<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>question Isilon User Mapping Rules with CDP / Kerberos in Support Questions</title>
    <link>https://community.cloudera.com/t5/Support-Questions/Isilon-User-Mapping-Rules-with-CDP-Kerberos/m-p/365963#M239454</link>
    <description>&lt;P&gt;We're trying to install CDP 7.1.7 on Isilon with OneFS 8.2.2&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We found several documents that we tried to follow:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;- &lt;A href="https://infohub.delltechnologies.com/section-assets/h18730-dell-emc-powerscale-onefs-cdp-private-base-install-guide" target="_blank" rel="noopener"&gt;https://infohub.delltechnologies.com/section-assets/h18730-dell-emc-powerscale-onefs-cdp-private-base-install-guide&lt;/A&gt;&lt;/P&gt;&lt;P&gt;- &lt;A href="https://dl.dell.com/content/docu92689_PowerScale_OneFS_HDFS_Reference_Guide.pdf?language=en_US&amp;amp;source=Coveo" target="_blank" rel="noopener"&gt;https://dl.dell.com/content/docu92689_PowerScale_OneFS_HDFS_Reference_Guide.pdf?language=en_US&amp;amp;source=Coveo&lt;/A&gt;&lt;/P&gt;&lt;P&gt;- &lt;A href="https://infohub.delltechnologies.com/l/powerscale-onefs-user-mapping-mapping-identities-across-authentication-providers/mapping-rules-cannot-contain-user-principal-name" target="_blank" rel="noopener"&gt;https://infohub.delltechnologies.com/l/powerscale-onefs-user-mapping-mapping-identities-across-authentication-providers/mapping-rules-cannot-contain-user-principal-name&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;And more....&lt;/P&gt;&lt;P&gt;We also used the isilon hadoop tools and found a few bugs which we provided Pull Requests for (&lt;A href="https://github.com/Isilon/isilon_hadoop_tools/pull/105" target="_blank" rel="noopener"&gt;https://github.com/Isilon/isilon_hadoop_tools/pull/105&lt;/A&gt; &amp;amp; &lt;A href="https://github.com/Isilon/isilon_hadoop_tools/pull/106" target="_blank" rel="noopener"&gt;https://github.com/Isilon/isilon_hadoop_tools/pull/106&lt;/A&gt; ) so it seems as if thas hasn't been used in a while.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We were able to finish the basic setup but we do have issues creating the proper User Mapping Rules.&lt;/P&gt;&lt;P class="BodyText"&gt;The docs say:&lt;/P&gt;&lt;P class="BodyText"&gt;"&lt;SPAN&gt;You cannot use a user principal name in a user mapping rule. A user principal name (UPN) is an Active Directory domain and username that are combined into an Internet-style name with an @ sign, like an email address: jane@example.com.&lt;/SPAN&gt;&lt;/P&gt;&lt;DIV class="slide-content transition-500"&gt;&lt;DIV class="content-slide-wrap fr-view aphukh-style"&gt;&lt;P class="BodyText"&gt;&lt;SPAN&gt;If you include a UPN in a rule, the mapping service ignores it and might return an error.&lt;/SPAN&gt;"&lt;/P&gt;&lt;P class="BodyText"&gt;&amp;nbsp;&lt;/P&gt;Unfortunately, something doesn't quite work.&lt;BR /&gt;&lt;P class="BodyText"&gt;Cloudera Manager automatically created all users in Active Directory for us which means that an impala user could end up having the name "cloudera_xnTfsrendtr" in Active Directory. It does have the correct UPN set ("impala@...") but the UPN can't be used in a mapping.&lt;/P&gt;&lt;P class="BodyText"&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="BodyText"&gt;This means for us that we have to create User Mapping Rules for all users manually which "join" the identities and maps one of those auto-generated users to real ones "cloudera_xnTfsrendtr" -&amp;gt; impala.&lt;/P&gt;&lt;P class="BodyText"&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="BodyText"&gt;That is very cumbersome and the CDP / Isilon install docs don't mention this at all.&lt;/P&gt;&lt;P class="BodyText"&gt;Are there updated docs anywhere/does anyone have notes on this/done this recently?&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
    <pubDate>Tue, 21 Apr 2026 07:42:44 GMT</pubDate>
    <dc:creator>larsfrancke</dc:creator>
    <dc:date>2026-04-21T07:42:44Z</dc:date>
    <item>
      <title>Isilon User Mapping Rules with CDP / Kerberos</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Isilon-User-Mapping-Rules-with-CDP-Kerberos/m-p/365963#M239454</link>
      <description>&lt;P&gt;We're trying to install CDP 7.1.7 on Isilon with OneFS 8.2.2&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We found several documents that we tried to follow:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;- &lt;A href="https://infohub.delltechnologies.com/section-assets/h18730-dell-emc-powerscale-onefs-cdp-private-base-install-guide" target="_blank" rel="noopener"&gt;https://infohub.delltechnologies.com/section-assets/h18730-dell-emc-powerscale-onefs-cdp-private-base-install-guide&lt;/A&gt;&lt;/P&gt;&lt;P&gt;- &lt;A href="https://dl.dell.com/content/docu92689_PowerScale_OneFS_HDFS_Reference_Guide.pdf?language=en_US&amp;amp;source=Coveo" target="_blank" rel="noopener"&gt;https://dl.dell.com/content/docu92689_PowerScale_OneFS_HDFS_Reference_Guide.pdf?language=en_US&amp;amp;source=Coveo&lt;/A&gt;&lt;/P&gt;&lt;P&gt;- &lt;A href="https://infohub.delltechnologies.com/l/powerscale-onefs-user-mapping-mapping-identities-across-authentication-providers/mapping-rules-cannot-contain-user-principal-name" target="_blank" rel="noopener"&gt;https://infohub.delltechnologies.com/l/powerscale-onefs-user-mapping-mapping-identities-across-authentication-providers/mapping-rules-cannot-contain-user-principal-name&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;And more....&lt;/P&gt;&lt;P&gt;We also used the isilon hadoop tools and found a few bugs which we provided Pull Requests for (&lt;A href="https://github.com/Isilon/isilon_hadoop_tools/pull/105" target="_blank" rel="noopener"&gt;https://github.com/Isilon/isilon_hadoop_tools/pull/105&lt;/A&gt; &amp;amp; &lt;A href="https://github.com/Isilon/isilon_hadoop_tools/pull/106" target="_blank" rel="noopener"&gt;https://github.com/Isilon/isilon_hadoop_tools/pull/106&lt;/A&gt; ) so it seems as if thas hasn't been used in a while.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We were able to finish the basic setup but we do have issues creating the proper User Mapping Rules.&lt;/P&gt;&lt;P class="BodyText"&gt;The docs say:&lt;/P&gt;&lt;P class="BodyText"&gt;"&lt;SPAN&gt;You cannot use a user principal name in a user mapping rule. A user principal name (UPN) is an Active Directory domain and username that are combined into an Internet-style name with an @ sign, like an email address: jane@example.com.&lt;/SPAN&gt;&lt;/P&gt;&lt;DIV class="slide-content transition-500"&gt;&lt;DIV class="content-slide-wrap fr-view aphukh-style"&gt;&lt;P class="BodyText"&gt;&lt;SPAN&gt;If you include a UPN in a rule, the mapping service ignores it and might return an error.&lt;/SPAN&gt;"&lt;/P&gt;&lt;P class="BodyText"&gt;&amp;nbsp;&lt;/P&gt;Unfortunately, something doesn't quite work.&lt;BR /&gt;&lt;P class="BodyText"&gt;Cloudera Manager automatically created all users in Active Directory for us which means that an impala user could end up having the name "cloudera_xnTfsrendtr" in Active Directory. It does have the correct UPN set ("impala@...") but the UPN can't be used in a mapping.&lt;/P&gt;&lt;P class="BodyText"&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="BodyText"&gt;This means for us that we have to create User Mapping Rules for all users manually which "join" the identities and maps one of those auto-generated users to real ones "cloudera_xnTfsrendtr" -&amp;gt; impala.&lt;/P&gt;&lt;P class="BodyText"&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="BodyText"&gt;That is very cumbersome and the CDP / Isilon install docs don't mention this at all.&lt;/P&gt;&lt;P class="BodyText"&gt;Are there updated docs anywhere/does anyone have notes on this/done this recently?&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Tue, 21 Apr 2026 07:42:44 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Isilon-User-Mapping-Rules-with-CDP-Kerberos/m-p/365963#M239454</guid>
      <dc:creator>larsfrancke</dc:creator>
      <dc:date>2026-04-21T07:42:44Z</dc:date>
    </item>
    <item>
      <title>Re: Isilon User Mapping Rules with CDP / Kerberos</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Isilon-User-Mapping-Rules-with-CDP-Kerberos/m-p/365984#M239459</link>
      <description>&lt;P&gt;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/12021"&gt;@larsfrancke&lt;/a&gt;&amp;nbsp;Unfortunately I do not have the exact solution or information you need.&amp;nbsp; However,&amp;nbsp; I do have multiple customers whom have gotten their CDP on Isilon kerberized and in production.&amp;nbsp; &amp;nbsp;There were some tickets on our support side leading through the kerberos setup, but the specific technical solution came from Dell's side since this is supported solution for Isilon.&amp;nbsp; My recommendation is to work with Cloudera Support to see if they have suggestions, and then work with Dell Support coming out of that.&amp;nbsp; &amp;nbsp;Your Cloudera account team and Dell Partner should have access to deeper resources if both support's cannot resolve.&lt;/P&gt;</description>
      <pubDate>Mon, 13 Mar 2023 14:18:39 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Isilon-User-Mapping-Rules-with-CDP-Kerberos/m-p/365984#M239459</guid>
      <dc:creator>steven-matison</dc:creator>
      <dc:date>2023-03-13T14:18:39Z</dc:date>
    </item>
    <item>
      <title>Re: Isilon User Mapping Rules with CDP / Kerberos</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Isilon-User-Mapping-Rules-with-CDP-Kerberos/m-p/365987#M239462</link>
      <description>&lt;P&gt;Thank you!&lt;/P&gt;&lt;P&gt;We've engaged Dell but it's been .... slow &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;I'll ask my customer to reach out to Cloudera Support as well, that's a good idea.&lt;/P&gt;</description>
      <pubDate>Mon, 13 Mar 2023 15:10:19 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Isilon-User-Mapping-Rules-with-CDP-Kerberos/m-p/365987#M239462</guid>
      <dc:creator>larsfrancke</dc:creator>
      <dc:date>2023-03-13T15:10:19Z</dc:date>
    </item>
    <item>
      <title>Re: Isilon User Mapping Rules with CDP / Kerberos</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Isilon-User-Mapping-Rules-with-CDP-Kerberos/m-p/391374#M247589</link>
      <description>&lt;P&gt;hi&amp;nbsp;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/12021"&gt;@larsfrancke&lt;/a&gt;&amp;nbsp;.&lt;BR /&gt;&lt;BR /&gt;I am facing the same problem. Could you share what was done to solve this issue?&lt;/P&gt;</description>
      <pubDate>Mon, 05 Aug 2024 21:44:08 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Isilon-User-Mapping-Rules-with-CDP-Kerberos/m-p/391374#M247589</guid>
      <dc:creator>teocjc</dc:creator>
      <dc:date>2024-08-05T21:44:08Z</dc:date>
    </item>
  </channel>
</rss>

