Tags » Kerberos

Enabling Security on Hadoop with Kerberos

1. Install the kerberos on a node with following packages :

yum install krb5-server krb5-libs krb5-auth-dialog krb5-workstation

2. Edit vi /etc/krb5.conf

 default = FILE:/var/log/krb5libs.log
 kdc = FILE:/var/log/krb5kdc.log
 admin_server = FILE:/var/log/kadmind.log


 default_realm = HADOOP.COM
 dns_lookup_realm = false
 dns_lookup_kdc = false
 ticket_lifetime = 24h
 renew_lifetime = 7d
 forwardable = true


 profile = /var/kerberos/krb5kdc/kdc.conf


 HADOOP.COM = {
  kdc = nn1.hadoop.com
  admin_server = nn1.hadoop.com
  default_domain = hadoop.com
 }


 .hadoop.com = HADOOP.COM
 hadoop.com = HADOOP.COM

… 1,385 more words

TECH::How to set up Kerberos on vSphere 6.0 servers for datastores on NFS

In case you were living under a rock somewhere, VMWare released vSphere 6.0 in March. I covered some of my thoughts from a NFS perspective in… 703 more words

Tech

Kerberoizing cluster

  • Download and Install the Kerberos Server and workstation on KDC server —  yum install -y krb5-workstation krb5-server
  • Configure KDC —   vi /var/kerberos/krb5kdc/kdc.conf //on server only (ports and realms etc.,)
  • 112 more words
Hadoop Security

Virtualization:Kerberos in production on virtual machines

At the moment I am investigating the possibility to use Kerberos as the primary authentication protocol for our cloud structure. We’ll probably follow through with this idea and for the sake of HA the best option would be multiple virtual machines. 15 more words

NASA Allowing Public To Name Features On Dwarf Planet Pluto

(CBS SF) — NASA has partnered with the International Astronomical Union to allow the public to nominate names for soon-to-be-discovered features on Pluto and its orbiting satellites. 243 more words

News

Enabling Kerberos via Cloudera Manager API

The Python API for Cloudera Manager is very powerful, anything you can do via the UI you can do via the API. I use it a lot for automating cluster initialisation. 771 more words

Automation

How to update group membership without logoff / logon /restart

This might be very useful for certain situations where you want to update a user’s or computer’s group membership without the need to re-logon / restart. 239 more words

Windows Server/Client