Modify TDGSS Properties Without TPA Reset | SQL Engine 17.10 | Teradata Vantage - Modify TDGSS Without a TPA Reset - Analytics Database - Teradata Vantage

Teradata Vantageā„¢ - Analytics Database Release Summary - 17.20 What's New

Deployment
VantageCloud
VantageCore
Edition
Enterprise
IntelliFlex
VMware
Product
Analytics Database
Teradata Vantage
Release Number
17.20
Published
June 2022
Language
English (United States)
Last Update
2024-01-30
dita:mapPath
jva1628096041737.ditamap
dita:ditavalPath
qkf1628213546010.ditaval
dita:id
weq1472245453190
Product Category
Teradata Vantage

Previously, when the TDGSS configuration changed a TPA reset was required for the new values in the TDGSSCONFIG GDO to take effect. Now, the following can be modified without a TPA reset:

  • Any attribute or property whose name begins with "Ldap" for KRB5 and LDAP
  • MechanismEnabled property for KRB5, LDAP, JWT, and PROXY
  • AuthorizationSupported property for KRB5 and LDAP
  • LDAP Service ID and password with no impact to user LDAP logons
  • The following properties in the PROXY mechanism:
    • CertificateFile
    • PrivateKeyFile
    • PrivateKeyPassword
    • PrivateKeypasswordProtected
    • CACertFile
    • CACertDir
    • SigningHashAlgorithm
  • Any JWT mechanism property whose name begins with "JWT"
  • All canonicalizations including the lightweight authorization structures

Additionally, tdgsstestcfg is a new tool to test configuration changes before making them permanent with run_tdgssconfig.

Benefits

  • Decreases downtime previously caused by mechanism property reconfiguration.
  • Simplifies steps when modifying mechanism properties.
  • The run_tdgssconfig tool informs you when a tpareset is required.

Considerations

The following configuration changes still require a tpareset:

  • A tpareset is still required for changes to all other mechanism properties not listed
  • QoP configuration
  • Local or global policy configuration, including service name changes
  • TDNEGO and SPNEGO

Additional Information

For more information about security, see Teradata Vantageā„¢ - Analytics Database Security Administration, B035-1100.