Authentication/Authorization with Zones | Teradata Vantage - Using External Authentication and Authorization with Zones - Advanced SQL Engine - Teradata Database

Security Administration

Product
Advanced SQL Engine
Teradata Database
Release Number
17.05
17.00
Published
September 2020
Language
English (United States)
Last Update
2021-01-23
dita:mapPath
ied1556235912841.ditamap
dita:ditavalPath
lze1555437562152.ditaval
dita:id
B035-1100
lifecycle
previous
Product Category
Teradata Vantage™

You can externally authenticate zone users using LDAP or Kerberos, but you cannot externally authorize zone users. The logon for any externally authorized user that is mapped to a zone user fails.

Zone guests can be externally authenticated and authorized. You can grant zone access to external roles that are mapped to groups in which zone guests are members. For external authorization to access objects within a zone to work, you must grant both of the following:
  • Zone access to the zone guests
  • The required discretionary access control privileges on the zone objects to external roles that are active for the zone guests’ sessions.