Common Content for Data Engineering
- Common Content for Data Engineering 10.2.2 HotFix 1
- All Products
Property
| Description
|
---|---|
default_realm
| Name of the Kerberos realm to which the Informatica domain services belong. The realm name must be in uppercase. The service realm name and the user realm name must be the same.
|
forwardable
| Allows a service to delegate client user credentials to another service. The Informatica domain requires application services to authenticate the client user credentials with other services.
Set to true.
|
default_tkt_enctypes
| Encryption types for the session key included in ticket-granting tickets (TGT). Set this property only if session keys must use specific encryption types. Ensure that the Kerberos Key Distribution Center (KDC) supports the encryption type that you specify.
Do not set this property to allow the Kerberos protocol to select the encryption type to use.
If the node hosts or Informatica client hosts use 256-bit encryption, install the Java Cryptography Extension (JCE) unlimited strength policy files on all node hosts and Informatica client hosts to avoid authentication issues.
|
rdns
| Determines whether reverse name lookup is used in addition to forward name lookup to canonicalize host names for use in service principal names.
Set to false.
|
renew_lifetime
| The default renewable lifetime for initial ticket requests.
|
ticket_lifetime
| The default lifetime for initial ticket requests.
|
udp_preference_limit
| Determines the protocol that Kerberos uses when it sends a message to the KDC.
Set to 1 to use the TCP protocol if the domain experiences intermittent Kerberos authentication failures.
|
[realms] COMPANY.COM = {...}
Property
| Description
|
---|---|
admin_server
| The name or IP address of the Kerberos administration server host.
You can include an optional port number, separated from the host name by a colon. Default is 749.
|
kdc
| The name or IP address of a host running the Key Distribution Center (KDC) for the realm.
You can include an optional port number, separated from the host name by a colon. Default is 88.
|
[realms] COMPANY.COM = { admin_server = KDC01.COMPANY.COM:749 kdc = KDC01.COMPANY.COM:88 }
[domain_realm] .company.com = COMPANY.COM company.com = COMPANY.COM
[libdefaults] default_realm = COMPANY.COM forwardable = true rdns = false renew_lifetime = 7d ticket_lifetime = 24h udp_preference_limit = 1 [realms] KERBREALM.COM = { admin_server = KDC01.COMPANY.COM:749 kdc = KDC01.COMPANY.COM:88 } [domain_realm] .company.com = COMPANY.COM company.com = COMPANY.COM