Nevermind on this: Sorted it out. Apparently Netezza KB https://www.ibm.com/docs/en/psfa/7.2.1?topic=jdbc-kerberos-authentication-clients contain no accurate info for Windows AD servers. Seems like all tested only on Linux to Linux and with use of local shell. Missing subjects:
- stronger encryption
- disabling principal logons (in case somebody steal / intercept NPS keytab)
- logging/debugging of above
- communication security (SSL/debugging) with Kerberos
Also seems for me that better now for NPS / JDBC is DBeaver. Aginity although natively support JDBC (and is now only option) , is enforcing password (one thing) and more important is that can't (or don't know how) to modify JVM startup to support custom config file.
As of now also MSLSA is a bit of struggle (though that not strictly related to Netezza - is for JDBC) - but there are workarounds....
huw@smart.associates can tell more about this stuff.
------------------------------
Adam Matusewicz
------------------------------