Sun Microsystems, Inc.  Oracle System Handbook - ISO 7.0 May 2018 Internal/Partner Edition
   Home | Current Systems | Former STK Products | EOL Systems | Components | General Info | Search | Feedback

Asset ID: 1-72-1645493.1
Update Date:2014-04-11
Keywords:

Solution Type  Problem Resolution Sure

Solution  1645493.1 :   How to enable Kerberos LDAP authentication in Exadata  


Related Items
  • Exadata Database Machine X2-2 Hardware
  •  
Related Categories
  • PLA-Support>Eng Systems>Exadata/ODA/SSC>Oracle Exadata>DB: Exadata_EST
  •  




In this Document
Symptoms
Cause
Solution
References


Created from <SR 3-8822356319>

Applies to:

Exadata Database Machine X2-2 Hardware - Version All Versions to All Versions [Release All Releases]
Information in this document applies to any platform.

Symptoms

How to enable Kerberos LDAP Authentication in Exadata.

The module / files required for enabling Kerberos LDAP authentication in Exadata are missing / not installed by default

Cause

To enable Kerberos LDAP authentication In OEL on Exadata database machines the module must be installed / present
 
The module /lib/security/pam_krb5.so is missing.

 

Solution

Install the module package for PAM Kerberos 5.

This can be done either using yum or by installing the package individually using the rpm utility.


To verify the installation is complete and the package is installed, execute the following two commands:
-----------------------------------
Open a terminal window and enter:
1: rpm -qa | grep pam

pam_pkcs11-0.5.3-26.el5
pam_smb-1.1.7-7.2.1
pam_passwdqc-1.0.2-1.2.2
pam_krb5-2.2.14-22.el5                  <<< Example of RPM installed.
pam-devel-0.99.6.2-6.el5_5.2
pam-0.99.6.2-6.el5_5.2
pam_ccreds-3-5

If the system returns -x.xx-x , where x is the version of the package, it is installed.

2: cd to /lib/security and verify pam_krb5.so exists.

Please be aware that future updates of the OS on the DB Node may remove this package requiring re-installation.

For additional information, please review:

<Note: 1541428.1> - Is it acceptable / supported to install additional or 3rd party software on Exadata machines and how to check for conflicts?


 

References

<NOTE:1382417.1> - PAM Product Page
<NOTE:1479793.1> - MySQL Authentication via Kerberos using the MySQL PAM Authentication Plugin; MySQL Enterprise Security
<NOTE:1478975.1> - Debugging the PAM Authentication Plugin in MySQL Enterprise Server
<NOTE:1521951.1> - PAM Authentication Plugin and External Services FAQ; MySQL Enterprise Security
<NOTE:1371858.1> - How to Configure MySQL Authentication to use LDAP Service via PAM
<NOTE:1541428.1> - Is it acceptable / supported to install additional or 3rd party software on Exadata machines and how to check for conflicts?

Attachments
This solution has no attachment
  Copyright © 2018 Oracle, Inc.  All rights reserved.
 Feedback