<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>question Kafka policies created in Ranger are not becoming active in Support Questions</title>
    <link>https://community.cloudera.com/t5/Support-Questions/Kafka-policies-created-in-Ranger-are-not-becoming-active/m-p/405101#M252411</link>
    <description>&lt;P&gt;Kafka policies created in Ranger are getting downloaded but not becoming active. Using Apache Ranger 2.6 and Apache Kafka 3.6. Couldn't find any specific errors related to this issue.&lt;/P&gt;&lt;P&gt;Ranger and Kafka are configured with LDAP and no kerberos. What could be the possible issue? Any help is appreciated!&lt;BR /&gt;&lt;BR /&gt;Ranger policies for HDFS and Hive works fine.&lt;BR /&gt;&lt;BR /&gt;Below are the ldap and ranger configs in Kafka&lt;/P&gt;&lt;P&gt;authorizer.class.name=org.apache.ranger.authorization.kafka.authorizer.RangerKafkaAuthorizer&lt;BR /&gt;&lt;BR /&gt;sasl.enabled.mechanisms=PLAIN&lt;/P&gt;&lt;P&gt;listener.name.sasl_plaintext.sasl.enabled.mechanisms=PLAIN&lt;BR /&gt;listener.name.sasl_plaintext.plain.sasl.jaas.config=org.apache.kafka.common.security.plain.PlainLoginModule required;&lt;BR /&gt;listener.name.sasl_plaintext.plain.sasl.server.callback.handler.class=io.confluent.security.auth.provider.ldap.LdapAuthenticateCallbackHandler&lt;/P&gt;&lt;P&gt;ldap.java.naming.provider.url=ldap://&amp;lt;ldap_host&amp;gt;:389&lt;BR /&gt;ldap.java.naming.security.authentication=simple&lt;BR /&gt;ldap.java.naming.security.principal=CN=&amp;lt;bind_user&amp;gt;,OU=Service_Accounts,DC=hadoop,DC=hdp,DC=com&lt;BR /&gt;ldap.java.naming.security.credentials=&lt;/P&gt;&lt;P&gt;ldap.user.name.attribute=sAMAccountName&lt;BR /&gt;ldap.user.object.class=user&lt;BR /&gt;ldap.user.search.base=OU=User_Accounts,DC=hadoop,DC=hdp,DC=com;OU=Service_Accounts,DC=hadoop,DC=hdp,DC=com&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;#server properties&lt;BR /&gt;ldap.java.naming.provider.url=ldap://&amp;lt;ldap_host&amp;gt;:389&lt;BR /&gt;ldap.java.naming.security.authentication=simple&lt;BR /&gt;ldap.java.naming.security.principal=CN=&amp;lt;bind_dn&amp;gt;,OU=Service_Accounts,DC=hadoop,DC=hdp,DC=com&lt;BR /&gt;ldap.java.naming.security.credentials=&lt;/P&gt;&lt;P&gt;ldap.search.mode=GROUPS&lt;BR /&gt;ldap.user.search.base=OU=User_Accounts,DC=hadoop,DC=hdp,DC=com;OU=Service_Accounts,DC=hadoop,DC=hdp,DC=com&lt;BR /&gt;ldap.user.object.class=user&lt;BR /&gt;ldap.user.name.attribute=sAMAccountName&lt;BR /&gt;&lt;BR /&gt;ldap.group.search.base=OU=Groups,DC=hadoop,DC=hdp,DC=com&lt;BR /&gt;ldap.group.object.class=group&lt;BR /&gt;ldap.group.name.attribute=cn&lt;BR /&gt;ldap.group.member.attribute=member&lt;/P&gt;</description>
    <pubDate>Sun, 30 Mar 2025 21:17:41 GMT</pubDate>
    <dc:creator>Hadoop16</dc:creator>
    <dc:date>2025-03-30T21:17:41Z</dc:date>
    <item>
      <title>Kafka policies created in Ranger are not becoming active</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Kafka-policies-created-in-Ranger-are-not-becoming-active/m-p/405101#M252411</link>
      <description>&lt;P&gt;Kafka policies created in Ranger are getting downloaded but not becoming active. Using Apache Ranger 2.6 and Apache Kafka 3.6. Couldn't find any specific errors related to this issue.&lt;/P&gt;&lt;P&gt;Ranger and Kafka are configured with LDAP and no kerberos. What could be the possible issue? Any help is appreciated!&lt;BR /&gt;&lt;BR /&gt;Ranger policies for HDFS and Hive works fine.&lt;BR /&gt;&lt;BR /&gt;Below are the ldap and ranger configs in Kafka&lt;/P&gt;&lt;P&gt;authorizer.class.name=org.apache.ranger.authorization.kafka.authorizer.RangerKafkaAuthorizer&lt;BR /&gt;&lt;BR /&gt;sasl.enabled.mechanisms=PLAIN&lt;/P&gt;&lt;P&gt;listener.name.sasl_plaintext.sasl.enabled.mechanisms=PLAIN&lt;BR /&gt;listener.name.sasl_plaintext.plain.sasl.jaas.config=org.apache.kafka.common.security.plain.PlainLoginModule required;&lt;BR /&gt;listener.name.sasl_plaintext.plain.sasl.server.callback.handler.class=io.confluent.security.auth.provider.ldap.LdapAuthenticateCallbackHandler&lt;/P&gt;&lt;P&gt;ldap.java.naming.provider.url=ldap://&amp;lt;ldap_host&amp;gt;:389&lt;BR /&gt;ldap.java.naming.security.authentication=simple&lt;BR /&gt;ldap.java.naming.security.principal=CN=&amp;lt;bind_user&amp;gt;,OU=Service_Accounts,DC=hadoop,DC=hdp,DC=com&lt;BR /&gt;ldap.java.naming.security.credentials=&lt;/P&gt;&lt;P&gt;ldap.user.name.attribute=sAMAccountName&lt;BR /&gt;ldap.user.object.class=user&lt;BR /&gt;ldap.user.search.base=OU=User_Accounts,DC=hadoop,DC=hdp,DC=com;OU=Service_Accounts,DC=hadoop,DC=hdp,DC=com&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;#server properties&lt;BR /&gt;ldap.java.naming.provider.url=ldap://&amp;lt;ldap_host&amp;gt;:389&lt;BR /&gt;ldap.java.naming.security.authentication=simple&lt;BR /&gt;ldap.java.naming.security.principal=CN=&amp;lt;bind_dn&amp;gt;,OU=Service_Accounts,DC=hadoop,DC=hdp,DC=com&lt;BR /&gt;ldap.java.naming.security.credentials=&lt;/P&gt;&lt;P&gt;ldap.search.mode=GROUPS&lt;BR /&gt;ldap.user.search.base=OU=User_Accounts,DC=hadoop,DC=hdp,DC=com;OU=Service_Accounts,DC=hadoop,DC=hdp,DC=com&lt;BR /&gt;ldap.user.object.class=user&lt;BR /&gt;ldap.user.name.attribute=sAMAccountName&lt;BR /&gt;&lt;BR /&gt;ldap.group.search.base=OU=Groups,DC=hadoop,DC=hdp,DC=com&lt;BR /&gt;ldap.group.object.class=group&lt;BR /&gt;ldap.group.name.attribute=cn&lt;BR /&gt;ldap.group.member.attribute=member&lt;/P&gt;</description>
      <pubDate>Sun, 30 Mar 2025 21:17:41 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Kafka-policies-created-in-Ranger-are-not-becoming-active/m-p/405101#M252411</guid>
      <dc:creator>Hadoop16</dc:creator>
      <dc:date>2025-03-30T21:17:41Z</dc:date>
    </item>
    <item>
      <title>Re: Kafka policies created in Ranger are not becoming active</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Kafka-policies-created-in-Ranger-are-not-becoming-active/m-p/405107#M252413</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/109626"&gt;@Hadoop16&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you for reaching out to the community&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is this a fresh setup? Also just double-check if noexec is not set /tmp&lt;/P&gt;&lt;P&gt;Could you please check the Kafka logs to see if there are any errors with the plugin? Also, check Ranger Admin logs&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Usually, kerberos is required for Ranger&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.cloudera.com/cdp-private-cloud-base/7.3.1/security-ranger-configuring-advanced/topics/security-ranger-configure-kerberos-authentication.html" target="_blank"&gt;https://docs.cloudera.com/cdp-private-cloud-base/7.3.1/security-ranger-configuring-advanced/topics/security-ranger-configure-kerberos-authentication.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.cloudera.com/runtime/7.3.1/kafka-securing/topics/kafka-secure-ranger-enable.html" target="_blank"&gt;https://docs.cloudera.com/runtime/7.3.1/kafka-securing/topics/kafka-secure-ranger-enable.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 31 Mar 2025 04:25:38 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Kafka-policies-created-in-Ranger-are-not-becoming-active/m-p/405107#M252413</guid>
      <dc:creator>upadhyayk04</dc:creator>
      <dc:date>2025-03-31T04:25:38Z</dc:date>
    </item>
    <item>
      <title>Re: Kafka policies created in Ranger are not becoming active</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Kafka-policies-created-in-Ranger-are-not-becoming-active/m-p/405159#M252421</link>
      <description>&lt;P&gt;@&lt;A class="dcxa-lithium-link" href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/95611" target="_blank"&gt;&lt;SPAN&gt;upadhyayk04&lt;/SPAN&gt;&lt;/A&gt; Thank you! I tried with Kerberos enabled on Ranger and Kafka but still policies are downloading fine but not becoming active. I could see below error in Kafka log.&lt;BR /&gt;&lt;BR /&gt;DEBUG Failed to get groups for user ANONYMOUS (org.apache.hadoop.security.UserGroupInformation) java.io.IOException: No groups found for user ANONYMOUS at org.apache.hadoop.security.Groups.noGroupsForUser(Groups.java:200)&lt;/P&gt;</description>
      <pubDate>Tue, 01 Apr 2025 02:12:43 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Kafka-policies-created-in-Ranger-are-not-becoming-active/m-p/405159#M252421</guid>
      <dc:creator>Hadoop16</dc:creator>
      <dc:date>2025-04-01T02:12:43Z</dc:date>
    </item>
  </channel>
</rss>

