Security Mechanism Policies | Teradata Vantage - 17.10 - About Security Mechanism Policies - Advanced SQL Engine - Teradata Database

Teradata Vantage™ - Advanced SQL Engine Security Administration

Product
Advanced SQL Engine
Teradata Database
Release Number
17.10
Release Date
July 2021
Content Type
Administration
Security
Publication ID
B035-1100-171K
Language
English (United States)

You can create security mechanism policies to restrict the mechanisms available to users when they log on to the database.

Users that are members of at least one policy can only use mechanisms in which they have membership. Users that are not members of any security mechanism policy are not restricted in their use of security mechanisms.

The TDNEGO mechanism itself is not restricted by security mechanism policy, but the mechanisms it selects may be restricted. Users do not have to be permitted to use TDNEGO, but they do have to be permitted to use mechanisms that TDNEGO might negotiate for them, so users need to be members of the mechanisms they want TDNEGO to pick for them. For example, if a user’s mechanism policy permits KRB5 and LDAP, then TDNEGO will restrict the user to those mechanisms.

To create a mechanism policy:

  1. Create the mechanisms container. See Creating the Mechanisms Container.
  2. Create mechanism objects in the mechanism container. See Creating Mechanism Objects in the Mechanisms Container.
  3. Specify the users that are members of the mechanism. See Adding Member Users to a Mechanism Policy.