Hi, could someone please help me answer the following customer question:
We are trying to configure Vertica to be able to use Kerberos authentication. From the basic instruction (https://www.vertica.com/docs/9.1.x/HTML/index.htm#Authoring/Security/Kerberos/CreatingthePrincipalsandKeytabonActiveDirectory.htm) we have it is not clear how to configure integration with multiple nodes.
The cornerstone is that phrase, which is really ambiguous:
>>Create a Windows account (principal) for the Vertica service and one Vertica host for each node/host in the cluster.
The root of ambiguity is whether we should create 1 account for service and many for hosts, or we should create 1+1 account for each node. In fact, I’m writing this letter mostly because I am not sure if we need more than 2 keytab files for the whole cluster. To explain my situation I will shortly describe the steps I took.
We tried the first path (N+1) in the following way. I created two host accounts: vertica_dev_n1 and vertica_dev_n2, and one service account vertica_dev. Next, I issued keytab files for hosts with the same command as in original instruction:
cmd> ktpass -out ./host.[FDQN].keytab -princ host/[FDQN]@[REALM] -mapuser vertica_dev_n[N] -mapop set -pass [PASSWORD] -ptype KRB5_NT_SRV_HST
Where FDQN – is replaced for fdqn for the vertica host, REALM is the same as domain but with uppercase, [N] – node number (from host name).
Next step was issuing keytab files for service, and here I tried to map two SPN to one AD user, by performing
cmd> ktpass -out ./vertica.[FDQN1].keytab -princ vertica/[FDQN1]@[REALM] -mapuser vertica_dev -mapop set -pass [PASS] -ptype KRB5_NT_PRINCIPAL cmd> ktpass -out ./vertica.[FDQN2].keytab -princ vertica/[FDQN2]@[REALM] -mapuser vertica_dev -mapop add -pass [PASS] -ptype KRB5_NT_PRINCIPAL
The setspn -L command confirms the mapping of two SPN to one user.
After that I have copied all obtained keytabs to my host1 – which is a solo host in the cluster (it’s CE VM). After joining keytabs pairwise I tried to test everything with kinit. And the results was a bit confusing for me.
First, I tried the compound host1 keytab file (which is combined of host/host1 and vertica/host1 keytabs)
$> kinit vertica/[host1] -k -t compound_host1.keytab
returned ‘Client not found’ error.
To figure out what is wrong I performed configurational tests and verified that domain integration is working correctly. To my surprise, even the
$> kinit vertica/[host2] -k -t compound_host2.keytab
worked! And I received the ticket, though I was physically on host1.
Then I tested pure service keytab obtained from AD (without host keytab) and it also worked (for host2, not host1).
It is pretty clear that something is not done right on keytab issuing step, but the host2 keytab file seems legit and works.
This leads to the following questions:
- First question from the very beginning – how many accounts in AD do we really need (or how to disambiguate the original instructions from docs) ?
- What ‘host’ keytab is really used for? What happen if we omit it?
- Can we use the single keytab on all hosts? Considering that in fact it works.
- And, if possible, what are the best practices in ADKerberos/Vertica integration.
Looking forward for a reply!
Thanks in advance.