Configuring Site-Aware SRV Resource Records in TDGSS - Advanced SQL Engine - Teradata Database

Security Administration

Product
Advanced SQL Engine
Teradata Database
Release Number
17.05
17.00
Published
September 2020
Language
English (United States)
Last Update
2021-01-23
dita:mapPath
ied1556235912841.ditamap
dita:ditavalPath
lze1555437562152.ditaval
dita:id
B035-1100
lifecycle
previous
Product Category
Teradata Vantage™

You can configure the authentication mechanism for site-aware selection of a local directory by editing the LdapServerName property to a DNS SRV RR formatted site name, for example:

Mechanism Name="ldap">
           <MechanismProperties
               MechanismEnabled="yes"
               AuthorizationSupported="no"
               .
               .
               LdapClientMechanism="simple"
               LdapServerName="_ldap._tcp.SanDiegoHQ._sites.domain1.com"
               .
               .
               />

       </Mechanism>
In addition to performing the TDGSS configuration shown above, if the DNS service for the domain in which the database or Unity server resides is not the one where Active Directory registers its site-aware DNS SRV RRs (that is, a “foreign” service), then you must also manually configure the site-aware SRV RRs in the foreign DNS service.

For DNS SRV RR configuration instructions, see LdapServerName.

where:

Configuration Option Description
<Mechanism Name="ldap"> Site awareness requires directory authentication of the user, using the LDAP mechanism.
MechanismEnabled="yes" The LDAP mechanism must be enabled.
AuthorizationSupported="no" Site awareness functions whether or not the directory authorizes the user.
LdapClientMechanism="simple" The example is for a system using simple binding, but site awareness also supports DIGEST-MD5 binding.
LdapServerName="_ldap._tcp.SanDiegoHQ._sites.domain1.com" This setting requires a DNS SRV RR formatted site name, which identifies the local site directories available to authenticate the user.

When you configure the LdapServerName property for site awareness, the authenticating mechanism selects a directory at random from among the available local directories for the site.