TLS Protection | Teradata Vantage - TLS Protection - Advanced SQL Engine - Teradata Database

Security Administration

Product
Advanced SQL Engine
Teradata Database
Release Number
17.10
Published
July 2021
Language
English (United States)
Last Update
2022-02-15
dita:mapPath
ppz1593203596223.ditamap
dita:ditavalPath
wrg1590696035526.ditaval
dita:id
B035-1100
lifecycle
previous
Product Category
Teradata Vantageā„¢

TLS protection encrypts the directory user ID and password during a bind to an LDAPv3-compliant directory, to prevent man-in-the-middle attacks and other security threats.

Teradata recommends TLS protection when:
  • LDAP authentication uses simple binding.
  • Kerberos authenticates users, while the directory authorizes user privileges in the database, resulting an automatic service bind (a type of simple bind).

You can configure LDAP protection properties in the LDAP, Kerberos, and SPNEGO mechanisms on Teradata Vantage nodes and on the Unity server, if the AuthorizationSupported property is set to yes. Also see LDAP Protection Properties.

If you implement TLS protection you should check, and if necessary reset, the AllowUnsafeServerConnection property in each mechanism that you configure for protection, to ensure optimal database operation with directories that supports IETF RFC 5746. See LdapClientTlsReqCert.

For configuration requirements when authentication is set for multiple directory services, see Creating the <LdapConfig> Section in the TdgssUserConfigFile.xml.