Hi, I'm Ask INFA!
What would you like to know?
ASK INFAPreview
Please to access Ask INFA.

Table of Contents

Search

  1. Preface
  2. Introduction to Informatica Security
  3. User Authentication
  4. LDAP Authentication
  5. Kerberos authentication
  6. SAML Authentication for Informatica Web Applications
  7. Domain Security
  8. Security Management in Informatica Administrator
  9. Users and Groups
  10. Privileges and Roles
  11. Permissions
  12. Audit Reports
  13. Appendix A: Command Line Privileges and Permissions
  14. Appendix B: Custom Roles

Security Guide

Security Guide

Enabling Kerberos on CDI-PC Nodes

Enabling Kerberos on
CDI-PC
Nodes

After you enable Kerberos in the domain, you must copy the Kerberos configuration file to each node in the domain. You must also configure web browsers to access the
CDI-PC
web applications.
Copy the keytab files to the following directory on each node:
<
CDI-PC
installation directory>\isp\config\keys
The keytab files you copy depends on whether you enable Kerberos authentication at the node level or at the process level.

Keytab Files at Node Level

Copy each keytab file generated at the node level to the corresponding node.
The following table shows the node to which to copy each keytab file:
Keytab File
Location on Node
<node name>.keytab
Copy each file to the corresponding node.
webapp_http.keytab
Copy each file to the corresponding gateway node.
ldapuser.keytab
Copy the file to each gateway node.

Keytab Files at Process Level

Copy each keytab file generated at the process level to the corresponding node.
The following table shows the node to which to copy each keytab file:
Keytab File
Location on Node
<node name>.keytab
Copy each file to the corresponding node.
webapp_http.keytab
Copy each file to the corresponding gateway node.
_AdminConsole.keytab
Copy each file to the corresponding gateway node.
<application service name>.keytab
Copy each file to the corresponding node on which the
CDI-PC
application service runs.
ldapuser.keytab
Copy the file to each gateway node.

Configure web browsers to access
CDI-PC
web applications.

In Microsoft Internet Explorer and Google Chrome, add the URL of the
CDI-PC
web applications, such as the Analyst tool, to the list of trusted sites.
If you are using Chrome version 41 or later, you must also set the AuthServerWhitelist and AuthNegotiateDelegateWhitelist policies.

0 COMMENTS

We’d like to hear from you!