Skip to main content
  • Place orders quickly and easily
  • View orders and track your shipping status
  • Enjoy members-only rewards and discounts
  • Create and access a list of your products
  • Manage your Dell EMC sites, products, and product-level contacts using Company Administration.

ECS 3.6.2 Data Access Guide

PDF

Hadoop Kerberos authentication mode

When Kerberos and the ECS AD server are integrated, the Kerberos realm provides a single namespace of users so that the Hadoop users authenticated with kinit are recognized as credentialed ECS users.

In a Hadoop cluster running in Kerberos mode, there must be a one-way cross-realm trust from the Kerberos realm to the AD realm used to authenticate ECS users.

The following identity translation properties in the core-site.xml file are used to ensure the proper Hadoop-to-ECS user translation:

  • fs.permissions.umask-mode: Set the value to 022.
  • fs.viprfs.auth.anonymous_translation: Set the value to CURRENT_USER.
  • fs.viprfs.auth.identity_translation: Set the value to CURRENT_USER_REALM so the realm of users is auto-detected.

In addition, you must set the following properties in the core-site.xml file to define a service principal:

  • viprfs.security.principal: vipr/_HOST@REALM.COM where REALM.COM is replaced by your Kerberos realm name.

Rate this content

Accurate
Useful
Easy to understand
Was this article helpful?
0/3000 characters
  Please provide ratings (1-5 stars).
  Please provide ratings (1-5 stars).
  Please provide ratings (1-5 stars).
  Please select whether the article was helpful or not.
  Comments cannot contain these special characters: <>()\