TDGSS AuthorizationSupported Property | Teradata Vantage - AuthorizationSupported - Analytics Database - Teradata Vantage

Security Administration

Deployment
VantageCloud
VantageCore
Edition
Enterprise
IntelliFlex
VMware
Product
Analytics Database
Teradata Vantage
Release Number
17.20
Published
June 2022
Language
English (United States)
Last Update
2024-04-05
dita:mapPath
hjo1628096075471.ditamap
dita:ditavalPath
qkf1628213546010.ditaval
dita:id
zuy1472246340572
lifecycle
latest
Product Category
Teradata Vantageā„¢

This property determines whether the mechanism supports directory authorization of users.

Valid Settings

Setting Description
yes The database accepts external authorization of user privileges.

Yes is the default for LDAP and TDNEGO.

no The database authorizes user privileges internally.

No is the default for all mechanisms, except for LDAP and TDNEGO.

Editing Guidelines

  • AuthorizationSupported must be set to yes if the directory authorizes user privileges, that is, if directory users are mapped to database objects.
  • You can edit this property in the TDGSS version of the TdgssUserConfigfile.xml on the database.
  • When the value of this property is set to yes, the gateway looks for authorization information from the directory specified in the LdapServerName property specified for the mechanism.
  • When the value of this property is set to no, the gateway ignores any authorization information in the directory. This setting allows you to authenticate directory users with LDAP, while authorizing user privileges in the database.
  • To set this property to yes for KRB5 or SPNEGO, you must copy the LdapServerName property from the TdgssLibraryConfigFile.xml into the TdgssUserConfigFile.xml, and then configure the property value.
  • Do not modify the AuthorizationSupported property for the TDNEGO mechanism because it does not use this property. TDNEGO passes the entire logon string to the underlying mechanisms, which means TDNEGO always supports authorization. Note, the underlying mechanism may not support authorization.