Enabling Kerberos when the IBM Spectrum Scale service is integrated

If Kerberos is to be enabled after IBM Spectrum Scale service is already integrated, the KDC_PRINCIPAL and KDC_PRINCIPAL_PASSWORD is required to be set in the IBM Spectrum Scale Configuration panel. Add the principal and password before enabling Kerberos. While enabling or disabling Kerberos, you do not need to stop the IBM Spectrum Scale service.

  1. Follow the steps in Setting up KDC server and enabling Kerberos to enable Kerberos.
    Note: During the enable Kerberos process, the Start and Test service is done. If the check services fail, you must exit, and go to the next step to add the KDC principal and password into IBM Spectrum Scale.
  2. From Ambari, click Spectrum Scale service > Configs tab > Advanced > Advanced gpfs-ambari-server-env.
    Type the KDC principal values and the KDC principal password values. Save the configuration.
    KDC Prinipal
  3. Restart all the services. Click Ambari panel > Service Actions > Stop All and Start All1.

    1For FPO cluster, do not run STOP ALL from the Ambari GUI. Refer to the Limitations > General section on how to properly stop IBM Spectrum® Scale.