16.10 - Using External Authentication and Authorization with Zones - Teradata Database

Teradata Database Security Administration

prodname
Teradata Database
vrm_release
16.10
created_date
June 2017
category
Administration
Security
featnum
B035-1100-161K

You can externally authenticate zone users using LDAP or Kerberos, but you cannot externally authorize zone users. The logon for any externally authorized user that is mapped to a zone user fails.

Zone guests can be externally authenticated and authorized. You can grant zone access to external roles that are mapped to groups in which zone guests are members. For external authorization to access objects within a zone to work, you must grant both of the following:

  • Zone access to the zone guests
  • The required discretionary access control privileges on the zone objects to external roles that are active for the zone guests’ sessions.