<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>question Re: Apache Knox LDAP configuration is not used in Support Questions</title>
    <link>https://community.cloudera.com/t5/Support-Questions/Apache-Knox-LDAP-configuration-is-not-used/m-p/331427#M230891</link>
    <description>&lt;P&gt;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/22763"&gt;@daba&lt;/a&gt;&amp;nbsp;Can you try adding the below lines to the Knox topology files&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;authentication.param.remove=main.pamRealm
authentication.param.remove=main.pamRealm.service&lt;/LI-CODE&gt;&lt;P&gt;Refer to the following doc for more info on how to configure LDAP/AD in knox&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.cloudera.com/runtime/7.2.10/knox-authentication/topics/security-knox-authe-ldap.html" target="_blank"&gt;https://docs.cloudera.com/runtime/7.2.10/knox-authentication/topics/security-knox-authe-ldap.html&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 02 Dec 2021 00:49:50 GMT</pubDate>
    <dc:creator>Scharan</dc:creator>
    <dc:date>2021-12-02T00:49:50Z</dc:date>
    <item>
      <title>Apache Knox LDAP configuration is not used</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Apache-Knox-LDAP-configuration-is-not-used/m-p/331417#M230889</link>
      <description>&lt;P&gt;Hello all,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have installed Apache Knox on a CDP 7.1.6 cluster and switched Shiro from PAM to LDAP (as described here &lt;A href="https://is.gd/FmexUD" target="_blank"&gt;https://is.gd/FmexUD&lt;/A&gt;). The changes are also done in the providers. PAM is disabled via the authentication.param.remove switch. Nevertheless PAM (KnoxPamRealm) is used for authentication instead of LDAP (KnoxLdapRealm). Does anyone have useful hints where to look for the cause? Thanks a lot!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Daniel&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 21 Apr 2026 08:03:16 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Apache-Knox-LDAP-configuration-is-not-used/m-p/331417#M230889</guid>
      <dc:creator>daba</dc:creator>
      <dc:date>2026-04-21T08:03:16Z</dc:date>
    </item>
    <item>
      <title>Re: Apache Knox LDAP configuration is not used</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Apache-Knox-LDAP-configuration-is-not-used/m-p/331427#M230891</link>
      <description>&lt;P&gt;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/22763"&gt;@daba&lt;/a&gt;&amp;nbsp;Can you try adding the below lines to the Knox topology files&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;authentication.param.remove=main.pamRealm
authentication.param.remove=main.pamRealm.service&lt;/LI-CODE&gt;&lt;P&gt;Refer to the following doc for more info on how to configure LDAP/AD in knox&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.cloudera.com/runtime/7.2.10/knox-authentication/topics/security-knox-authe-ldap.html" target="_blank"&gt;https://docs.cloudera.com/runtime/7.2.10/knox-authentication/topics/security-knox-authe-ldap.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 02 Dec 2021 00:49:50 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Apache-Knox-LDAP-configuration-is-not-used/m-p/331427#M230891</guid>
      <dc:creator>Scharan</dc:creator>
      <dc:date>2021-12-02T00:49:50Z</dc:date>
    </item>
    <item>
      <title>Re: Apache Knox LDAP configuration is not used</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Apache-Knox-LDAP-configuration-is-not-used/m-p/331453#M230895</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/35149"&gt;@Scharan&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;many thanks for your answer! Both parameters you mentioned are set. In the Knox Admin UI, all relevant providers also have the LDAP configuration (KnoxLdapRealm). But KnoxPamRealm is still used. It is interesting that when Knox is started, the shiro.ini with the PAM configuration is pulled from the JAR (WEB-INF/shiro.ini). Otherwise, there is no other shiro.ini in the file system that could replace it.&lt;/P&gt;</description>
      <pubDate>Thu, 02 Dec 2021 08:12:41 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Apache-Knox-LDAP-configuration-is-not-used/m-p/331453#M230895</guid>
      <dc:creator>daba</dc:creator>
      <dc:date>2021-12-02T08:12:41Z</dc:date>
    </item>
    <item>
      <title>Re: Apache Knox LDAP configuration is not used</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Apache-Knox-LDAP-configuration-is-not-used/m-p/332936#M231304</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/22763"&gt;@daba&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Could you check the following topology file in the Knox gateway node to validate if the authentication provider change you made in the CM UI is reflected at the host level as well?&lt;/P&gt;&lt;P&gt;-&amp;nbsp;/var/lib/knox/gateway/conf/topologies/knoxsso.xml&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;BR /&gt;Prashanth Vishnu&lt;/P&gt;</description>
      <pubDate>Tue, 28 Dec 2021 10:43:34 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Apache-Knox-LDAP-configuration-is-not-used/m-p/332936#M231304</guid>
      <dc:creator>pvishnu</dc:creator>
      <dc:date>2021-12-28T10:43:34Z</dc:date>
    </item>
    <item>
      <title>Re: Apache Knox LDAP configuration is not used</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Apache-Knox-LDAP-configuration-is-not-used/m-p/336199#M232186</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/63344"&gt;@pvishnu&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thank you for your response! The ldap configuration which I made in the Cloudera Manager will not be persist in the topology file &lt;SPAN&gt;/var/lib/knox/gateway/conf/topologies/knoxsso.xml. There is still the pamRealm configuration. One solution is to manually edit the topology file, but that is not&amp;nbsp;my expectation if you use Cloudera Manager.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Regards,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Daniel&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 14 Feb 2022 07:27:05 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Apache-Knox-LDAP-configuration-is-not-used/m-p/336199#M232186</guid>
      <dc:creator>daba</dc:creator>
      <dc:date>2022-02-14T07:27:05Z</dc:date>
    </item>
  </channel>
</rss>

