<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>question Re: Spark-submit - mapping of principal in Support Questions</title>
    <link>https://community.cloudera.com/t5/Support-Questions/Spark-submit-mapping-of-principal/m-p/354185#M236860</link>
    <description>&lt;P&gt;Great, thanks&lt;/P&gt;</description>
    <pubDate>Thu, 06 Oct 2022 14:15:46 GMT</pubDate>
    <dc:creator>Jarinek</dc:creator>
    <dc:date>2022-10-06T14:15:46Z</dc:date>
    <item>
      <title>Spark-submit - mapping of principal</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Spark-submit-mapping-of-principal/m-p/354035#M236833</link>
      <description>&lt;P&gt;Hello,&lt;BR /&gt;on our system CDP 7.1.7, we have use konfiguration parameter&lt;BR /&gt;kafka.properties_role_safety_valve&lt;BR /&gt;add set attribute&lt;BR /&gt;sasl.kerberos.principal.to.local.rules&lt;BR /&gt;to map ActiveDirectory principals to entities created in ranger.&lt;/P&gt;&lt;P&gt;In our system, the AD user have a prefix e.g. xjohndoe@SAMPLE.COM maps to a ranger entity "johndoe"&lt;/P&gt;&lt;P&gt;During a spark-submit (over yarn), we also need to pass a principal, however as there is no such mapping, we obtain an error saying the unix user "xjohndoe" does not exist. This is true indeed, we eed to map it to "johndoe".&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Ist there any possibility to map principals during spark-spark-submit possibly similarly to sasl.kerberos.principal.to.local.rules in kafka or any other possibility?&lt;/P&gt;&lt;P&gt;Best regards&lt;BR /&gt;Jaro&lt;/P&gt;</description>
      <pubDate>Tue, 04 Oct 2022 19:47:15 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Spark-submit-mapping-of-principal/m-p/354035#M236833</guid>
      <dc:creator>Jarinek</dc:creator>
      <dc:date>2022-10-04T19:47:15Z</dc:date>
    </item>
    <item>
      <title>Re: Spark-submit - mapping of principal</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Spark-submit-mapping-of-principal/m-p/354076#M236841</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/80158"&gt;@Jarinek&lt;/a&gt;&amp;nbsp;, Yes, in CDH/CDP every service which depends on HDFS will inherit the HDFS configuration "&lt;SPAN&gt;auth-to-local rules", in CM in HDFS Configuration see "Additional Rules to Map Kerberos Principals to Short Names".&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Kafka does not need HDFS so that's why it has a separate such configuration.&lt;/P&gt;&lt;P&gt;See the documentation how to set it:&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.cloudera.com/cdp-private-cloud-base/7.1.7/security-kerberos-authentication/topics/cm-security-kerberos-authentication-auth-to-local-isolate.html" target="_blank"&gt;https://docs.cloudera.com/cdp-private-cloud-base/7.1.7/security-kerberos-authentication/topics/cm-security-kerberos-authentication-auth-to-local-isolate.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Best regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;Miklos&lt;/P&gt;</description>
      <pubDate>Wed, 05 Oct 2022 08:44:19 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Spark-submit-mapping-of-principal/m-p/354076#M236841</guid>
      <dc:creator>mszurap</dc:creator>
      <dc:date>2022-10-05T08:44:19Z</dc:date>
    </item>
    <item>
      <title>Re: Spark-submit - mapping of principal</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Spark-submit-mapping-of-principal/m-p/354185#M236860</link>
      <description>&lt;P&gt;Great, thanks&lt;/P&gt;</description>
      <pubDate>Thu, 06 Oct 2022 14:15:46 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Spark-submit-mapping-of-principal/m-p/354185#M236860</guid>
      <dc:creator>Jarinek</dc:creator>
      <dc:date>2022-10-06T14:15:46Z</dc:date>
    </item>
  </channel>
</rss>

