
6. Execute the following commands and enter the
cn=admin,cn=config
password when prompted for the
LDAP password.
#
ldapmodify -x -W -D "cn=admin,cn=config" -H ldap://localhost -f crayadmpw_meta.ldif
Enter LDAP Password: (enter the cn=admin,cn=config password)
modifying entry "olcDatabase={2}meta,cn=config"
The LDAP password for "
cn=crayadm,dc=urika,dc=com
" will now be reset to the new password that was
provided to
slappasswd
.
7. Log on to the SMW as root.
8. Edit the
global
file, located under the
/etc/sysconfig/uxtenant
directory, to configure the new
password in the environment variable
UXTENANT_GLOBAL_LDAP_ROOT_PW
For example, if the password requested by
slappasswd
was entered as "
changeme
" then the variable would
need to be set as:
UXTENANT_GLOBAL_LDAP_ROOT_PW="changeme"
7.10 Tableau Authorization and Authentication Mechanisms
Urika-GX ships with LDAP authentication enabled for Spark Thrift Server.
CAUTION: Enabling LDAP authentication for HiveServer2 may result in misconfiguration of HUE. To
resolve this issue, please follow the instructions documented at
SSL authentication for Tableau can be set up using instructions documented in Enable SSL on Urika-GX. Urika-
GX ships without authorization enabled. To enable storage based authorization for connecting to HiveServer2,
follow the instructions documented by Hive, visit
To learn more about using Tableau, visit
7.11 Enable SSL
Prerequisites
This procedure requires root privileges and needs the host name of the machine to be known. The host name
should resolve to the site's DNS.
About this task
Users access applications by using the login1 node's
https://IP:PORT
using SSL. HA Proxy decrypts SSL
and then forwards the HTTP communication to back end servers over the internal Aries or management network.
Back-end applications send their communication back to HA Proxy via HTTP. HA Proxy then encrypts the
response and send it back to the user using SSL. HA or redundant models are also supported so it is possible to
multiple back-ends available, as long as the data is in sync.
Urika-GX's SSL setup is depicted in the following figure:
Security
S3016
229