RDS for Db2 Can Now Join Your Self-Managed Active Directory Directly!
Hey everyone, it's me! Today I found a nice little update for Amazon RDS for Db2, so let me share it with you.
AWS What's NewWhat was announced?
Over on AWS What's New, they announced that Amazon RDS for Db2 can now directly domain-join a self-managed Microsoft Active Directory (AD). Whether your AD lives on-premises, on AWS, or in another cloud, you can connect your RDS for Db2 instances straight to it. Authentication uses Kerberos, so your database users get single sign-on.
The story so far
Until now, if you wanted Kerberos authentication against a self-managed AD, you first had to deploy AWS Managed Microsoft AD and set up a trust between that managed domain and your self-managed domain. That was an extra step or two of complexity.
What changes
From now on, you can use your existing self-managed AD directly for authentication and authorization. No more standing up a managed directory or wiring together a directory trust. Because you can reuse your existing identity infrastructure, it becomes easier to meet your compliance requirements.
Dive Deep
You can domain-join either by creating a new instance or by modifying an existing one. What you need is the credentials of a delegated AD service account, stored in AWS Secrets Manager and encrypted with AWS KMS.
Using self-managed AD is free of charge. And this feature is now generally available in all AWS Regions where Amazon RDS for Db2 is offered, including the AWS GovCloud (US) Regions. The setup steps are in the Amazon RDS for Db2 User Guide.
Wrap-up
- Amazon RDS for Db2 now supports direct domain-join to self-managed Microsoft AD (single sign-on via Kerberos)
- No more building AWS Managed Microsoft AD or setting up a directory trust
- Service account credentials are managed with Secrets Manager and KMS, and self-managed AD is free
- GA in all RDS for Db2 Regions, including GovCloud (US)
If you run Db2 with an existing AD and want to simplify your authentication setup, this update is for you!