If you want to enable Kerberos authentication for the cluster, verify the following prerequisites:
Make sure that you merge the user and host keytab files before you enable Kerberos authentication for the Catalog Service.
Set the
udp_preference_limit
value to
1
in
$INFA_HOME/services/shared/security/krb5.conf
Make sure that the KDC certificate is present in the domain node.
If you want to enable Kerberos authentication for Enterprise Data Catalog deployed on a multi-node Informatica domain, make sure that you complete the following prerequisites:
Make sure that all the domain nodes include the krb5.conf file in the following directories:
$INFA_HOME/services/shared/security/
/etc/
in all cluster nodes.
Ensure that you use the same krb5.conf file on the Informatica domain and the cluster nodes.
Make sure that the
/etc/hosts
file of all cluster nodes and domain nodes include the krb hosts entry and a host entry for other nodes.
Install krb5-workstation in all domain nodes.
Make sure that the keytab file is present in a common location on all domain nodes.
Verify that you install the following prerequisite packages before you enable Kerberos for Enterprise Data Catalog on Red Hat Enterprise Linux:
krb5-workstation
krb5-libs
For Enterprise Data Catalog on SUSE Linux Enterprise Server, make sure that you install the following prerequisite packages: