Steps for new deployment

Here are high-level steps for implementing DSE Unified Authentication in a new deployment.

To implement authentication and authorization in a pre-established DataStax Enterprise (DSE) environment, additional precautions and steps are required. See Steps for production environments.


To configure DSE Unified Authentication:

  1. Ensure that required data for logins and permission management are accessible and in all datacenters. See Configuring the security keyspaces replication factors.

  2. Configure the system settings. See Enabling DSE Unified Authentication.

  3. Configuring authentication and authorization methods (schemes):

  4. Configuring JMX authentication: Requires changes to the for nodetool and dsetool to run against an authentication enabled cluster.

    The location of the file depends on the type of installation:

    • Package installations: /etc/dse/cassandra/

    • Tarball installations: <installation_location>/resources/cassandra/conf/

  5. Restart DSE. See Starting and stopping DataStax Enterprise.

    Nodes are vulnerable to malicious activity following the restart. Anybody can access the system using the default cassandra account with password cassandra. DataStax recommends isolating the cluster until after disabling the cassandra account.

  6. Set up your own root account and disable or drop the default, cassandra account. See Adding a superuser login.

    Using the default cassandra account may impact performance, because all requests including login execute with consistency level QUORUM. DataStax recommends only using this account to create your root account.

  7. Create roles that map to users in the configured schemes and grant permission to allow users access to database resources, such as keyspaces and tables. See Setting up logins and users.

    • Use the latest version of DataStax drivers in all applications connecting to DSE Unified Authentication-enabled transactional nodes. For more information, including supported authentication methods and externally-managed role assignment, see Authentication in DataStax drivers.

    • Apache Spark™ component limitations: DataStax Enterprise provides internal authentication support for connecting Apache Spark to DSE transactional nodes, not for authenticating between Spark components.

Was this helpful?

Give Feedback

How can we improve the documentation?

© 2025 DataStax | Privacy policy | Terms of use | Manage Privacy Choices

Apache, Apache Cassandra, Cassandra, Apache Tomcat, Tomcat, Apache Lucene, Apache Solr, Apache Hadoop, Hadoop, Apache Pulsar, Pulsar, Apache Spark, Spark, Apache TinkerPop, TinkerPop, Apache Kafka and Kafka are either registered trademarks or trademarks of the Apache Software Foundation or its subsidiaries in Canada, the United States and/or other countries. Kubernetes is the registered trademark of the Linux Foundation.

General Inquiries: +1 (650) 389-6000,