Based on the security requirements of the user environment, you can modify the Kerberos and LDAP configurations in the OMS on FusionInsight Manager.
After the OMS service configuration parameters are modified, the corresponding OMS module needs to be restarted. In this case, FusionInsight Manager cannot be used.
Modifying the okerberos configuration
Parameter |
Description |
---|---|
KDC Timeout (ms) |
Timeout duration for an application to connect to Kerberos, in milliseconds. The value must be an integer. |
Max Retries |
Maximum number of retries for an application to connect to Kerberos, in seconds. The value must be an integer. |
LDAP Timeout (ms) |
Timeout duration for Kerberos to connect to LDAP, in milliseconds. |
LDAP Search Timeout (ms) |
Timeout duration for Kerberos to query user information in LDAP, in milliseconds. |
Kadmin Listening Port |
Port number of the Kadmin service. |
KDC Listening Port |
Port number of the kinit service. |
Kpasswd Listening Port |
Port number of the Kpasswd service. |
In the displayed dialog box, enter the password of the current login user and click OK. In the displayed confirmation dialog box, click OK.
Modifying the oldap configuration
In the displayed dialog box, enter the password of the current login user and click OK. In the displayed confirmation dialog box, click OK.
To reset the password of the LDAP account, you need to restart ACS. The procedure is as follows:
sh ${BIGDATA_HOME}/om-server/om/sbin/restart-RealmConfig.sh
The command is run successfully if the following information is displayed:
Modify realm successfully. Use the new password to log into FusionInsight again.
Restarting the cluster