<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>question Ranger User sync not able to sync users while group is getting synced. in Support Questions</title>
    <link>https://community.cloudera.com/t5/Support-Questions/Ranger-User-sync-not-able-to-sync-users-while-group-is/m-p/315679#M226533</link>
    <description>&lt;P&gt;Hi,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am facing an issue while running ranger user sync. It's able to sync groups but not users. I am not getting any errors also.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 30 Apr 2021 18:52:22 GMT</pubDate>
    <dc:creator>dmahato</dc:creator>
    <dc:date>2021-04-30T18:52:22Z</dc:date>
    <item>
      <title>Ranger User sync not able to sync users while group is getting synced.</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Ranger-User-sync-not-able-to-sync-users-while-group-is/m-p/315679#M226533</link>
      <description>&lt;P&gt;Hi,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am facing an issue while running ranger user sync. It's able to sync groups but not users. I am not getting any errors also.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 30 Apr 2021 18:52:22 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Ranger-User-sync-not-able-to-sync-users-while-group-is/m-p/315679#M226533</guid>
      <dc:creator>dmahato</dc:creator>
      <dc:date>2021-04-30T18:52:22Z</dc:date>
    </item>
    <item>
      <title>Re: Ranger User sync not able to sync users while group is getting synced.</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Ranger-User-sync-not-able-to-sync-users-while-group-is/m-p/315682#M226536</link>
      <description>&lt;P&gt;Not sure if this &lt;A href="https://community.cloudera.com/t5/Support-Questions/Issue-with-Ranger-User-group-sync/m-p/219124#M181025" target="_blank" rel="noopener"&gt;older solution&lt;/A&gt; will help but it's worth a look.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 30 Apr 2021 19:29:47 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Ranger-User-sync-not-able-to-sync-users-while-group-is/m-p/315682#M226536</guid>
      <dc:creator>cjervis</dc:creator>
      <dc:date>2021-04-30T19:29:47Z</dc:date>
    </item>
    <item>
      <title>Re: Ranger User sync not able to sync users while group is getting synced.</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Ranger-User-sync-not-able-to-sync-users-while-group-is/m-p/317015#M226986</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Did you enable user search and Please share usersync configs.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Vamsi&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 24 May 2021 10:32:21 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Ranger-User-sync-not-able-to-sync-users-while-group-is/m-p/317015#M226986</guid>
      <dc:creator>vamsi_redd</dc:creator>
      <dc:date>2021-05-24T10:32:21Z</dc:date>
    </item>
    <item>
      <title>Re: Ranger User sync not able to sync users while group is getting synced.</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Ranger-User-sync-not-able-to-sync-users-while-group-is/m-p/317101#M227008</link>
      <description>&lt;P&gt;Hi, Are you able to see the users in the usersync logs ? can you please share the usersync logs from ranger and also some users which are not synced to check logs.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 25 May 2021 08:45:23 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Ranger-User-sync-not-able-to-sync-users-while-group-is/m-p/317101#M227008</guid>
      <dc:creator>arunek95</dc:creator>
      <dc:date>2021-05-25T08:45:23Z</dc:date>
    </item>
    <item>
      <title>Re: Ranger User sync not able to sync users while group is getting synced.</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Ranger-User-sync-not-able-to-sync-users-while-group-is/m-p/317151#M227034</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Below are configuration for connecting Apache Ranger with LDAP/LDAPS. There's an important tool that will help to identify some settings in your AD&amp;nbsp;&lt;A href="https://docs.microsoft.com/en-us/sysinternals/downloads/adexplorer" target="_blank" rel="noopener nofollow noopener noreferrer"&gt;AD Explorer - Windows Sysinternals | Microsoft Docs&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;This configuration will sync LDAP users and link them with their LDAP groups every 12 hour, so you later from Apache Ranger you can give permission based on LDAP groups as well.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For connecting using LDAPS, make sure you have the proper certificates added in the same server that contains the Ranger's UserSync service.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;TABLE border="1" width="104.42477876106194%"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="50%" height="29px"&gt;&lt;STRONG&gt;Configuration Name&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD width="25%" height="29px"&gt;&lt;STRONG&gt;Configuration Value&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD width="25%"&gt;&lt;STRONG&gt;Comment&lt;/STRONG&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="50%" height="29px"&gt;ranger.usersync.source.impl.class&lt;/TD&gt;&lt;TD width="25%" height="29px"&gt;org.apache.ranger.ldapusersync.process.LdapUserGroupBuilder&lt;/TD&gt;&lt;TD width="25%"&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="50%" height="29px"&gt;ranger.usersync.sleeptimeinmillisbetweensynccycle&lt;/TD&gt;&lt;TD width="25%" height="29px"&gt;12 hour&lt;/TD&gt;&lt;TD width="25%"&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="50%" height="29px"&gt;ranger.usersync.ldap.url&lt;/TD&gt;&lt;TD width="25%" height="29px"&gt;ldaps://myldapserver.example.com&lt;/TD&gt;&lt;TD width="25%"&gt;ldaps or ldap based on your LDAP security&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="50%" height="29px"&gt;ranger.usersync.ldap.binddn&lt;/TD&gt;&lt;TD width="25%" height="29px"&gt;myuser@example.com&lt;/TD&gt;&lt;TD width="25%"&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="50%" height="29px"&gt;ranger.usersync.ldap.ldapbindpassword&lt;/TD&gt;&lt;TD width="25%" height="29px"&gt;mypassword&lt;/TD&gt;&lt;TD width="25%"&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="50%" height="29px"&gt;ranger.usersync.ldap.searchBase&lt;/TD&gt;&lt;TD width="25%" height="29px"&gt;OU=hadoop,DC=example,DC=com&lt;/TD&gt;&lt;TD width="25%"&gt;you can browse your AD and check which OU you want to make Ranger sync&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="50%" height="29px"&gt;ranger.usersync.ldap.user.searchbase&lt;/TD&gt;&lt;TD width="25%" height="29px"&gt;OU=hadoop2,DC=example,DC=com;OU=hadoop,DC=example,DC=com&lt;/TD&gt;&lt;TD width="25%"&gt;you can browse your AD and check which OU you want to make Ranger sync, you can also add 2 OU and separate them with ;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="50%" height="29px"&gt;ranger.usersync.ldap.user.objectclass&lt;/TD&gt;&lt;TD width="25%" height="29px"&gt;user&lt;/TD&gt;&lt;TD width="25%"&gt;double check the same&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="50%" height="29px"&gt;ranger.usersync.ldap.user.searchfilter&lt;/TD&gt;&lt;TD width="25%" height="29px"&gt;(memberOf=CN=HADOOP_ACCESS,DC=example,DC=com)&lt;/TD&gt;&lt;TD width="25%"&gt;if you want to filter specific users to be synced in ranger and not your entire AD&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="50%"&gt;ranger.usersync.ldap.user.nameattribute&lt;/TD&gt;&lt;TD width="25%"&gt;sAMAccountName&lt;/TD&gt;&lt;TD width="25%"&gt;double check the same&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="50%"&gt;ranger.usersync.ldap.user.groupnameattribute&lt;/TD&gt;&lt;TD width="25%"&gt;memberOf&lt;/TD&gt;&lt;TD width="25%"&gt;double check the same&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="50%"&gt;ranger.usersync.user.searchenabled&lt;/TD&gt;&lt;TD width="25%"&gt;true&lt;/TD&gt;&lt;TD width="25%"&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="50%"&gt;ranger.usersync.group.searchbase&lt;/TD&gt;&lt;TD width="25%"&gt;OU=hadoop,DC=example,DC=com&lt;/TD&gt;&lt;TD width="25%"&gt;you can browse your AD and check which OU you want to make Ranger sync&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="50%"&gt;ranger.usersync.group.objectclass&lt;/TD&gt;&lt;TD width="25%"&gt;group&lt;/TD&gt;&lt;TD width="25%"&gt;double check the same&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="50%"&gt;ranger.usersync.group.searchfilter&lt;/TD&gt;&lt;TD width="25%"&gt;(cn=hadoop_*)&lt;/TD&gt;&lt;TD width="25%"&gt;if you want to sync specific groups not all AD groups&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="50%"&gt;ranger.usersync.group.nameattribute&lt;/TD&gt;&lt;TD width="25%"&gt;cn&lt;/TD&gt;&lt;TD width="25%"&gt;double check the same&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="50%"&gt;ranger.usersync.group.memberattributename&lt;/TD&gt;&lt;TD width="25%"&gt;member&lt;/TD&gt;&lt;TD width="25%"&gt;double check the same&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="50%"&gt;ranger.usersync.group.search.first.enabled&lt;/TD&gt;&lt;TD width="25%"&gt;true&lt;/TD&gt;&lt;TD width="25%"&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="50%"&gt;&lt;SPAN&gt;ranger.usersync.truststore.file&lt;/SPAN&gt;&lt;/TD&gt;&lt;TD width="25%"&gt;/path/to/truststore-file&lt;/TD&gt;&lt;TD width="25%"&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="50%"&gt;&lt;DIV class="header-column"&gt;&lt;DIV class="property-name small"&gt;ranger.usersync.truststore.password&lt;/DIV&gt;&lt;/DIV&gt;&lt;/TD&gt;&lt;TD width="25%"&gt;TRUST_STORE_PASSWORD&lt;/TD&gt;&lt;TD width="25%"&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;There's some helpful links about how to construct complex LDAP search queries&amp;nbsp;&lt;A href="https://docs.microsoft.com/en-us/windows/win32/adsi/search-filter-syntax" target="_blank" rel="noopener nofollow noopener noreferrer"&gt;Search Filter Syntax - Win32 apps | Microsoft Docs&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best Regards,&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 26 May 2021 11:57:51 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Ranger-User-sync-not-able-to-sync-users-while-group-is/m-p/317151#M227034</guid>
      <dc:creator>tarekabouzeid91</dc:creator>
      <dc:date>2021-05-26T11:57:51Z</dc:date>
    </item>
  </channel>
</rss>

