Cloudera Docs » » Ambari Security Guide
Ambari Security Guide
Also available as:
PDF
  • Contents
loading table of contents...
  • 1. Ambari Security Guide
  • 2. Configuring Ambari and Hadoop for Kerberos
    • 1. Kerberos Overview
    • 2. Hadoop and Kerberos Principals
    • 3. Installing and Configuring the KDC
      • 3.1. Use an Existing MIT KDC
      • 3.2. Use an Existing Active Directory
      • 3.3. Use Manual Kerberos Setup
      • 3.4. (Optional) Install a new MIT KDC
    • 4. Enabling Kerberos Security
      • 4.1. Installing the JCE
        • 4.1.1. Install the JCE
      • 4.2. Running the Kerberos Security Wizard
        • 4.2.1. Launching the Kerberos Wizard (Automated Setup)
        • 4.2.2. Launching the Kerberos Wizard (Manual Setup)
    • 5. Kerberos Client Packages
    • 6. Disabling Kerberos Security
    • 7. Customizing the Attribute Template
    • 8. Managing Admin Credentials
  • 3. Advanced Security Options for Ambari
    • 1. Configuring Ambari for LDAP or Active Directory Authentication
      • 1.1. Setting Up LDAP User Authentication
      • 1.2. Configure Ambari to use LDAP Server
        • 1.2.1. Example Active Directory Configuration
      • 1.3. Synchronizing LDAP Users and Groups
      • 1.4. Specific Set of Users and Groups
      • 1.5. Existing Users and Groups
      • 1.6. All Users and Groups
    • 2. Setting Up Hadoop Group Mapping for LDAP/AD
      • 2.1. Configure Hadoop Group Mapping for LDAP/AD Using SSSD (Recommended)
      • 2.2. Configure Hadoop Group Mapping in core-site.xml
      • 2.3. Manually Create the Users and Groups in the Linux Environment
    • 3. Configuring Ambari for Non-Root
      • 3.1. How to Configure Ambari Server for Non-Root
      • 3.2. How to Configure an Ambari Agent for Non-Root
        • 3.2.1. Sudoer Configuration
        • 3.2.2. Customizable Users
        • 3.2.3. Non-Customizable Users
        • 3.2.4. Commands
        • 3.2.5. Sudo Defaults
    • 4. Optional: Encrypt Database and LDAP Passwords
      • 4.1. Reset Encryption
      • 4.2. Remove Encryption Entirely
      • 4.3. Change the Current Master Key
    • 5. Optional: Set Up SSL for Ambari
    • 6. Optional: Ambari Web Inactivity Timeout
    • 7. Set Up Kerberos for Ambari Server
    • 8. Set Up Truststore for Ambari Server
    • 9. Optional: Set Up Two-Way SSL Between Ambari Server and Ambari Agents
    • 10. Optional: Configure Ciphers and Protocols for Ambari Server
    • 11. Optional: HTTP Cookie Persistence
  • 4. Enabling SPNEGO Authentication for Hadoop
    • 1. Configure Ambari Server for Authenticated HTTP
    • 2. Configuring HTTP Authentication for HDFS, YARN, MapReduce2, HBase, Oozie, Falcon and Storm
« Prev
Next »

​Chapter 3. Advanced Security Options for Ambari

This section describes several security options for an Ambari-monitored-and-managed Hadoop cluster.

  • Configuring Ambari for LDAP or Active Directory Authentication

  • Setting Up Hadoop Group Mapping for LDAP/AD

  • Configuring Ambari for Non-Root

  • Optional: Encrypt Database and LDAP Passwords

  • Optional: Set Up SSL for Ambari

  • Optional: Ambari Web Inactivity Timeout

  • Set Up Kerberos for Ambari Server

  • Set Up Truststore for Ambari Server

  • Optional: Set Up Two-Way SSL Between Ambari Server and Ambari Agents

  • Optional: Configure Ciphers and Protocols for Ambari Server

  • Optional: HTTP Cookie Persistence

© 2012–2020, Cloudera, Inc.
Document licensed under the Creative Commons Attribution ShareAlike 4.0 License.
Cloudera.com | Documentation | Support | Community