Setting up trust for existing Cloudera on cloud environments

Learn how to set up cross-realm trust between FreeIPA and Active Directory for an existing public cloud environment.

You can add a cross-realm Kerberos trust to an existing Cloudera on cloud environment to enable unified authentication and data access with your corporate Active Directory. This allows users authenticated against your on-premises Active Directory to access services and data in your Cloudera on cloud environment using their existing corporate credentials.

The trust setup is a two-stage process:
  1. Add Trust (one-way): Cloudera configures FreeIPA to establish a one-way cross-realm trust with your Active Directory. After this step, the trust is active, and the environment remains available. One-way trust is a trust relationship from FreeIPA to Active Directory; for example, on-premises Kerberos sessions can authenticate to cloud services.
  2. Convert to Two-Way (optional): You can optionally convert the trust to a two-way trust by configuring the trust relationship on the Active Directory side and then confirming the conversion in Cloudera.