<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>question Re: LDAP File Sync issue in Support Questions</title>
    <link>https://community.cloudera.com/t5/Support-Questions/LDAP-File-Sync-issue/m-p/163799#M126173</link>
    <description>&lt;P&gt;I follow all your setups but still I am getting Authentication exception that I mentioned below&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;ERROR: Exiting with exit code 1. 
REASON: Caught exception running LDAP sync. [LDAP: error code 49 - INVALID_CREDENTIALS: Bind failed: ERR_229 Cannot authenticate user uid=admin,ou=people,dc=hadoop,dc=apache,dc=org]; nested exception is javax.naming.AuthenticationException: [LDAP: error code 49 - INVALID_CREDENTIALS: Bind failed: ERR_229 Cannot authenticate user uid=admin,ou=people,dc=hadoop,dc=apache,dc=org]&lt;/STRONG&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 21 Dec 2016 12:35:46 GMT</pubDate>
    <dc:creator>narasimha_varma</dc:creator>
    <dc:date>2016-12-21T12:35:46Z</dc:date>
    <item>
      <title>LDAP File Sync issue</title>
      <link>https://community.cloudera.com/t5/Support-Questions/LDAP-File-Sync-issue/m-p/163794#M126168</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I'm using HDP 2.4. I'm preparing&lt;A href="https://community.hortonworks.com/articles/7341/nifi-user-authentication-with-ldap.html"&gt; nifi user authentication with ldap&lt;/A&gt;. When i try to sync ldap it shows below error. &lt;/P&gt;&lt;P&gt;[root@sandbox ~]ambari-server sync-ldap --users /root/users.txt 
Using python  /usr/bin/python2
Syncing with LDAP...
Enter Ambari Admin login: admin
Enter Ambari Admin password: 
Syncing specified users and groups...ERROR: Exiting with exit code 1. 
REASON: Caught exception running LDAP sync. localhost:33389; nested exception is javax.naming.CommunicationException: localhost:33389 [Root exception is java.net.ConnectException: Connection refused (Connection refused)]&lt;/P&gt;&lt;P&gt;ldap Setup has been done by &lt;A href="https://community.cloudera.com/legacyfs/online/attachments/10535-ldap-setup.txt"&gt;&lt;/A&gt;&lt;A href="https://community.cloudera.com/legacyfs/online/attachments/10535-ldap-setup.txt"&gt;&lt;/A&gt;&lt;A href="https://community.cloudera.com/legacyfs/online/attachments/10535-ldap-setup.txt"&gt;ldap-setup.txt&lt;/A&gt;.&lt;/P&gt;&lt;P&gt;My user.txt file contains:&lt;/P&gt;&lt;P&gt;varma/varma&lt;/P&gt;&lt;P&gt;pls tell me how to resolve this issue? and what is the value has to be given for primary url and base dn value while ambari-ldap setup?&lt;/P&gt;</description>
      <pubDate>Tue, 20 Dec 2016 16:27:12 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/LDAP-File-Sync-issue/m-p/163794#M126168</guid>
      <dc:creator>narasimha_varma</dc:creator>
      <dc:date>2016-12-20T16:27:12Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP File Sync issue</title>
      <link>https://community.cloudera.com/t5/Support-Questions/LDAP-File-Sync-issue/m-p/163795#M126169</link>
      <description>&lt;A rel="user" href="https://community.cloudera.com/users/14967/narasimhavarman.html" nodeid="14967"&gt;@Narasimma varman&lt;/A&gt;&lt;P&gt;1] From the attached ldap-setup.tx, looks like the port configured is 389 however the logs say's 33389, please make sure ldap server is installed on localhost.&lt;/P&gt;&lt;P&gt;2] BaseDN is a "valid" path in LDAP server from where users who login/sync to ambari server are search for. Below link gives a reference value however this will change per your setup.&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.hortonworks.com/HDPDocuments/Ambari-2.1.1.0/bk_Ambari_Security_Guide/content/_setting_up_ldap_user_authentication.html" target="_blank"&gt;https://docs.hortonworks.com/HDPDocuments/Ambari-2.1.1.0/bk_Ambari_Security_Guide/content/_setting_up_ldap_user_authentication.html&lt;/A&gt; &lt;/P&gt;&lt;P&gt;3] manager DN can any valid user/path in LDAP server, again the link shared above is for reference only, value will change as per your setup.&lt;/P&gt;</description>
      <pubDate>Tue, 20 Dec 2016 16:37:17 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/LDAP-File-Sync-issue/m-p/163795#M126169</guid>
      <dc:creator>sgowda</dc:creator>
      <dc:date>2016-12-20T16:37:17Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP File Sync issue</title>
      <link>https://community.cloudera.com/t5/Support-Questions/LDAP-File-Sync-issue/m-p/163796#M126170</link>
      <description>&lt;P&gt;Hi &lt;A rel="user" href="https://community.cloudera.com/users/14967/narasimhavarman.html" nodeid="14967"&gt;@Narasimma varman&lt;/A&gt;&lt;/P&gt;&lt;P&gt;After running ambari-server setup-ldap did you restart the Ambari Server?&lt;/P&gt;&lt;P&gt;The localhost:33389 error means Ambari Server hasn't been restarted and it's using the default configuration.&lt;/P&gt;</description>
      <pubDate>Tue, 20 Dec 2016 17:27:37 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/LDAP-File-Sync-issue/m-p/163796#M126170</guid>
      <dc:creator>aanghel</dc:creator>
      <dc:date>2016-12-20T17:27:37Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP File Sync issue</title>
      <link>https://community.cloudera.com/t5/Support-Questions/LDAP-File-Sync-issue/m-p/163797#M126171</link>
      <description>&lt;P&gt;I tried both 389,636 ports as per configured in ranger. But still this naming exeception with connection refused error. how to check ldap running or not on these port number?&lt;/P&gt;</description>
      <pubDate>Tue, 20 Dec 2016 18:48:25 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/LDAP-File-Sync-issue/m-p/163797#M126171</guid>
      <dc:creator>narasimha_varma</dc:creator>
      <dc:date>2016-12-20T18:48:25Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP File Sync issue</title>
      <link>https://community.cloudera.com/t5/Support-Questions/LDAP-File-Sync-issue/m-p/163798#M126172</link>
      <description>&lt;P&gt;Hi &lt;A rel="user" href="https://community.cloudera.com/users/14967/narasimhavarman.html" nodeid="14967"&gt;@Narasimma varman&lt;/A&gt;&lt;/P&gt;&lt;P&gt;After reading your message again it looks like you're trying to follow &lt;A href="https://community.hortonworks.com/articles/7341/nifi-user-authentication-with-ldap.html" target="_blank"&gt;https://community.hortonworks.com/articles/7341/nifi-user-authentication-with-ldap.html&lt;/A&gt; which at a close look is using the Demo LDAP as part of Knox.&lt;/P&gt;&lt;P&gt;The Knox Demo LDAP listens on port 33389 however it's not started automatically when you start Knox.&lt;/P&gt;&lt;P&gt;Please make sure you go to Knox in Ambari and select Start Demo LDAP from the Service Actions as per the screenshot from the link above: &lt;A href="https://community.hortonworks.com/storage/attachments/956-1.jpg" target="_blank"&gt;https://community.hortonworks.com/storage/attachments/956-1.jpg&lt;/A&gt;&lt;/P&gt;&lt;P&gt;You can verify if the Demo LDAP has started and listening on port 33389 by running:&lt;/P&gt;&lt;PRE&gt;netstat -tnlp|grep 33389&lt;/PRE&gt;&lt;P&gt;If you see a process listening then you can configure ambari-server setup-ldap with the following options (use admin-password when asked for the Manager password):&lt;/P&gt;&lt;PRE&gt;# ambari-server setup-ldap
Using python  /usr/bin/python
Setting up LDAP properties...
Primary URL* {host:port} (localhost:33389): localhost:33389
Secondary URL {host:port} : 
Use SSL* [true/false] (false): 
User object class* (person): person
User name attribute* (uid): uid
Group object class* (groupofnames): groupofnames
Group name attribute* (cn): cn
Group member attribute* (member): member
Distinguished name attribute* (dn): dn
Base DN* (dc=hadoop,dc=apache,dc=org): dc=hadoop,dc=apache,dc=org
Referral method [follow/ignore] (follow): 
Bind anonymously* [true/false] (false): false
Manager DN* (uid=admin,ou=people,dc=hadoop,dc=apache,dc=org): uid=admin,ou=people,dc=hadoop,dc=apache,dc=org
Enter Manager Password* : 
Re-enter password: 
====================
Review Settings
====================
authentication.ldap.managerDn: uid=admin,ou=people,dc=hadoop,dc=apache,dc=org
authentication.ldap.managerPassword: *****
Save settings [y/n] (y)? y
Saving...done
Ambari Server 'setup-ldap' completed successfully.&lt;/PRE&gt;&lt;P&gt;You might also need to turn off pagination as the Knox LDAP doesn't support it:&lt;/P&gt;&lt;PRE&gt;echo "authentication.ldap.pagination.enabled=false" &amp;gt;&amp;gt; /etc/ambari-server/conf/ambari.properties&lt;/PRE&gt;&lt;P&gt;Now, don't forget to restart Ambari Server and be careful that after running ambari-server sync-ldap --all, the admin user password will change to admin-password&lt;/P&gt;&lt;P&gt;Other users can be found by running this:&lt;/P&gt;&lt;PRE&gt;cat /etc/knox/conf/users.ldif|egrep "^uid|^userPassword"&lt;/PRE&gt;&lt;P&gt;And you can add new users by changing Advanced users-ldif under the Knox Config in Ambari.&lt;/P&gt;&lt;P&gt;Good luck!&lt;/P&gt;</description>
      <pubDate>Wed, 21 Dec 2016 05:45:21 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/LDAP-File-Sync-issue/m-p/163798#M126172</guid>
      <dc:creator>aanghel</dc:creator>
      <dc:date>2016-12-21T05:45:21Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP File Sync issue</title>
      <link>https://community.cloudera.com/t5/Support-Questions/LDAP-File-Sync-issue/m-p/163799#M126173</link>
      <description>&lt;P&gt;I follow all your setups but still I am getting Authentication exception that I mentioned below&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;ERROR: Exiting with exit code 1. 
REASON: Caught exception running LDAP sync. [LDAP: error code 49 - INVALID_CREDENTIALS: Bind failed: ERR_229 Cannot authenticate user uid=admin,ou=people,dc=hadoop,dc=apache,dc=org]; nested exception is javax.naming.AuthenticationException: [LDAP: error code 49 - INVALID_CREDENTIALS: Bind failed: ERR_229 Cannot authenticate user uid=admin,ou=people,dc=hadoop,dc=apache,dc=org]&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 21 Dec 2016 12:35:46 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/LDAP-File-Sync-issue/m-p/163799#M126173</guid>
      <dc:creator>narasimha_varma</dc:creator>
      <dc:date>2016-12-21T12:35:46Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP File Sync issue</title>
      <link>https://community.cloudera.com/t5/Support-Questions/LDAP-File-Sync-issue/m-p/163800#M126174</link>
      <description>&lt;P&gt;Thanks  for your response &lt;A href="https://community.hortonworks.com/users/10940/aanghel.html"&gt;Alexandru Anghe&lt;/A&gt;,&lt;/P&gt;&lt;P style="margin-left: 40px;"&gt;Finally, I successfully login Nifi with LDAP users&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.hortonworks.com/users/10940/aanghel.html"&gt;&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 21 Dec 2016 14:38:52 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/LDAP-File-Sync-issue/m-p/163800#M126174</guid>
      <dc:creator>narasimha_varma</dc:creator>
      <dc:date>2016-12-21T14:38:52Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP File Sync issue</title>
      <link>https://community.cloudera.com/t5/Support-Questions/LDAP-File-Sync-issue/m-p/163801#M126175</link>
      <description>&lt;P&gt;Thanks for your response &lt;A href="https://community.hortonworks.com/users/10616/sgowda.html"&gt;Santhosh B Gowda&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 21 Dec 2016 14:39:29 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/LDAP-File-Sync-issue/m-p/163801#M126175</guid>
      <dc:creator>narasimha_varma</dc:creator>
      <dc:date>2016-12-21T14:39:29Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP File Sync issue</title>
      <link>https://community.cloudera.com/t5/Support-Questions/LDAP-File-Sync-issue/m-p/163802#M126176</link>
      <description>&lt;P&gt;That's great to hear &lt;A rel="user" href="https://community.cloudera.com/users/14967/narasimhavarman.html" nodeid="14967"&gt;@Narasimma varman&lt;/A&gt; !&lt;/P&gt;&lt;P&gt;Can you accept the answer please so we know this issue / thread is closed?&lt;/P&gt;</description>
      <pubDate>Wed, 21 Dec 2016 17:36:48 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/LDAP-File-Sync-issue/m-p/163802#M126176</guid>
      <dc:creator>aanghel</dc:creator>
      <dc:date>2016-12-21T17:36:48Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP File Sync issue</title>
      <link>https://community.cloudera.com/t5/Support-Questions/LDAP-File-Sync-issue/m-p/163803#M126177</link>
      <description>&lt;P&gt;yes, I restart Ambari Server after running ambari-server setup-ldap&lt;/P&gt;</description>
      <pubDate>Thu, 22 Dec 2016 15:05:06 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/LDAP-File-Sync-issue/m-p/163803#M126177</guid>
      <dc:creator>narasimha_varma</dc:creator>
      <dc:date>2016-12-22T15:05:06Z</dc:date>
    </item>
  </channel>
</rss>

