Dynamically set LDAP Authenticator Connection Search Password
With LDAP enabled on your nodes, you can dynamically set a new value for the DSE LdapAuthenticator bean’s ConnectionSearchPassword attribute — without having to change static configuration in dse.yaml or system properties — by using a JMX console at runtime.
Prerequisites
If you haven’t already, enable LDAP.
In cassandra.yaml, verify that DSE Unified Authentication and Authorization features are configured. The following settings are defined by default.
-
Verify that
authenticatoris set toDseAuthenticatorin cassandra.yaml.authenticator: com.datastax.bdp.cassandra.auth.DseAuthenticator -
Verify that
authorizeris set toDseAuthorizerin cassandra.yaml.authorizer: com.datastax.bdp.cassandra.auth.DseAuthorizer -
Verify that
role_manageris set toDseRoleManagerin cassandra.yaml.role_manager: com.datastax.bdp.cassandra.auth.DseRoleManager
In dse.yaml, verify that LDAP has been enabled with a defined LDAP scheme.
Then, restart all nodes to apply the changes made in cassandra.yaml and dse.yaml.
Procedure via a JMX console
With LDAP enabled and DSE running, use a JMX console to navigate to the LdapAuthenticator bean.
This example uses JConsole.
-
In JConsole, connect to the running DSE process,
com.datastax.bdp.DseModule. Example:
-
On the Mbeans tab, under
com.datastax.bdp.core, navigate to theLdapAuthenticatorbean. TheObjectNameiscom.datastax.bdp:type=core,name=LdapAuthenticator, and theinterfaceClassNameiscom.datastax.bdp.cassandra.auth.LdapUtilsMXBean.
-
Open the Attributes pane and enter a new password for
ConnectionSearchPassword. Click into the Value column for the attribute. Example:
Never use passwords from documentation examples in your environment.
-
Click
Refresh. (The entered value is not displayed.) -
Result: the new
ConnectionSearchPasswordpassword is dynamically activated and used by the DSE LDAP Authenticator.