> For the complete documentation index, see [llms.txt](https://docs.pentaho.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.pentaho.com/pdia-data-integration/9.3-data-integration/advanced-topics-pentaho-data-integration-overview/connecting-to-a-hadoop-cluster-with-the-pdi-client-article/adding-a-cluster-connection-connect-to-a-hadoop-cluster-with-the-pdi-client/secure-cluster-connections-add-hadoop-cluster-connection/kerberos-security-type-secure-hadoop-cluster-connections-in-pdi.md).

# Specify Kerberos security

Perform the following steps to specify the credentials for your Kerberos security.

1. Select **Kerberos** as your security type.
2. Click **Next** to select your Kerberos security method.
3. Choose one of the following security methods and specify the Kerberos credentials you obtained from your cluster administrator:
   * **Password**: Specify the **Authentication username** and **Password** options.

     ![Password options for Hadoop cluster secured with Kerberos](/files/1fysUk3qs6HKio25HVTn)

     If you are connected to the Pentaho Repository and are using secure impersonation, specify the additional **Impersonation username** and **Password** options. See **Try Pentaho Data Integration and Analytics** if your environment requires advanced settings, your server is on Windows, or you are using a Cloudera Impala database for secure impersonation.
   * **Keytab**: Specify the **Authentication username** and **Authentication Keytab** options. Click **Browse** to navigate to your keytab file.

     ![Keytab options for Hadoop cluster secured with Kerberos](/files/JxVtV6wxnrWC58v5kww7)

     If you are connected to the Pentaho Repository and are using secure impersonation, specify the additional **Impersonation username** and **Impersonation Keytab** options. See **Try Pentaho Data Integration and Analytics** if your environment requires advanced settings, your server is on Windows, or you are using a Cloudera Impala database for secure impersonation.
4. Click **Next** to test your connection. See [Configure and test connection](/pdia-data-integration/9.3-data-integration/advanced-topics-pentaho-data-integration-overview/connecting-to-a-hadoop-cluster-with-the-pdi-client-article/adding-a-cluster-connection-connect-to-a-hadoop-cluster-with-the-pdi-client/test-the-cluster-connection-add-hadoop-cluster-connection.md) for more information.

After you specify your security credentials, PDI tests the connection to your Hadoop cluster. If no errors occur during the connection, PDI is successfully connected to your Hadoop cluster.

**Note:** You can define different principal users for each of your named connections only if all the clusters for these connections are in the same Kerberos realm. See [MIT Kerberos Documentation](https://web.mit.edu/kerberos/krb5-devel/doc/admin/realm_config.html) for more information about Kerberos realms.

If you have problems, see troubleshooting sections of the **Administer Pentaho Data Integration and Analytics** document to resolve the errors, then test your connection again.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.pentaho.com/pdia-data-integration/9.3-data-integration/advanced-topics-pentaho-data-integration-overview/connecting-to-a-hadoop-cluster-with-the-pdi-client-article/adding-a-cluster-connection-connect-to-a-hadoop-cluster-with-the-pdi-client/secure-cluster-connections-add-hadoop-cluster-connection/kerberos-security-type-secure-hadoop-cluster-connections-in-pdi.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
