Configuring Kerberos Authentication in an Informatica Domain

Configuring Kerberos Authentication in an Informatica Domain

Step 5. Enable Delegation for the User Accounts in Active Directory

Step 5. Enable Delegation for the User Accounts in Active Directory

Enable delegation for the node process and HTTP process user accounts you created in Active Directory.
Delegated authentication happens when a user is authenticated with one service and that service uses the credentials of the authenticated user to connect to another service. Because services in the Informatica domain need to connect to other services to complete an operation, the Informatica domain requires the delegation option to be enabled in Active Directory.
You must enable delegation for all accounts for all of the accounts you created, except for the account that is used to access and search Active Directory during LDAP synchronization. Set delegation to
Trust this user for delegation to any service (Kerberos only)
in the Delegation tab in the properties dialog box for each user account.
The Delegation tab is not available in the properties dialog box until you run ktpass to create the keytab files.
The following image shows the Delegation tab in the nodeuser01 properties dialog box:

0 COMMENTS

We’d like to hear from you!