<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>question Re: Configure LdapGroupsMapping in ClouderaManager in Support Questions</title>
    <link>https://community.cloudera.com/t5/Support-Questions/Configure-LdapGroupsMapping-in-ClouderaManager/m-p/292360#M216052</link>
    <description>&lt;P&gt;Thank you&amp;nbsp;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/4054"&gt;@bgooley&lt;/a&gt;&amp;nbsp;for answering, I have been with this problem for a month.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Perform the test with the ldapsearch command and the result was as follows:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT size="2"&gt;[c12345a@servernode ~]$ ldapsearch -x -H ldap://sub.us.domain.local:389 -D "ClouderaManager@SUB.US.DOMAIN.LOCAL" -W -b "DC=sub,DC=us,DC=domain,DC=local" "(&amp;amp;(objectClass=user)(sAMAccountName=c12345a))"&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;Enter LDAP Password:&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;# extended LDIF&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;#&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;# LDAPv3&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;# base &amp;lt;DC=sub,DC=us,DC=domain,DC=local&amp;gt; with scope subtree&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;# filter: (&amp;amp;(objectClass=user)(sAMAccountName=c12345a))&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;# requesting: ALL&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;#&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT size="2"&gt;# Charlie Brown, Computec, General Accounts, Accounts, sub.us.domain.local&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;dn: CN=Charlie Brown,OU=Computec,OU=General Accounts,OU=Accounts,DC=sub,DC=us,&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;DC=domain,DC=local&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;objectClass: top&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;objectClass: person&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;objectClass: organizationalPerson&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;objectClass: user&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;cn: Charlie Brown&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;sn: Brown&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;c: C&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;l: city D.C.&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;st: city&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;title: Admin&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;postalCode: 571&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;physicalDeliveryOfficeName: CO city principal office&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;givenName: Charlie&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;distinguishedName: CN=Charlie Brown,OU=Computec,OU=General Accounts,OU=Accounts,DC=sub,DC=us,DC=domain,DC=local&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;instanceType: 4&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;whenCreated: 20191128190334.0Z&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;whenChanged: 20200318065357.0Z&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;displayName: Brown, Charlie&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;uSNCreated: 36937614&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;memberOf: CN=Unix_KafkaServer04_kfk_group,OU=UnixSecondaryGroups,OU=DomainLATAM,OU=UnixGroups,OU=Groups,DC=sub,DC=us,DC=domain,DC=local&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;memberOf: CN=Unix_KafkaServer04_kfk_adm_Group,OU=UnixSecondaryGroups,OU=DomainLATAM,OU=UnixGroups,OU=Groups,DC=sub,DC=us,DC=domain,DC=local&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;memberOf: CN=Unix_KafkaServer03_kfk_group,OU=UnixSecondaryGroups,OU=DomainLATAM,OU=UnixGroups,OU=Groups,DC=sub,DC=us,DC=domain,DC=local&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;memberOf: CN=Unix_KafkaServer03_kfk_adm_Group,OU=UnixSecondaryGroups,OU=DomainLATAM,OU=UnixGroups,OU=Groups,DC=sub,DC=us,DC=domain,DC=local&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;memberOf: CN=Unix_KafkaServer02_kfk_group,OU=UnixSecondaryGroups,OU=DomainLATAM,OU=UnixGroups,OU=Groups,DC=sub,DC=us,DC=domain,DC=local&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;memberOf: CN=Unix_KafkaServer02_kfk_adm_Group,OU=UnixSecondaryGroups,OU=DomainLATAM,OU=UnixGroups,OU=Groups,DC=sub,DC=us,DC=domain,DC=local&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;memberOf: CN=Unix_KafkaServer01_kfk_group,OU=UnixSecondaryGroups,OU=DomainLATAM,OU=UnixGroups,OU=Groups,DC=sub,DC=us,DC=domain,DC=local&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;memberOf: CN=Unix_KafkaServer01_kfk_adm_Group,OU=UnixSecondaryGroups,OU=DomainLATAM,OU=UnixGroups,OU=Groups,DC=sub,DC=us,DC=domain,DC=local&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;memberOf: CN=Unix_KafkaServer04_Users,OU=UnixSecondaryGroups,OU=DomainLATAM,OU=UnixGroups,OU=Groups,DC=sub,DC=us,DC=domain,DC=local&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;memberOf: CN=Unix_KafkaServer03_Users,OU=UnixSecondaryGroups,OU=DomainLATAM,OU=UnixGroups,OU=Groups,DC=sub,DC=us,DC=domain,DC=local&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;memberOf: CN=Unix_KafkaServer02_Users,OU=UnixSecondaryGroups,OU=DomainLATAM,OU=UnixGroups,OU=Groups,DC=sub,DC=us,DC=domain,DC=local&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;memberOf: CN=Unix_KafkaServer01_users,OU=UnixSecondaryGroups,OU=DomainLATAM,OU=UnixGroups,OU=Groups,DC=sub,DC=us,DC=domain,DC=local&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;memberOf: CN=kfk_adm_Group,OU=General Groups,OU=Groups,DC=sub,DC=us,DC=domain,DC=local&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;memberOf: CN=kfk_group,OU=General Groups,OU=Groups,DC=sub,DC=us,DC=domain,DC=local&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;memberOf: CN=APP-MyPeopleExperience-Users,OU=General Groups,OU=Groups,DC=sub,DC=us,DC=domain,DC=local&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;memberOf: CN=APP-IDCentral_SkypeOnline_DesktopSharing,OU=Identity Central,OU=Application Groups,OU=Groups,DC=sub,DC=us,DC=domain,DC=local&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;memberOf: CN=ADMIN DomainLATAM Centrify KAFKA,OU=UserRoleGroups,OU=DomainLATAM,OU=UnixGroups,OU=Groups,DC=sub,DC=us,DC=domain,DC=local&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;memberOf: CN=APP-IDCentral_Remote_mailbox,OU=Identity Central,OU=Application Groups,OU=Groups,DC=sub,DC=us,DC=domain,DC=local&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;memberOf: CN=GlobalDLP,OU=Global DLP Groups,OU=Groups,DC=us,DC=domain,DC=local&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;memberOf: CN=APP-Sailpoint-IIQ-Users,OU=General Groups,OU=Groups,DC=sub,DC=us,DC=domain,DC=local&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;memberOf: CN=Allow External Email Access,OU=AzureSync,OU=Secured Groups,OU=Groups,DC=sub,DC=us,DC=domain,DC=local&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;memberOf: CN=O365.LicenseSkypefB,OU=Office365 Licensing,OU=Application Groups,OU=Groups,DC=sub,DC=us,DC=domain,DC=local&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;memberOf: CN=APP-Webex_Users,OU=AzureSync,OU=General Groups,OU=Groups,DC=sub,DC=us,DC=domain,DC=local&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;memberOf: CN=O365.LicenseSharepointOnline,OU=Office365 Licensing,OU=Application Groups,OU=Groups,DC=sub,DC=us,DC=domain,DC=local&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;memberOf: CN=O365.LicenseExchangeOnlineE3,OU=Office365 Licensing,OU=Application Groups,OU=Groups,DC=sub,DC=us,DC=domain,DC=local&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;memberOf: CN=O365.LicenseBasicServicesE3andEMS,OU=Office365 Licensing,OU=Application Groups,OU=Groups,DC=sub,DC=us,DC=domain,DC=local&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;memberOf: CN=O365.LicenseTeams,OU=Office365 Licensing,OU=Application Groups,OU=Groups,DC=sub,DC=us,DC=domain,DC=local&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;memberOf: CN=city - Internal Users Street ,OU=O365 DL Migration Project - Exclusions,OU=Distribution Groups,OU=Groups,DC=sub,DC=us,DC=domain,DC=local&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;memberOf: CN=GN_CO_Internet_Basic,OU=Computec,OU=Application Groups,OU=Groups,DC=sub,DC=us,DC=domain,DC=local&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;memberOf: CN=Archer.SUB_Users,OU=Archer Groups,OU=Application Groups,OU=Groups,DC=sub,DC=us,DC=domain,DC=local&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;memberOf: CN=UNIFY SUB Authorized Users,OU=General Groups,OU=Groups,DC=sub,DC=us,DC=domain,DC=local&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;uSNChanged: 74565754&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;co: CO&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;department: Sp Latam:Global&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;company: Domain S.A&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;proxyAddresses: x500:/o=ExchangeLabs/ou=Exchange Administrative Group (FBOH3SPDLT)/cn=Recipients/cn=9812d54ca41c79c8585597c61dc85-Charlie Brown&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;proxyAddresses: smtp:DMN-Charlie.Brown@domain.mail.onmicrosoft.com&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;proxyAddresses: SMTP:Charlie.Brown@domain.com&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;targetAddress: SMTP:DMN-Charlie.Brown@domain.mail.onmicrosoft.com&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;extensionAttribute1: 7282705&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;extensionAttribute2: 601&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;extensionAttribute6: CO city Oficina principal&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;extensionAttribute7: Contingent&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;extensionAttribute8: Contingent Worker&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;extensionAttribute9: Worker&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;mailNickname: C12345A&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;extensionAttribute12: NAC_&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;extensionAttribute13: C12345A@sub.us.domain.local&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;extensionAttribute15: NAC&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;name: Charlie Brown&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;objectGUID:: D8xfdlcMGkmuEghNTYiA==&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;userAccountControl: 512&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;badPwdCount: 0&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;codePage: 0&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;countryCode: 0&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;badPasswordTime: 132283366751489998&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;lastLogoff: 0&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;lastLogon: 132294797156347726&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;pwdLastSet: 132282329603092576&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;primaryGroupID: 513&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;userParameters:: bXR4Q2ZnUHJlc2VudCAgICAgICA&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;objectSid:: AQUAAAAAAAUVAAhkqT5EAb4UEAA==&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;accountExpires: 132507324000000000&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;logonCount: 1814&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;sAMAccountName: C12345A&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;sAMAccountType: 8030638&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;showInAddressBook: CN=Default Global Address List,CN=All Global Address Lists,CN=Address Lists Container,CN=Domain,CN=Microsoft Exchange,CN=Services,CN=Configuration,DC=domain,DC=local&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;managedObjects: CN=Unix_KafkaServer04_kfk_group,OU=UnixSecondaryGroups,OU=DomainLATAM,OU=UnixGroups,OU=Groups,DC=sub,DC=us,DC=domain,DC=local&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;managedObjects: CN=Unix_KafkaServer04_kfk_adm_Group,OU=UnixSecondaryGroups,OU=DomainLATAM,OU=UnixGroups,OU=Groups,DC=sub,DC=us,DC=domain,DC=local&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;managedObjects: CN=Unix_KafkaServer03_kfk_group,OU=UnixSecondaryGroups,OU=DomainLATAM,OU=UnixGroups,OU=Groups,DC=sub,DC=us,DC=domain,DC=local&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;managedObjects: CN=Unix_KafkaServer03_kfk_adm_Group,OU=UnixSecondaryGroups,OU=DomainLATAM,OU=UnixGroups,OU=Groups,DC=sub,DC=us,DC=domain,DC=local&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;managedObjects: CN=Unix_KafkaServer02_kfk_group,OU=UnixSecondaryGroups,OU=DomainLATAM,OU=UnixGroups,OU=Groups,DC=sub,DC=us,DC=domain,DC=local&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;managedObjects: CN=Unix_KafkaServer02_kfk_adm_Group,OU=UnixSecondaryGroups,OU=DomainLATAM,OU=UnixGroups,OU=Groups,DC=sub,DC=us,DC=domain,DC=local&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;managedObjects: CN=Unix_KafkaServer01_kfk_group,OU=UnixSecondaryGroups,OU=DomainLATAM,OU=UnixGroups,OU=Groups,DC=sub,DC=us,DC=domain,DC=local&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;managedObjects: CN=Unix_KafkaServer01_kfk_adm_Group,OU=UnixSecondaryGroups,OU=DomainLATAM,OU=UnixGroups,OU=Groups,DC=sub,DC=us,DC=domain,DC=local&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;managedObjects: CN=Unix_KafkaServer04_Users,OU=UnixSecondaryGroups,OU=DomainLATAM,OU=UnixGroups,OU=Groups,DC=sub,DC=us,DC=domain,DC=local&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;managedObjects: CN=Unix_KafkaServer03_Users,OU=UnixSecondaryGroups,OU=DomainLATAM,OU=UnixGroups,OU=Groups,DC=sub,DC=us,DC=domain,DC=local&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;managedObjects: CN=Unix_KafkaServer02_Users,OU=UnixSecondaryGroups,OU=DomainLATAM,OU=UnixGroups,OU=Groups,DC=sub,DC=us,DC=domain,DC=local&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;managedObjects: CN=Unix_KafkaServer01_users,OU=UnixSecondaryGroups,OU=DomainLATAM,OU=UnixGroups,OU=Groups,DC=sub,DC=us,DC=domain,DC=local&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;legacyExchangeDN: /o=Domain/ou=Exchange Administrative Group (FYDI23SPDL&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;T)/cn=Recipients/cn=Charlie Brown&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;userPrincipalName: Charlie.Brown@domain.com&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;lockoutTime: 0&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;objectCategory: CN=Person,CN=Schema,CN=Configuration,DC=domain,DC=local&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;msRADIUSFramedIPAddress: 17419&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;msRASSavedFramedIPAddress: 17419&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;dSCorePropagationData: 16010101000000.0Z&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;mS-DS-ConsistencyGuid:: D8xfdlcMGkmuEghNTYiyvA==&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;lastLogonTimestamp: 132289880375204341&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;msDS-ExternalDirectoryObjectId: User_3821ddab-be44-4cd5-956d-bdcb648ddbb7&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;mail: Charlie.Brown@domain.com&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;manager: CN=\,chief,OU=Infrastructure,OU=Technology,OU=Country,OU=Co&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;mputec,OU=General Accounts,OU=Accounts,DC=sub,DC=us,DC=domain,DC=local&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;middleName: Middle&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;msExchPoliciesExcluded: {261cfc-9e50-4857-861b-0cb8d7}&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;msExchArchiveStatus: 1&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;msExchRemoteRecipientType: 3&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;msExchVersion: 442&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;msExchUsageLocation: CO&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;msExchUMDtmfMap: emailAddress:945766&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;msExchUMDtmfMap: lastNameFirstName:56926694&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;msExchUMDtmfMap: firstNameLastName:945766566&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;msExchArchiveGUID:: ajkdQhlawkK6SQ3heE/lA==&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;msExchRecipientDisplayType: -21474842&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;msExchArchiveName: Personal Archive - Charlie Brown&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;msExchRecipientTypeDetails: 21474848&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT size="2"&gt;# search reference&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;ref: ldap://DomainDnsZones.sub.us.domain.local/DC=DomainDnsZones,DC=sub,DC=u&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;s,DC=domain,DC=local&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT size="2"&gt;# search result&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;search: 2&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;result: 0 Success&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT size="2"&gt;# numResponses: 3&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;# numEntries: 1&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;# numReferences: 1&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The clouderamanager user has the possibility to consult the AD, what other problem could it be?&lt;/P&gt;&lt;P&gt;Thanks for the help&lt;/P&gt;</description>
    <pubDate>Tue, 24 Mar 2020 02:00:39 GMT</pubDate>
    <dc:creator>WilsonLozano</dc:creator>
    <dc:date>2020-03-24T02:00:39Z</dc:date>
    <item>
      <title>Configure LdapGroupsMapping in ClouderaManager</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Configure-LdapGroupsMapping-in-ClouderaManager/m-p/292149#M215923</link>
      <description>&lt;P&gt;Currently I have a problem with configuring the LdapGroupsMapping, I cannot get the groups of the users and it generates the following error message with the command:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;$hadoop org.apache.hadoop.security.UserGroupInformation&lt;/P&gt;
&lt;P&gt;20/03/19 16:44:20 WARN security.LdapGroupsMapping: Failed to get groups for user c12345a&lt;/P&gt;
&lt;P&gt;(retry=0) by javax.naming.NamingException: [LDAP: error code 1 - 000004DC: LdapErr: DSID-0C090A4C, comment: In order to perform this operation a successful bind must be completed on the connection., data 0, v3839]; remaining name 'DC=sub,DC=us,DC=domain,DC=local'&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;$hdfs dfsadmin -refreshUserToGroupsMappings&lt;BR /&gt;Refresh user to groups mapping successful&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;$hdfs groups&lt;BR /&gt;c12345a@SUB.US.DOMAIN.LOCAL :&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;the core-site.xml configuration is as follows&lt;/P&gt;
&lt;P&gt;-&amp;lt;property&amp;gt;&lt;BR /&gt;&amp;lt;name&amp;gt;hadoop.security.group.mapping&amp;lt;/name&amp;gt;&lt;BR /&gt;&amp;lt;value&amp;gt;org.apache.hadoop.security.LdapGroupsMapping&amp;lt;/value&amp;gt;&lt;BR /&gt;&amp;lt;/property&amp;gt;&lt;BR /&gt;-&amp;lt;property&amp;gt;&lt;BR /&gt;&amp;lt;name&amp;gt;hadoop.security.group.mapping.ldap.url&amp;lt;/name&amp;gt;&lt;BR /&gt;&amp;lt;value&amp;gt;ldap://sub.us.domain.local:389&amp;lt;/value&amp;gt;&lt;BR /&gt;&amp;lt;/property&amp;gt;&lt;BR /&gt;-&amp;lt;property&amp;gt;&lt;BR /&gt;&amp;lt;name&amp;gt;hadoop.security.group.mapping.ldap.use.ssl&amp;lt;/name&amp;gt;&lt;BR /&gt;&amp;lt;value&amp;gt;true&amp;lt;/value&amp;gt;&lt;BR /&gt;&amp;lt;/property&amp;gt;&lt;BR /&gt;-&amp;lt;property&amp;gt;&lt;BR /&gt;&amp;lt;name&amp;gt;hadoop.security.group.mapping.ldap.ssl.keystore&amp;lt;/name&amp;gt;&lt;BR /&gt;&amp;lt;value&amp;gt;{{CMF_CONF_DIR}}/cm-auto-global_truststore.jks&amp;lt;/value&amp;gt;&lt;BR /&gt;&amp;lt;/property&amp;gt;&lt;BR /&gt;-&amp;lt;property&amp;gt;&lt;BR /&gt;&amp;lt;name&amp;gt;hadoop.security.group.mapping.ldap.bind.user&amp;lt;/name&amp;gt;&lt;BR /&gt;&amp;lt;value&amp;gt;ClouderaManager@SUB.US.DOMAIN.LOCAL&amp;lt;/value&amp;gt;&lt;BR /&gt;&amp;lt;/property&amp;gt;&lt;BR /&gt;-&amp;lt;property&amp;gt;&lt;BR /&gt;&amp;lt;name&amp;gt;hadoop.security.group.mapping.ldap.base&amp;lt;/name&amp;gt;&lt;BR /&gt;&amp;lt;value&amp;gt;DC=sub,DC=us,DC=domain,DC=local&amp;lt;/value&amp;gt;&lt;BR /&gt;&amp;lt;/property&amp;gt;&lt;BR /&gt;-&amp;lt;property&amp;gt;&lt;BR /&gt;&amp;lt;name&amp;gt;hadoop.security.group.mapping.ldap.search.filter.user&amp;lt;/name&amp;gt;&lt;BR /&gt;&amp;lt;value&amp;gt;(&amp;amp;(objectClass=user)(sAMAccountName={0}))&amp;lt;/value&amp;gt;&lt;BR /&gt;&amp;lt;/property&amp;gt;&lt;BR /&gt;-&amp;lt;property&amp;gt;&lt;BR /&gt;&amp;lt;name&amp;gt;hadoop.security.group.mapping.ldap.search.filter.group&amp;lt;/name&amp;gt;&lt;BR /&gt;&amp;lt;value&amp;gt;(objectClass=group)&amp;lt;/value&amp;gt;&lt;BR /&gt;&amp;lt;/property&amp;gt;&lt;BR /&gt;-&amp;lt;property&amp;gt;&lt;BR /&gt;&amp;lt;name&amp;gt;hadoop.security.group.mapping.ldap.search.attr.member&amp;lt;/name&amp;gt;&lt;BR /&gt;&amp;lt;value&amp;gt;member&amp;lt;/value&amp;gt;&lt;BR /&gt;&amp;lt;/property&amp;gt;&lt;BR /&gt;-&amp;lt;property&amp;gt;&lt;BR /&gt;&amp;lt;name&amp;gt;hadoop.security.group.mapping.ldap.search.attr.group.name&amp;lt;/name&amp;gt;&lt;BR /&gt;&amp;lt;value&amp;gt;cn&amp;lt;/value&amp;gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you for your help&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 20 Mar 2020 10:05:31 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Configure-LdapGroupsMapping-in-ClouderaManager/m-p/292149#M215923</guid>
      <dc:creator>WilsonLozano</dc:creator>
      <dc:date>2020-03-20T10:05:31Z</dc:date>
    </item>
    <item>
      <title>Re: Configure LdapGroupsMapping in ClouderaManager</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Configure-LdapGroupsMapping-in-ClouderaManager/m-p/292346#M216038</link>
      <description>&lt;P&gt;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/73386"&gt;@WilsonLozano&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I believe the error you are getting indicates that the bind user defined in hadoop.security.group.mapping.ldap.bind.user does not existing in the LDAP server, but I didn't search online for confirmation.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You could try using ldapsearch to test something like this:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier,monospace"&gt;ldapsearch -x -H ldap://sub.us.domain.local:389 -D "ClouderaManager@SUB.US.DOMAIN.LOCAL" -W -b "DC=sub,DC=us,DC=domain,DC=local" "(&amp;amp;(objectClass=user)(sAMAccountName=c12345a))"&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If the above returns an error, you can try using debugging in ldapsearch to get a clearer picture what failed by using the "-d1" option in the command above (after -W for instance).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 23 Mar 2020 20:36:23 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Configure-LdapGroupsMapping-in-ClouderaManager/m-p/292346#M216038</guid>
      <dc:creator>bgooley</dc:creator>
      <dc:date>2020-03-23T20:36:23Z</dc:date>
    </item>
    <item>
      <title>Re: Configure LdapGroupsMapping in ClouderaManager</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Configure-LdapGroupsMapping-in-ClouderaManager/m-p/292360#M216052</link>
      <description>&lt;P&gt;Thank you&amp;nbsp;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/4054"&gt;@bgooley&lt;/a&gt;&amp;nbsp;for answering, I have been with this problem for a month.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Perform the test with the ldapsearch command and the result was as follows:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT size="2"&gt;[c12345a@servernode ~]$ ldapsearch -x -H ldap://sub.us.domain.local:389 -D "ClouderaManager@SUB.US.DOMAIN.LOCAL" -W -b "DC=sub,DC=us,DC=domain,DC=local" "(&amp;amp;(objectClass=user)(sAMAccountName=c12345a))"&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;Enter LDAP Password:&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;# extended LDIF&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;#&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;# LDAPv3&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;# base &amp;lt;DC=sub,DC=us,DC=domain,DC=local&amp;gt; with scope subtree&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;# filter: (&amp;amp;(objectClass=user)(sAMAccountName=c12345a))&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;# requesting: ALL&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;#&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT size="2"&gt;# Charlie Brown, Computec, General Accounts, Accounts, sub.us.domain.local&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;dn: CN=Charlie Brown,OU=Computec,OU=General Accounts,OU=Accounts,DC=sub,DC=us,&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;DC=domain,DC=local&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;objectClass: top&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;objectClass: person&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;objectClass: organizationalPerson&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;objectClass: user&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;cn: Charlie Brown&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;sn: Brown&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;c: C&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;l: city D.C.&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;st: city&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;title: Admin&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;postalCode: 571&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;physicalDeliveryOfficeName: CO city principal office&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;givenName: Charlie&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;distinguishedName: CN=Charlie Brown,OU=Computec,OU=General Accounts,OU=Accounts,DC=sub,DC=us,DC=domain,DC=local&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;instanceType: 4&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;whenCreated: 20191128190334.0Z&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;whenChanged: 20200318065357.0Z&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;displayName: Brown, Charlie&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;uSNCreated: 36937614&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;memberOf: CN=Unix_KafkaServer04_kfk_group,OU=UnixSecondaryGroups,OU=DomainLATAM,OU=UnixGroups,OU=Groups,DC=sub,DC=us,DC=domain,DC=local&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;memberOf: CN=Unix_KafkaServer04_kfk_adm_Group,OU=UnixSecondaryGroups,OU=DomainLATAM,OU=UnixGroups,OU=Groups,DC=sub,DC=us,DC=domain,DC=local&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;memberOf: CN=Unix_KafkaServer03_kfk_group,OU=UnixSecondaryGroups,OU=DomainLATAM,OU=UnixGroups,OU=Groups,DC=sub,DC=us,DC=domain,DC=local&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;memberOf: CN=Unix_KafkaServer03_kfk_adm_Group,OU=UnixSecondaryGroups,OU=DomainLATAM,OU=UnixGroups,OU=Groups,DC=sub,DC=us,DC=domain,DC=local&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;memberOf: CN=Unix_KafkaServer02_kfk_group,OU=UnixSecondaryGroups,OU=DomainLATAM,OU=UnixGroups,OU=Groups,DC=sub,DC=us,DC=domain,DC=local&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;memberOf: CN=Unix_KafkaServer02_kfk_adm_Group,OU=UnixSecondaryGroups,OU=DomainLATAM,OU=UnixGroups,OU=Groups,DC=sub,DC=us,DC=domain,DC=local&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;memberOf: CN=Unix_KafkaServer01_kfk_group,OU=UnixSecondaryGroups,OU=DomainLATAM,OU=UnixGroups,OU=Groups,DC=sub,DC=us,DC=domain,DC=local&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;memberOf: CN=Unix_KafkaServer01_kfk_adm_Group,OU=UnixSecondaryGroups,OU=DomainLATAM,OU=UnixGroups,OU=Groups,DC=sub,DC=us,DC=domain,DC=local&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;memberOf: CN=Unix_KafkaServer04_Users,OU=UnixSecondaryGroups,OU=DomainLATAM,OU=UnixGroups,OU=Groups,DC=sub,DC=us,DC=domain,DC=local&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;memberOf: CN=Unix_KafkaServer03_Users,OU=UnixSecondaryGroups,OU=DomainLATAM,OU=UnixGroups,OU=Groups,DC=sub,DC=us,DC=domain,DC=local&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;memberOf: CN=Unix_KafkaServer02_Users,OU=UnixSecondaryGroups,OU=DomainLATAM,OU=UnixGroups,OU=Groups,DC=sub,DC=us,DC=domain,DC=local&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;memberOf: CN=Unix_KafkaServer01_users,OU=UnixSecondaryGroups,OU=DomainLATAM,OU=UnixGroups,OU=Groups,DC=sub,DC=us,DC=domain,DC=local&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;memberOf: CN=kfk_adm_Group,OU=General Groups,OU=Groups,DC=sub,DC=us,DC=domain,DC=local&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;memberOf: CN=kfk_group,OU=General Groups,OU=Groups,DC=sub,DC=us,DC=domain,DC=local&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;memberOf: CN=APP-MyPeopleExperience-Users,OU=General Groups,OU=Groups,DC=sub,DC=us,DC=domain,DC=local&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;memberOf: CN=APP-IDCentral_SkypeOnline_DesktopSharing,OU=Identity Central,OU=Application Groups,OU=Groups,DC=sub,DC=us,DC=domain,DC=local&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;memberOf: CN=ADMIN DomainLATAM Centrify KAFKA,OU=UserRoleGroups,OU=DomainLATAM,OU=UnixGroups,OU=Groups,DC=sub,DC=us,DC=domain,DC=local&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;memberOf: CN=APP-IDCentral_Remote_mailbox,OU=Identity Central,OU=Application Groups,OU=Groups,DC=sub,DC=us,DC=domain,DC=local&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;memberOf: CN=GlobalDLP,OU=Global DLP Groups,OU=Groups,DC=us,DC=domain,DC=local&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;memberOf: CN=APP-Sailpoint-IIQ-Users,OU=General Groups,OU=Groups,DC=sub,DC=us,DC=domain,DC=local&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;memberOf: CN=Allow External Email Access,OU=AzureSync,OU=Secured Groups,OU=Groups,DC=sub,DC=us,DC=domain,DC=local&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;memberOf: CN=O365.LicenseSkypefB,OU=Office365 Licensing,OU=Application Groups,OU=Groups,DC=sub,DC=us,DC=domain,DC=local&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;memberOf: CN=APP-Webex_Users,OU=AzureSync,OU=General Groups,OU=Groups,DC=sub,DC=us,DC=domain,DC=local&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;memberOf: CN=O365.LicenseSharepointOnline,OU=Office365 Licensing,OU=Application Groups,OU=Groups,DC=sub,DC=us,DC=domain,DC=local&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;memberOf: CN=O365.LicenseExchangeOnlineE3,OU=Office365 Licensing,OU=Application Groups,OU=Groups,DC=sub,DC=us,DC=domain,DC=local&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;memberOf: CN=O365.LicenseBasicServicesE3andEMS,OU=Office365 Licensing,OU=Application Groups,OU=Groups,DC=sub,DC=us,DC=domain,DC=local&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;memberOf: CN=O365.LicenseTeams,OU=Office365 Licensing,OU=Application Groups,OU=Groups,DC=sub,DC=us,DC=domain,DC=local&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;memberOf: CN=city - Internal Users Street ,OU=O365 DL Migration Project - Exclusions,OU=Distribution Groups,OU=Groups,DC=sub,DC=us,DC=domain,DC=local&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;memberOf: CN=GN_CO_Internet_Basic,OU=Computec,OU=Application Groups,OU=Groups,DC=sub,DC=us,DC=domain,DC=local&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;memberOf: CN=Archer.SUB_Users,OU=Archer Groups,OU=Application Groups,OU=Groups,DC=sub,DC=us,DC=domain,DC=local&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;memberOf: CN=UNIFY SUB Authorized Users,OU=General Groups,OU=Groups,DC=sub,DC=us,DC=domain,DC=local&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;uSNChanged: 74565754&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;co: CO&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;department: Sp Latam:Global&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;company: Domain S.A&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;proxyAddresses: x500:/o=ExchangeLabs/ou=Exchange Administrative Group (FBOH3SPDLT)/cn=Recipients/cn=9812d54ca41c79c8585597c61dc85-Charlie Brown&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;proxyAddresses: smtp:DMN-Charlie.Brown@domain.mail.onmicrosoft.com&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;proxyAddresses: SMTP:Charlie.Brown@domain.com&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;targetAddress: SMTP:DMN-Charlie.Brown@domain.mail.onmicrosoft.com&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;extensionAttribute1: 7282705&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;extensionAttribute2: 601&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;extensionAttribute6: CO city Oficina principal&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;extensionAttribute7: Contingent&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;extensionAttribute8: Contingent Worker&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;extensionAttribute9: Worker&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;mailNickname: C12345A&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;extensionAttribute12: NAC_&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;extensionAttribute13: C12345A@sub.us.domain.local&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;extensionAttribute15: NAC&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;name: Charlie Brown&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;objectGUID:: D8xfdlcMGkmuEghNTYiA==&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;userAccountControl: 512&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;badPwdCount: 0&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;codePage: 0&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;countryCode: 0&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;badPasswordTime: 132283366751489998&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;lastLogoff: 0&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;lastLogon: 132294797156347726&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;pwdLastSet: 132282329603092576&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;primaryGroupID: 513&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;userParameters:: bXR4Q2ZnUHJlc2VudCAgICAgICA&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;objectSid:: AQUAAAAAAAUVAAhkqT5EAb4UEAA==&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;accountExpires: 132507324000000000&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;logonCount: 1814&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;sAMAccountName: C12345A&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;sAMAccountType: 8030638&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;showInAddressBook: CN=Default Global Address List,CN=All Global Address Lists,CN=Address Lists Container,CN=Domain,CN=Microsoft Exchange,CN=Services,CN=Configuration,DC=domain,DC=local&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;managedObjects: CN=Unix_KafkaServer04_kfk_group,OU=UnixSecondaryGroups,OU=DomainLATAM,OU=UnixGroups,OU=Groups,DC=sub,DC=us,DC=domain,DC=local&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;managedObjects: CN=Unix_KafkaServer04_kfk_adm_Group,OU=UnixSecondaryGroups,OU=DomainLATAM,OU=UnixGroups,OU=Groups,DC=sub,DC=us,DC=domain,DC=local&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;managedObjects: CN=Unix_KafkaServer03_kfk_group,OU=UnixSecondaryGroups,OU=DomainLATAM,OU=UnixGroups,OU=Groups,DC=sub,DC=us,DC=domain,DC=local&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;managedObjects: CN=Unix_KafkaServer03_kfk_adm_Group,OU=UnixSecondaryGroups,OU=DomainLATAM,OU=UnixGroups,OU=Groups,DC=sub,DC=us,DC=domain,DC=local&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;managedObjects: CN=Unix_KafkaServer02_kfk_group,OU=UnixSecondaryGroups,OU=DomainLATAM,OU=UnixGroups,OU=Groups,DC=sub,DC=us,DC=domain,DC=local&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;managedObjects: CN=Unix_KafkaServer02_kfk_adm_Group,OU=UnixSecondaryGroups,OU=DomainLATAM,OU=UnixGroups,OU=Groups,DC=sub,DC=us,DC=domain,DC=local&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;managedObjects: CN=Unix_KafkaServer01_kfk_group,OU=UnixSecondaryGroups,OU=DomainLATAM,OU=UnixGroups,OU=Groups,DC=sub,DC=us,DC=domain,DC=local&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;managedObjects: CN=Unix_KafkaServer01_kfk_adm_Group,OU=UnixSecondaryGroups,OU=DomainLATAM,OU=UnixGroups,OU=Groups,DC=sub,DC=us,DC=domain,DC=local&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;managedObjects: CN=Unix_KafkaServer04_Users,OU=UnixSecondaryGroups,OU=DomainLATAM,OU=UnixGroups,OU=Groups,DC=sub,DC=us,DC=domain,DC=local&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;managedObjects: CN=Unix_KafkaServer03_Users,OU=UnixSecondaryGroups,OU=DomainLATAM,OU=UnixGroups,OU=Groups,DC=sub,DC=us,DC=domain,DC=local&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;managedObjects: CN=Unix_KafkaServer02_Users,OU=UnixSecondaryGroups,OU=DomainLATAM,OU=UnixGroups,OU=Groups,DC=sub,DC=us,DC=domain,DC=local&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;managedObjects: CN=Unix_KafkaServer01_users,OU=UnixSecondaryGroups,OU=DomainLATAM,OU=UnixGroups,OU=Groups,DC=sub,DC=us,DC=domain,DC=local&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;legacyExchangeDN: /o=Domain/ou=Exchange Administrative Group (FYDI23SPDL&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;T)/cn=Recipients/cn=Charlie Brown&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;userPrincipalName: Charlie.Brown@domain.com&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;lockoutTime: 0&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;objectCategory: CN=Person,CN=Schema,CN=Configuration,DC=domain,DC=local&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;msRADIUSFramedIPAddress: 17419&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;msRASSavedFramedIPAddress: 17419&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;dSCorePropagationData: 16010101000000.0Z&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;mS-DS-ConsistencyGuid:: D8xfdlcMGkmuEghNTYiyvA==&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;lastLogonTimestamp: 132289880375204341&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;msDS-ExternalDirectoryObjectId: User_3821ddab-be44-4cd5-956d-bdcb648ddbb7&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;mail: Charlie.Brown@domain.com&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;manager: CN=\,chief,OU=Infrastructure,OU=Technology,OU=Country,OU=Co&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;mputec,OU=General Accounts,OU=Accounts,DC=sub,DC=us,DC=domain,DC=local&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;middleName: Middle&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;msExchPoliciesExcluded: {261cfc-9e50-4857-861b-0cb8d7}&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;msExchArchiveStatus: 1&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;msExchRemoteRecipientType: 3&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;msExchVersion: 442&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;msExchUsageLocation: CO&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;msExchUMDtmfMap: emailAddress:945766&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;msExchUMDtmfMap: lastNameFirstName:56926694&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;msExchUMDtmfMap: firstNameLastName:945766566&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;msExchArchiveGUID:: ajkdQhlawkK6SQ3heE/lA==&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;msExchRecipientDisplayType: -21474842&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;msExchArchiveName: Personal Archive - Charlie Brown&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;msExchRecipientTypeDetails: 21474848&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT size="2"&gt;# search reference&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;ref: ldap://DomainDnsZones.sub.us.domain.local/DC=DomainDnsZones,DC=sub,DC=u&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;s,DC=domain,DC=local&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT size="2"&gt;# search result&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;search: 2&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;result: 0 Success&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT size="2"&gt;# numResponses: 3&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;# numEntries: 1&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;# numReferences: 1&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The clouderamanager user has the possibility to consult the AD, what other problem could it be?&lt;/P&gt;&lt;P&gt;Thanks for the help&lt;/P&gt;</description>
      <pubDate>Tue, 24 Mar 2020 02:00:39 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Configure-LdapGroupsMapping-in-ClouderaManager/m-p/292360#M216052</guid>
      <dc:creator>WilsonLozano</dc:creator>
      <dc:date>2020-03-24T02:00:39Z</dc:date>
    </item>
    <item>
      <title>Re: Configure LdapGroupsMapping in ClouderaManager</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Configure-LdapGroupsMapping-in-ClouderaManager/m-p/292466#M216121</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/73386"&gt;@WilsonLozano&lt;/a&gt; ,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Based on the fact that the ldapsearch command returned the object without issue, we can conclude that the bind user and password are correct.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thus, I believe we can assume that the issue may involve referrals and how they are being followed.&amp;nbsp; I find this odd since I believe that ldapgroupsmapping should have referral following off by default.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Nonetheless, we see in your ldapsearch result:&lt;BR /&gt;&lt;BR /&gt;ref: ldap://DomainDnsZones.sub.us.domain.local/DC=DomainDnsZones,DC=sub,DC=u&lt;BR /&gt;s,DC=domain,DC=local&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So, what I would suggest trying is either:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Change your search base to something more specific like "OU=Accounts,DC=sub,DC=us,&lt;BR /&gt;DC=domain,DC=local" so that no referral is returned from Active Directory&lt;/LI&gt;&lt;LI&gt;Try using the Global Catalog (port 3268 (non-TLS))&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;I am pretty confident that referrals are involved, but I don't know why hadoop commons would be following them.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Another thing you could do is use "tcpdump" to capture packets on port 389 and then use WireShark to decode them.&amp;nbsp; That would show us exactly what the client is trying to do and the response (in terms of LDAP protocol).&lt;/P&gt;</description>
      <pubDate>Tue, 24 Mar 2020 20:03:25 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Configure-LdapGroupsMapping-in-ClouderaManager/m-p/292466#M216121</guid>
      <dc:creator>bgooley</dc:creator>
      <dc:date>2020-03-24T20:03:25Z</dc:date>
    </item>
    <item>
      <title>Re: Configure LdapGroupsMapping in ClouderaManager</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Configure-LdapGroupsMapping-in-ClouderaManager/m-p/293029#M216437</link>
      <description>&lt;P&gt;Ok we finally got it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The downside is that when setting the hadoop.security.group.mapping.ldap.bind.password.file property, it did not update the core-site.xml file.&lt;/P&gt;&lt;P&gt;Perform the following procedure:&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://community.cloudera.com/t5/Community-Articles/Secure-LDAP-bind-password-in-Hadoop-Configuration/ta-p/247789" target="_blank"&gt;https://community.cloudera.com/t5/Community-Articles/Secure-LDAP-bind-password-in-Hadoop-Configuration/ta-p/247789&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;And add the property in Cluster-wide Advanced Configuration Snippet (Safety Valve) for core-site.xml of hdfs in cloudera manager&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you very much &lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/4054"&gt;@bgooley&lt;/a&gt;&amp;nbsp;for your help&lt;/P&gt;</description>
      <pubDate>Tue, 31 Mar 2020 21:38:38 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Configure-LdapGroupsMapping-in-ClouderaManager/m-p/293029#M216437</guid>
      <dc:creator>WilsonLozano</dc:creator>
      <dc:date>2020-03-31T21:38:38Z</dc:date>
    </item>
  </channel>
</rss>

