<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>question Re: Groups not imported by Ranger User Sync from Active Directory in Support Questions</title>
    <link>https://community.cloudera.com/t5/Support-Questions/Groups-not-imported-by-Ranger-User-Sync-from-Active/m-p/168946#M131264</link>
    <description>&lt;P&gt;&lt;A rel="user" href="https://community.cloudera.com/users/2591/adija-1.html" nodeid="2591"&gt;@Adi Jabkowsky&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Can you please check once the property value set in configs as per - &lt;A href="https://docs.hortonworks.com/HDPDocuments/Ambari-2.2.0.0/bk_Ambari_Security_Guide/content/setting_up_hadoop_group_mappping_for_ldap_ad.html" target="_blank"&gt;https://docs.hortonworks.com/HDPDocuments/Ambari-2.2.0.0/bk_Ambari_Security_Guide/content/setting_up_hadoop_group_mappping_for_ldap_ad.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Also if possible please attach ranger ugsync logs.&lt;/P&gt;</description>
    <pubDate>Wed, 09 Nov 2016 02:12:31 GMT</pubDate>
    <dc:creator>sshimpi</dc:creator>
    <dc:date>2016-11-09T02:12:31Z</dc:date>
    <item>
      <title>Groups not imported by Ranger User Sync from Active Directory</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Groups-not-imported-by-Ranger-User-Sync-from-Active/m-p/168945#M131263</link>
      <description>&lt;P&gt;Hello experts &lt;/P&gt;&lt;P&gt;We have HDP 2.3.2 with Ranger 0.5 that is configured to sync users &amp;amp; groups from Active Directory.
SSSD is configured in all machines.&lt;/P&gt;&lt;P&gt;ranger.usersync.ldap.user.searchbase &amp;amp; ranger.usersync.group.searchbase are configured to the relevant OUs.&lt;/P&gt;&lt;P&gt;Usersync does sync users and maps to their AD groups without a problem. I'm able to grant users permissions using Ranger but i'd rather manage groups and not users. When i search for groups in Ranger i can only see groups that have been mapped from the synced users - and not all the groups in the ranger.usersync.group.searchbase OU.
Bottom line, usersync syncs only users &amp;amp; their own groups - but not groups that are in the anger.usersync.group.searchbase OU.&lt;/P&gt;&lt;P&gt;All groups in Ranger are from source "Internal" and none "external".&lt;/P&gt;&lt;P&gt;I've set the following values under "Advanced ranger-ugsync-site":&lt;/P&gt;&lt;P&gt;ranger.usersync.ldap.user.groupnameattribute&lt;/P&gt;&lt;P&gt;ranger.usersync.group.nameattribute&lt;/P&gt;&lt;P&gt;ranger.usersync.group.searchbase&lt;/P&gt;&lt;P&gt;ranger.usersync.group.searchenabled = true&lt;/P&gt;&lt;P&gt;ranger.usersync.group.usermapsyncenabled = true&lt;/P&gt;&lt;P&gt;Any ideas why usersync does not sync the groups ?&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Adi&lt;/P&gt;</description>
      <pubDate>Tue, 08 Nov 2016 22:29:53 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Groups-not-imported-by-Ranger-User-Sync-from-Active/m-p/168945#M131263</guid>
      <dc:creator>Adija1</dc:creator>
      <dc:date>2016-11-08T22:29:53Z</dc:date>
    </item>
    <item>
      <title>Re: Groups not imported by Ranger User Sync from Active Directory</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Groups-not-imported-by-Ranger-User-Sync-from-Active/m-p/168946#M131264</link>
      <description>&lt;P&gt;&lt;A rel="user" href="https://community.cloudera.com/users/2591/adija-1.html" nodeid="2591"&gt;@Adi Jabkowsky&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Can you please check once the property value set in configs as per - &lt;A href="https://docs.hortonworks.com/HDPDocuments/Ambari-2.2.0.0/bk_Ambari_Security_Guide/content/setting_up_hadoop_group_mappping_for_ldap_ad.html" target="_blank"&gt;https://docs.hortonworks.com/HDPDocuments/Ambari-2.2.0.0/bk_Ambari_Security_Guide/content/setting_up_hadoop_group_mappping_for_ldap_ad.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Also if possible please attach ranger ugsync logs.&lt;/P&gt;</description>
      <pubDate>Wed, 09 Nov 2016 02:12:31 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Groups-not-imported-by-Ranger-User-Sync-from-Active/m-p/168946#M131264</guid>
      <dc:creator>sshimpi</dc:creator>
      <dc:date>2016-11-09T02:12:31Z</dc:date>
    </item>
    <item>
      <title>Re: Groups not imported by Ranger User Sync from Active Directory</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Groups-not-imported-by-Ranger-User-Sync-from-Active/m-p/168947#M131265</link>
      <description>&lt;P&gt;&lt;A rel="user" href="https://community.cloudera.com/users/2648/sshimpi.html" nodeid="2648" target="_blank"&gt;@Sagar Shimpi&lt;/A&gt;
Thank you for replying.&lt;/P&gt;&lt;P&gt;I've completed all configurations for group mapping as described in the document, and group mapping works. The problem is that usersync does not import groups from LDAP. Just users and creates their groups as internal.
This means that groups from ldap which have no users (new groups) are unavailable in Ranger.&lt;/P&gt;&lt;P&gt;I can't attach the logs because they hold names and addresses from out production environment, however i can attach the beginning of the log file which shows the values for usersync and i can tell you that there are no errors in the log.&lt;/P&gt;&lt;P&gt;Here is the problem in screenshots:&lt;/P&gt;&lt;P&gt;Users from Active Directory and their respectable groups:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="9267-snap-2016-11-09-at-100611.png" style="width: 1556px;"&gt;&lt;img src="https://community.cloudera.com/t5/image/serverpage/image-id/20163iF3FBB81F6D6F587E/image-size/medium?v=v2&amp;amp;px=400" role="button" title="9267-snap-2016-11-09-at-100611.png" alt="9267-snap-2016-11-09-at-100611.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Groups are only "internal" &lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="9268-snap-2016-11-09-at-100724.png" style="width: 1114px;"&gt;&lt;img src="https://community.cloudera.com/t5/image/serverpage/image-id/20164i04BB57B40FD44B9F/image-size/medium?v=v2&amp;amp;px=400" role="button" title="9268-snap-2016-11-09-at-100724.png" alt="9268-snap-2016-11-09-at-100724.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;No external groups:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="9269-snap-2016-11-09-at-100733.png" style="width: 1192px;"&gt;&lt;img src="https://community.cloudera.com/t5/image/serverpage/image-id/20165i82188695F9D36516/image-size/medium?v=v2&amp;amp;px=400" role="button" title="9269-snap-2016-11-09-at-100733.png" alt="9269-snap-2016-11-09-at-100733.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;The begining of the log (i did change some of the OU names for privacy reasons):&lt;/P&gt;&lt;P&gt;&lt;EM&gt;09 Nov 2016 09:21:19  INFO UserGroupSync [UnixUserSyncThread] - initializing source: org.apache.ranger.ldapusersync.process.LdapUserGroupBuilder
09 Nov 2016 09:21:19  INFO UserGroupSync [UnixUserSyncThread] - Begin: initial load of user/group from source==&amp;gt;sink
09 Nov 2016 09:21:19  INFO LdapUserGroupBuilder [UnixUserSyncThread] - LDAPUserGroupBuilder updateSink started
09 Nov 2016 09:21:19  INFO LdapUserGroupBuilder [UnixUserSyncThread] - LdapUserGroupBuilder initialization started
09 Nov 2016 09:21:19  INFO LdapUserGroupBuilder [UnixUserSyncThread] - LdapUserGroupBuilder initialization completed with --  ldapUrl: ldap://&amp;lt;myldapserver&amp;gt;:389,  ldapBindDn: CN=&amp;lt;ldapuser&amp;gt;,OU=&amp;lt;blabla&amp;gt;,OU=Users,OU=Administration,DC=corp,DC=cellcom,DC=co,DC=il,  ldapBindPassword: ***** ,  ldapAuthenticationMechanism: simple,  searchBase: OU=Administration,DC=corp,DC=cellcom,DC=co,DC=il,  userSearchBase: OU=&amp;lt;usersOU&amp;gt;,OU=&amp;lt;parentou&amp;gt;,OU=Organization,OU=Administration,DC=corp,DC=cellcom,DC=co,DC=il,  userSearchScope: 2,  userObjectClass: person,  userSearchFilter: objectclass=top,  extendedUserSearchFilter: (&amp;amp;(objectclass=person)(objectclass=top)),  userNameAttribute: sAMAccountName,  userSearchAttributes: [sAMAccountName, ismemberof, memberof],  userGroupNameAttributeSet: [ismemberof, memberof],  pagedResultsEnabled: true,  pagedResultsSize: 500,  groupSearchEnabled: true,  groupSearchBase: OU=&amp;lt;ouforgroups&amp;gt;,OU=&amp;lt;parentou&amp;gt;,DC=corp,DC=cellcom,DC=co,DC=il,  groupSearchScope: 2,  groupObjectClass: group,  groupSearchFilter: ,  extendedGroupSearchFilter: (&amp;amp;(objectclass=group)(member={0})),  extendedAllGroupsSearchFilter: (&amp;amp;(objectclass=group)),  groupMemberAttributeName: member,  groupNameAttribute: distinguishedName,  groupUserMapSyncEnabled: true,  ldapReferral: ignore&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;
&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;I would expect usersync to import groups from the groups OU thanks to the following:&lt;/P&gt;&lt;P&gt;&lt;EM&gt;groupSearchEnabled: true, groupSearchBase: OU=&amp;lt;ouforgroups&amp;gt;,OU=&amp;lt;parentou&amp;gt;,DC=corp,DC=cellcom,DC=co,DC=il, &lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Any ideas ?&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 18 Aug 2019 10:53:01 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Groups-not-imported-by-Ranger-User-Sync-from-Active/m-p/168947#M131265</guid>
      <dc:creator>Adija1</dc:creator>
      <dc:date>2019-08-18T10:53:01Z</dc:date>
    </item>
    <item>
      <title>Re: Groups not imported by Ranger User Sync from Active Directory</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Groups-not-imported-by-Ranger-User-Sync-from-Active/m-p/168948#M131266</link>
      <description>&lt;P&gt;It seems that Ranger 0.5 retrieves just the groups that hold the users that it synced. Empty groups are not retrieved. In Ranger 0.6 it is fixed.&lt;/P&gt;&lt;P&gt;&lt;A href="https://issues.apache.org/jira/browse/RANGER-869" target="_blank"&gt;https://issues.apache.org/jira/browse/RANGER-869&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 10 Nov 2016 01:15:45 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Groups-not-imported-by-Ranger-User-Sync-from-Active/m-p/168948#M131266</guid>
      <dc:creator>Adija1</dc:creator>
      <dc:date>2016-11-10T01:15:45Z</dc:date>
    </item>
    <item>
      <title>Re: Groups not imported by Ranger User Sync from Active Directory</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Groups-not-imported-by-Ranger-User-Sync-from-Active/m-p/168949#M131267</link>
      <description>&lt;A rel="user" href="https://community.cloudera.com/users/2591/adija-1.html" nodeid="2591"&gt;@Adi Jabkowsky&lt;/A&gt;&lt;P&gt;Yes and I see an internal RPM filed with Hortonworks -  &lt;A href="https://hortonworks.jira.com/browse/RMP-4999" target="_blank"&gt;https://hortonworks.jira.com/browse/RMP-4999&lt;/A&gt;&lt;/P&gt;&lt;P&gt;and is Fixed in HDP2.5 version.&lt;/P&gt;</description>
      <pubDate>Thu, 10 Nov 2016 03:13:41 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Groups-not-imported-by-Ranger-User-Sync-from-Active/m-p/168949#M131267</guid>
      <dc:creator>sshimpi</dc:creator>
      <dc:date>2016-11-10T03:13:41Z</dc:date>
    </item>
    <item>
      <title>Re: Groups not imported by Ranger User Sync from Active Directory</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Groups-not-imported-by-Ranger-User-Sync-from-Active/m-p/168950#M131268</link>
      <description>&lt;P&gt;1. I'm have upgraded to HDP-2.5.3.0 with Ranger 0.6.0.2.5 1-2 months ago.
I have the same issue with users=external and groups=internal, and unfortunately I don't have access to the jira.com link.
Should I do anything for this to start working normally ?&lt;/P&gt;&lt;P&gt;2. Users "First Name", "Last Name" and "Email" + Groups "Description" is not synced correctly - where do I change this ?&lt;/P&gt;&lt;P&gt;3. Filters on User + Group sync doesn't seem to have effect eventhough I have configured:&lt;/P&gt;&lt;P&gt;- User Config -&amp;gt; User Search Filter: "membersOf=CN=&amp;lt;GROUP&amp;gt;,OU=&amp;lt;OU1&amp;gt;,OU=&amp;lt;OU2&amp;gt;,DC=&amp;lt;DC1&amp;gt;,DC=&amp;lt;DC2&amp;gt;"&lt;/P&gt;&lt;P&gt;- Group Configs -&amp;gt; Group Search Filter: "CN=&amp;lt;PART_OF_GROUP*&amp;gt;"&lt;/P&gt;&lt;P&gt;Perhaps these are all related... otherwise just disregard question 2+3 &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; !&lt;/P&gt;</description>
      <pubDate>Thu, 09 Feb 2017 17:01:16 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Groups-not-imported-by-Ranger-User-Sync-from-Active/m-p/168950#M131268</guid>
      <dc:creator>michael2</dc:creator>
      <dc:date>2017-02-09T17:01:16Z</dc:date>
    </item>
  </channel>
</rss>

