<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>question Why can't we use LDAP for Hadoop authentication? in Support Questions</title>
    <link>https://community.cloudera.com/t5/Support-Questions/Why-can-t-we-use-LDAP-for-Hadoop-authentication/m-p/147239#M109782</link>
    <description>&lt;P&gt;We all know that Hadoop needs Kerberos to be fully secure. LDAP is an authentication solution used with several Hadoop tools (Ambari, Nifi, Ambari, etc). Why we need Kerberos in addition of LDAP ?&lt;/P&gt;</description>
    <pubDate>Fri, 16 Sep 2022 10:38:53 GMT</pubDate>
    <dc:creator>tim_david1954</dc:creator>
    <dc:date>2022-09-16T10:38:53Z</dc:date>
    <item>
      <title>Why can't we use LDAP for Hadoop authentication?</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Why-can-t-we-use-LDAP-for-Hadoop-authentication/m-p/147239#M109782</link>
      <description>&lt;P&gt;We all know that Hadoop needs Kerberos to be fully secure. LDAP is an authentication solution used with several Hadoop tools (Ambari, Nifi, Ambari, etc). Why we need Kerberos in addition of LDAP ?&lt;/P&gt;</description>
      <pubDate>Fri, 16 Sep 2022 10:38:53 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Why-can-t-we-use-LDAP-for-Hadoop-authentication/m-p/147239#M109782</guid>
      <dc:creator>tim_david1954</dc:creator>
      <dc:date>2022-09-16T10:38:53Z</dc:date>
    </item>
    <item>
      <title>Re: Why can't we use LDAP for Hadoop authentication?</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Why-can-t-we-use-LDAP-for-Hadoop-authentication/m-p/147240#M109783</link>
      <description>&lt;P&gt;Here is your answer:
You can easily spoof your Hadoop cluster with a change of a simple environment variable.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="7536-1-spoof-security.gif" style="width: 581px;"&gt;&lt;img src="https://community.cloudera.com/t5/image/serverpage/image-id/21380iE9485877B8938292/image-size/medium?v=v2&amp;amp;px=400" role="button" title="7536-1-spoof-security.gif" alt="7536-1-spoof-security.gif" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;See also &lt;/P&gt;&lt;P&gt;&lt;A href="https://community.hortonworks.com/questions/2982/kerberos-adldap-and-ranger.html" target="_blank" rel="nofollow noopener noreferrer"&gt;https://community.hortonworks.com/questions/2982/kerberos-adldap-and-ranger.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 18 Aug 2019 13:19:45 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Why-can-t-we-use-LDAP-for-Hadoop-authentication/m-p/147240#M109783</guid>
      <dc:creator>amcbarnett</dc:creator>
      <dc:date>2019-08-18T13:19:45Z</dc:date>
    </item>
    <item>
      <title>Re: Why can't we use LDAP for Hadoop authentication?</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Why-can-t-we-use-LDAP-for-Hadoop-authentication/m-p/147241#M109784</link>
      <description>&lt;P&gt;&lt;A rel="user" href="https://community.cloudera.com/users/369/amcbarnett.html" nodeid="369"&gt;@Ancil McBarnett
&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Thanks, I am already aware of this. My question is more on why we can not use LDAP ? is it because Hadoop doesn't support it and we can some day implement and LDAP integration ? or because LDAP is lacking a feature, hence can not and will never replace Kerberos ?
&lt;A rel="user" href="https://community.cloudera.com/users/369/amcbarnett.html" nodeid="369"&gt;&lt;/A&gt; &lt;/P&gt;</description>
      <pubDate>Mon, 12 Sep 2016 22:14:41 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Why-can-t-we-use-LDAP-for-Hadoop-authentication/m-p/147241#M109784</guid>
      <dc:creator>tim_david1954</dc:creator>
      <dc:date>2016-09-12T22:14:41Z</dc:date>
    </item>
    <item>
      <title>Re: Why can't we use LDAP for Hadoop authentication?</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Why-can-t-we-use-LDAP-for-Hadoop-authentication/m-p/147242#M109785</link>
      <description>&lt;P&gt;You can use LDAP in ADDITION to Kerberos.  LDAP is the authentication authority. Kerberos is the ticketing system.

LDAP is like the DMV giving you your driver's licence.  Kerberos is your boarding pass to get on the plane.

Kerberos can be enabled with AD, FreeIPA as your LDAP in HAdoop.

Ambari, Nifi, Ranger will authenticate with those LDAPs.

The only exception is Hive where when Kerberos is enabled it replaces LDAP authentication.&lt;/P&gt;</description>
      <pubDate>Mon, 12 Sep 2016 22:36:11 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Why-can-t-we-use-LDAP-for-Hadoop-authentication/m-p/147242#M109785</guid>
      <dc:creator>amcbarnett</dc:creator>
      <dc:date>2016-09-12T22:36:11Z</dc:date>
    </item>
  </channel>
</rss>

