against your Active Directory can now access services in your Cloudera on cloud environment, and vice versa.