Skip to main content
Question

Kerberos accounts

  • November 22, 2018
  • 2 replies
  • 20 views

savyuk

Hi, could someone please help me answer the following customer question:

We are trying to configure Vertica to be able to use Kerberos authentication. From the basic instruction (https://www.vertica.com/docs/9.1.x/HTML/index.htm#Authoring/Security/Kerberos/CreatingthePrincipalsandKeytabonActiveDirectory.htm) we have it is not clear how to configure integration with multiple nodes.

The cornerstone is that phrase, which is really ambiguous:
>>Create a Windows account (principal) for the Vertica service and one Vertica host for each node/host in the cluster.
The root of ambiguity is whether we should create 1 account for service and many for hosts, or we should create 1+1 account for each node. In fact, I’m writing this letter mostly because I am not sure if we need more than 2 keytab files for the whole cluster. To explain my situation I will shortly describe the steps I took.

We tried the first path (N+1) in the following way. I created two host accounts: vertica_dev_n1 and vertica_dev_n2, and one service account vertica_dev. Next, I issued keytab files for hosts with the same command as in original instruction:

cmd> ktpass -out ./host.[FDQN].keytab -princ host/[FDQN]@[REALM] -mapuser vertica_dev_n[N]  -mapop set -pass [PASSWORD] -ptype KRB5_NT_SRV_HST

Where FDQN – is replaced for fdqn for the vertica host, REALM is the same as domain but with uppercase, [N] – node number (from host name).

Next step was issuing keytab files for service, and here I tried to map two SPN to one AD user, by performing

cmd> ktpass -out ./vertica.[FDQN1].keytab -princ vertica/[FDQN1]@[REALM] -mapuser vertica_dev -mapop set -pass [PASS] -ptype KRB5_NT_PRINCIPAL
cmd> ktpass -out ./vertica.[FDQN2].keytab -princ vertica/[FDQN2]@[REALM] -mapuser vertica_dev -mapop add -pass [PASS] -ptype KRB5_NT_PRINCIPAL

The setspn -L command confirms the mapping of two SPN to one user.

After that I have copied all obtained keytabs to my host1 – which is a solo host in the cluster (it’s CE VM). After joining keytabs pairwise I tried to test everything with kinit. And the results was a bit confusing for me.

First, I tried the compound host1 keytab file (which is combined of host/host1 and vertica/host1 keytabs)

$> kinit vertica/[host1] -k -t compound_host1.keytab

returned ‘Client not found’ error.

To figure out what is wrong I performed configurational tests and verified that domain integration is working correctly. To my surprise, even the

$> kinit vertica/[host2] -k -t compound_host2.keytab

worked! And I received the ticket, though I was physically on host1.

Then I tested pure service keytab obtained from AD (without host keytab) and it also worked (for host2, not host1).

It is pretty clear that something is not done right on keytab issuing step, but the host2 keytab file seems legit and works.

This leads to the following questions:

  • First question from the very beginning – how many accounts in AD do we really need (or how to disambiguate the original instructions from docs) ?
  • What ‘host’ keytab is really used for? What happen if we omit it?
  • Can we use the single keytab on all hosts? Considering that in fact it works.
  • And, if possible, what are the best practices in ADKerberos/Vertica integration.

Looking forward for a reply!
Thanks in advance.

2 replies

Dingqiang
Forum|alt.badge.img+1
  • Participating Frequently
  • November 22, 2018
One of my customer also confused by our document about Kerberos on AD, I've sent following email to vertica-docfeedback@microfocus.com, but it seems nobody listen on that email address.

Regards,
DQ

From: "Liu, Ding-Qiang"
Date: Tuesday, August 7, 2018 at 15:05
To: "vertica-docfeedback@microfocus.com"
Subject: Feedback on Vertica Analytic Database 9.1.x documentation: Creating the Principals and Keytab on Active Directory

_______________________________________________________________

Help Topic ID: CreatingthePrincipalsandKeytabonActiveDirectory.htm

Product: Vertica Analytic Database 9.1.x

Topic Title: Creating the Principals and Keytab on Active Directory

Feedback: Could you explain why there should be a host/HOSTNAME@DOMAIN principal for keytab from Active Directory, but it’s not required by MIT KDC ? Sorry our customers are confused many times about this.

/usr/kerberos/sbin/ktutil
ktutil: rkt host.verticanode01.dc.com.keytab
ktutil: rkt vertica.verticanode01.dc.com.keytab
ktutil: list
slot KVNO Principal

poojan
  • New Participant
  • December 13, 2018

Hi,
I am sorry for the confusion caused by wording, I am actively working with the doc team to get the example fixed.

Each SPN will need its on account, here is a three node (node-01, node-02, node-03) example in powershell script.

Create account vertica and host for every host. (this password is never used)

dsadd user "CN=vertica-node-01,CN=Users,DC=vertqa,DC=local" -pwd P4ssword -pwdneverexpires yes -canchpwd no
dsadd user "CN=vertica-node-02,CN=Users,DC=vertqa,DC=local" -pwd P4ssword -pwdneverexpires yes -canchpwd no
dsadd user "CN=vertica-node-03,CN=Users,DC=vertqa,DC=local" -pwd P4ssword -pwdneverexpires yes -canchpwd no

dsadd user "CN=host-node-01,CN=Users,DC=vertqa,DC=local" -pwd P4ssword -pwdneverexpires yes -canchpwd no
dsadd user "CN=host-node-02,CN=Users,DC=vertqa,DC=local" -pwd P4ssword -pwdneverexpires yes -canchpwd no
dsadd user "CN=host-node-03,CN=Users,DC=vertqa,DC=local" -pwd P4ssword -pwdneverexpires yes -canchpwd no

Add the service principal name to a user by adding the ldap attribute to the cn of the user

setspn -S vertica/node-01.verticacorp.com vertica-node-01
setspn -S vertica/node-02.verticacorp.com vertica-node-02
setspn -S vertica/node-03.verticacorp.com vertica-node-03

setspn -S host/node-01.verticacorp.com host-node-01
setspn -S host/node-02.verticacorp.com host-node-02
setspn -S host/node-03.verticacorp.com host-node-03

Test whether SPNs are correctly set

setspn -L vertica-node-01
setspn -L vertica-node-02
setspn -L vertica-node-03

setspn -L host-node-01
setspn -L host-node-02
setspn -L host-node-03

Export keytab and map user

ktpass /princ vertica/node-01.verticacorp.com@VERTQA.LOCAL /out vertica-node-01.keytab /mapuser vertqa\vertica-node-01 /mapOp set /crypto ALL /rndPass /ptype KRB5_NT_PRINCIPAL

ktpass /princ vertica/node-02.verticacorp.com@VERTQA.LOCAL /out vertica-node-02.keytab /mapuser vertqa\vertica-node-02 /mapOp set /crypto ALL /rndPass /ptype KRB5_NT_PRINCIPAL

ktpass /princ vertica/node-03.verticacorp.com@VERTQA.LOCAL /out vertica-node-03.keytab /mapuser vertqa\vertica-node-03 /mapOp set /crypto ALL /rndPass /ptype KRB5_NT_PRINCIPAL

ktpass /princ host/node-01.verticacorp.com@VERTQA.LOCAL /out host-node-01.keytab /mapuser vertqa\host-node-01 /mapOp set /crypto ALL /rndPass /ptype KRB5_NT_PRINCIPAL

ktpass /princ host/node-02.verticacorp.com@VERTQA.LOCAL /out host-node-02.keytab /mapuser vertqa\host-node-02 /mapOp set /crypto ALL /rndPass /ptype KRB5_NT_PRINCIPAL

ktpass /princ host/node-03.verticacorp.com@VERTQA.LOCAL /out host-node-03.keytab /mapuser vertqa\host-node-03 /mapOp set /crypto ALL /rndPass /ptype KRB5_NT_PRINCIPAL

Test if the keytabs are generated correctly

ktpass /in vertica-node-01.keytab
ktpass /in vertica-node-02.keytab
ktpass /in vertica-node-03.keytab

ktpass /in host-node-01.keytab
ktpass /in host-node-02.keytab
ktpass /in host-node-03.keytab

Merge the keytabs using ktutil