<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>question Ranger LDAP groups not working in Support Questions</title>
    <link>https://community.cloudera.com/t5/Support-Questions/Ranger-LDAP-groups-not-working/m-p/193540#M155601</link>
    <description>&lt;P&gt;I have successfully setup Ranger LDAP sync. I can see all users and mapped groups in Ranger. I also have added my machines to our domain and I am able to see the group mappings from active directory by typing hdfs groups &lt;EM&gt;username&lt;/EM&gt;. However, when I try to add an AD group to an HDFS folder through ranger the users in that group are still denied. Any suggestions?&lt;/P&gt;</description>
    <pubDate>Fri, 10 Nov 2017 22:59:18 GMT</pubDate>
    <dc:creator>david_j_william</dc:creator>
    <dc:date>2017-11-10T22:59:18Z</dc:date>
    <item>
      <title>Ranger LDAP groups not working</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Ranger-LDAP-groups-not-working/m-p/193540#M155601</link>
      <description>&lt;P&gt;I have successfully setup Ranger LDAP sync. I can see all users and mapped groups in Ranger. I also have added my machines to our domain and I am able to see the group mappings from active directory by typing hdfs groups &lt;EM&gt;username&lt;/EM&gt;. However, when I try to add an AD group to an HDFS folder through ranger the users in that group are still denied. Any suggestions?&lt;/P&gt;</description>
      <pubDate>Fri, 10 Nov 2017 22:59:18 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Ranger-LDAP-groups-not-working/m-p/193540#M155601</guid>
      <dc:creator>david_j_william</dc:creator>
      <dc:date>2017-11-10T22:59:18Z</dc:date>
    </item>
    <item>
      <title>Re: Ranger LDAP groups not working</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Ranger-LDAP-groups-not-working/m-p/193541#M155602</link>
      <description>&lt;A rel="user" href="https://community.cloudera.com/users/44193/davidjwilliamson.html" nodeid="44193"&gt;@David Williamson&lt;/A&gt;&lt;P&gt;Please take at look at the following link if this helps:&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.hortonworks.com/articles/145832/ranger-user-sync-issues-due-to-case-difference.html" target="_blank"&gt;https://community.hortonworks.com/articles/145832/ranger-user-sync-issues-due-to-case-difference.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 11 Nov 2017 03:35:59 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Ranger-LDAP-groups-not-working/m-p/193541#M155602</guid>
      <dc:creator>spolavarapu</dc:creator>
      <dc:date>2017-11-11T03:35:59Z</dc:date>
    </item>
    <item>
      <title>Re: Ranger LDAP groups not working</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Ranger-LDAP-groups-not-working/m-p/193542#M155603</link>
      <description>&lt;P&gt;Well I am not sure if that really applies to my situation. For example, I can add a user to the ranger pollicy and the ranger permissions work, but if I add a group instead it does not work.&lt;/P&gt;</description>
      <pubDate>Sat, 11 Nov 2017 03:48:58 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Ranger-LDAP-groups-not-working/m-p/193542#M155603</guid>
      <dc:creator>david_j_william</dc:creator>
      <dc:date>2017-11-11T03:48:58Z</dc:date>
    </item>
    <item>
      <title>Re: Ranger LDAP groups not working</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Ranger-LDAP-groups-not-working/m-p/193543#M155604</link>
      <description>&lt;P&gt;&lt;A rel="user" href="https://community.cloudera.com/users/44193/davidjwilliamson.html" nodeid="44193"&gt;@David Williamson&lt;/A&gt;,&lt;/P&gt;&lt;P&gt; Can you check the ranger audit logs and see which policy is denying access? Also, you can enable debug logs on the hdfs and see what is the group name sent as part of the authorization request to ranger.&lt;/P&gt;&lt;P&gt;If you can post the output of the "hdfs groups" for the failed case and the corresponding group names for policy configuration, that will be helpful.&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Sailaja. &lt;/P&gt;</description>
      <pubDate>Fri, 17 Nov 2017 02:45:04 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Ranger-LDAP-groups-not-working/m-p/193543#M155604</guid>
      <dc:creator>spolavarapu</dc:creator>
      <dc:date>2017-11-17T02:45:04Z</dc:date>
    </item>
    <item>
      <title>Re: Ranger LDAP groups not working</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Ranger-LDAP-groups-not-working/m-p/193544#M155605</link>
      <description>&lt;P&gt;After changing the case for the groups and reimporting everything then it synced from the hosts and now everything is working.&lt;/P&gt;</description>
      <pubDate>Fri, 17 Nov 2017 22:37:52 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Ranger-LDAP-groups-not-working/m-p/193544#M155605</guid>
      <dc:creator>david_j_william</dc:creator>
      <dc:date>2017-11-17T22:37:52Z</dc:date>
    </item>
    <item>
      <title>Re: Ranger LDAP groups not working</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Ranger-LDAP-groups-not-working/m-p/303841#M221745</link>
      <description>&lt;P&gt;Did you change only the groups to lowercase?&lt;/P&gt;</description>
      <pubDate>Fri, 02 Oct 2020 09:59:16 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Ranger-LDAP-groups-not-working/m-p/303841#M221745</guid>
      <dc:creator>BGabor</dc:creator>
      <dc:date>2020-10-02T09:59:16Z</dc:date>
    </item>
    <item>
      <title>Re: Ranger LDAP groups not working</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Ranger-LDAP-groups-not-working/m-p/304125#M221895</link>
      <description>&lt;P&gt;It's working for me now with our AD. I had to add the group as external with&amp;nbsp;@domainname.com, even if Ranger imports this without. You don't have to do anything else. The reason for this: in our environment if I executing groups [userid], I get the AD Groups in FQDN format, so you have to have it in Ranger in FQDN format too.&lt;/P&gt;</description>
      <pubDate>Fri, 09 Oct 2020 18:45:00 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Ranger-LDAP-groups-not-working/m-p/304125#M221895</guid>
      <dc:creator>BGabor</dc:creator>
      <dc:date>2020-10-09T18:45:00Z</dc:date>
    </item>
  </channel>
</rss>

