When two security-mode clusters managed by different FusionInsight Managers need to access each other's resources, the system administrator can configure cross-Manager mutual trust for them.
The secure usage scope of users in each system is called a domain. Each FusionInsight Manager must have a unique domain name. Cross-Manager access allows users to use resources across domains.
A maximum of 500 mutually trusted clusters can be configured.
Click next to the target cluster and select Stop. Enter the password of the cluster administrator. In the Stop Cluster dialog box that is displayed, click OK. Wait until the cluster is stopped.
Parameter |
Description |
---|---|
realm_name |
Enter the domain name of the peer system. |
ip_port |
Enter the KDC address of the peer system. Value format: IP address of the node accommodating the Kerberos service in the peer system:Port number
|
If you need to configure mutual trust for multiple Managers, click to add a new item and set parameters. A maximum of 16 systems can be mutually trusted. Click
to delete unnecessary configurations.
sh ${BIGDATA_HOME}/om-server/om/sbin/restart-RealmConfig.sh
The command is executed successfully if the following information is displayed:
Modify realm successfully. Use the new password to log into FusionInsight again.
After the restart, some hosts and services cannot be accessed and an alarm is generated. This problem can be automatically resolved in about 1 minute after restart-RealmConfig.sh is run.
Click next to the name of the target cluster and select Start. In the displayed Start Cluster dialog box, click OK. Wait until the cluster is started.