
7.17 Urika-GX Security Quick Reference Information
Configuration of LDAP Settings on Urika-GX
The Open LDAP server on Urika-GX runs on login node 1. For example, if the system's hostname is
hostnatme
,
then the Open LDAP service would run on
hostname-login1
. The particular ID of the login node (such as
nid00030
on a 48 node system) would change, based on the number of nodes in the system i.e. 16N, 32N or
48N. The Open LDAP server and can be connected with the site corporate LDAP server from which, groups,
permissions and user credentials will be inherited. Please refer to the site specific LDAP server documentation for
details on setup and configuration.
LDAP and User management Information
For details of how to add, enable and manage users on LDAP please refer to
.
●
Configure LDAP settings - The Open LDAP server on Urika-GX can be connected with the site/corporate
LDAP server, from which groups, permissions, and user credentials will be inherited.
●
Open LDAP service node - The Open LDAP service runs on login node 1 of Urika-GX system. For example,
if the Urika-GX hostname is
hostname
then Open LDAP service is running on
hostname
-login1. The
particular node (such as: nid00030) would change, based on the number of nodes in the system i.e. 16N, 32N
or 48N
●
Authenticate users - Urika-GX uses LDAP based authentication. System administrators can use LDAP
servers to setup user authentication.
●
Add a user to a group - Use the
usermod
command to add a user to an existing group.
●
Add a user to LDAP - Use the
ldapadd
command to add a user to LDAP.
●
Create a group on each node - In order to enable group permissions in HDFS, the changes on the Linux
system need to take place on the server that is running the NameNode service. If it is unclear which node is
running the NameNode service, run the
urika-inventory
command from the SMW. For consistency, it is
recommended to set up group(s) from the SMW on all nodes via
pdsh
. Use the
groupadd
command to
create a group on each node and the
hdfs groups
command to confirm that HDFS recognizes the new
group.
●
Change user passwords - Use the
ldappasswd
command to change user passwords.
●
Create HDFS home directory - Use the
hdfs dfs -mkdir
command to create a HDFS home directory.
●
Change user permissions - Use the
hadoop dfs -chown
command to change permissions on directory
to make new user the owner of home directory
The user authorization list uses LDAP. If this list is moved to a different location, the following items will need to be
modified to point to the new location:
●
Tenancy related configuration file, located at
/etc/sysconfig/uxtenant/global
on the SMW
Urika-GX tenant proxy PAM modules, located at
/etc/utp.d/pam_cray_utp.conf
on all the physical
nodes and tenant VM
For more information, refer to
Authentication and Authorization
on page 175
Security
S3016
241