If a user uses a security mode cluster to develop applications, the keytab file of the user needs to be obtained for security authentication. You can export keytab files on MRS Manager.
After a user password is changed, the exported keytab file becomes invalid, and you need to export a keytab file again.
Before downloading the keytab file of a Human-Machine user, the password of the user must be changed at least once on the Manager portal or a client; otherwise, the downloaded keytab file cannot be used For details, see Changing a User Password.
If the credential is downloaded to the server or a remote node, delete it after using it to prevent leakage.
The generated file is stored in the /tmp/FusionInsight-Keytab/ directory on the active OMS node by default. If the path does not exist, it will be created. If the path already has an authentication credential file, the existing authentication credential file will be overwritten. For user omm, write permission for the path is required.
After the file is generated, copy the downloaded package to another directory as the omm user.
Parameter |
Description |
Example Value |
|---|---|---|
Save to Path |
Path for storing the authentication credential file. If there is already a credential file in the path, it will be overwritten. For a remote node, write permission for the path is required. |
/tmp/FusionInsight-Keytab-Remote/ |
Host IP Address |
IP address of the remote node. |
x.x.x.x |
Host Port |
Host port of the remote node. |
22 |
Username |
Username for logging in to the remote node. For a remote node, write permission for the path is required. |
xxx |
Authentication Method |
You can choose one of the following methods:
|
Password |
Password |
This parameter is mandatory when Authentication Method is set to Password. This parameter indicates the password used for login. |
xxx |
The authentication credential includes the krb5.conf file of the Kerberos service.
After the authentication credential file is decompressed, you can obtain the following two files: