Authentication

EMR step (EMR API) is a straightforward way using AWS credentials to authenticate users. LDAP support is available for HiveServer2, Presto Coordinator, Spark Thrift Server, Hue Server, and Zeppelin Server. For SSH with EC2 key pair, the user ID is hadoop (super user).

Authentication with Kerberos involves using a secret-key cryptography to provide strong authentication so that passwords or other credentials aren't sent over the network in an unencrypted format. You can do cross-realm with AD and have all the corporate users SSH in as themselves. This is useful for auditing and governance purposes. You can easily launch a large cluster that is fully Kerberosized with KDC on the master node with service principals for all cluster nodes. So, if you want to do a one-way trust with your AD, you can SSH in as yourself.

For more details on using Kerberos authentication, refer to AWS documentation: https://docs.aws.amazon.com/emr/latest/ManagementGuide/emr-kerberos.html.
..................Content has been hidden....................

You can't read the all page of ebook, please click here login for view all page.
Reset
3.15.143.40