<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>question Re: IPA  ldap Ambari Sync in Support Questions</title>
    <link>https://community.cloudera.com/t5/Support-Questions/IPA-ldap-Ambari-Sync/m-p/118407#M81190</link>
    <description>&lt;P&gt;&lt;A rel="user" href="https://community.cloudera.com/users/10529/akeezhadath.html" nodeid="10529"&gt;@Arun A K&lt;/A&gt; I just use the Web Gui that comes with IPA ldap.  Keep in mind I am not managing a large user base, but rather just doing small recreations to help customers.  I would think the GUI would get cumbersome if you were doing an entire enterprise.&lt;/P&gt;</description>
    <pubDate>Thu, 25 Aug 2016 02:42:33 GMT</pubDate>
    <dc:creator>orlandoteixeira</dc:creator>
    <dc:date>2016-08-25T02:42:33Z</dc:date>
    <item>
      <title>IPA  ldap Ambari Sync</title>
      <link>https://community.cloudera.com/t5/Support-Questions/IPA-ldap-Ambari-Sync/m-p/118397#M81180</link>
      <description>&lt;P&gt;Hi All, 
I am trying to sync my Directory users from IPA server to Ambari. I have been using &lt;A target="_blank" href="https://docs.hortonworks.com/HDPDocuments/Ambari-2.1.1.0/bk_Ambari_Security_Guide/content/_configure_ambari_to_use_ldap_server.html "&gt;these instructions&lt;/A&gt;&lt;/P&gt;&lt;P&gt;However, I am not certain what need to be the value of &lt;STRONG&gt;&lt;EM&gt;Distinguished name attribute&lt;/EM&gt;&lt;/STRONG&gt;. &lt;/P&gt;&lt;P&gt;Provided I have the following structure &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;PRE&gt;uid=u1,ou=ou11,ou=o1,dc=example,dc=com 

uid=u2,ou=ou12,ou=o1,dc=example,dc=com 

uid=u3,ou=ou21,ou=02,dc=example,dc=com 

uid=u4,ou=ou22,ou=02,dc=example,dc=com&lt;/PRE&gt;</description>
      <pubDate>Thu, 25 Aug 2016 01:50:05 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/IPA-ldap-Ambari-Sync/m-p/118397#M81180</guid>
      <dc:creator>arunak</dc:creator>
      <dc:date>2016-08-25T01:50:05Z</dc:date>
    </item>
    <item>
      <title>Re: IPA  ldap Ambari Sync</title>
      <link>https://community.cloudera.com/t5/Support-Questions/IPA-ldap-Ambari-Sync/m-p/118398#M81181</link>
      <description>&lt;P&gt;Here are the default IPA Values (If you used a out of the box no changes IPA) that work for me:&lt;/P&gt;&lt;P&gt;authentication.ldap.dnAttribute=dn&lt;/P&gt;&lt;P&gt;authentication.ldap.groupMembershipAttr= memberUid&lt;/P&gt;&lt;P&gt;authentication.ldap.groupObjectClass=posixGroup&lt;/P&gt;&lt;P&gt;authentication.ldap.userObjectClass=mepManagedEntry&lt;/P&gt;&lt;P&gt;authentication.ldap.usernameAttribute=cn&lt;/P&gt;</description>
      <pubDate>Thu, 25 Aug 2016 01:55:35 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/IPA-ldap-Ambari-Sync/m-p/118398#M81181</guid>
      <dc:creator>orlandoteixeira</dc:creator>
      <dc:date>2016-08-25T01:55:35Z</dc:date>
    </item>
    <item>
      <title>Re: IPA  ldap Ambari Sync</title>
      <link>https://community.cloudera.com/t5/Support-Questions/IPA-ldap-Ambari-Sync/m-p/118399#M81182</link>
      <description>&lt;P&gt;Try Distinguished name attribute* (dn): &lt;STRONG&gt;dn&lt;/STRONG&gt;

&lt;/P&gt;</description>
      <pubDate>Thu, 25 Aug 2016 01:58:53 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/IPA-ldap-Ambari-Sync/m-p/118399#M81182</guid>
      <dc:creator>WhiteHa</dc:creator>
      <dc:date>2016-08-25T01:58:53Z</dc:date>
    </item>
    <item>
      <title>Re: IPA  ldap Ambari Sync</title>
      <link>https://community.cloudera.com/t5/Support-Questions/IPA-ldap-Ambari-Sync/m-p/118400#M81183</link>
      <description>&lt;P&gt;Thanks &lt;A rel="user" href="https://community.cloudera.com/users/215/oteixeira.html" nodeid="215"&gt;@Orlando Teixeira&lt;/A&gt;. Could you share me a sample ldif file that you used for ldapadd. I was able to sync the user bases using the default specified above. I did not see a &lt;STRONG&gt;dn&lt;/STRONG&gt; attribute to any of my user/group using jxplore and hence wanted to know how relevant these default values are.  

After the sync, the admin user in IPA which is defaulted to admin messed up my Ambari admin user, which is also by default admin. &lt;/P&gt;</description>
      <pubDate>Thu, 25 Aug 2016 02:04:28 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/IPA-ldap-Ambari-Sync/m-p/118400#M81183</guid>
      <dc:creator>arunak</dc:creator>
      <dc:date>2016-08-25T02:04:28Z</dc:date>
    </item>
    <item>
      <title>Re: IPA  ldap Ambari Sync</title>
      <link>https://community.cloudera.com/t5/Support-Questions/IPA-ldap-Ambari-Sync/m-p/118401#M81184</link>
      <description>&lt;P&gt;Thanks &lt;A rel="user" href="https://community.cloudera.com/users/2755/kpandey.html" nodeid="2755"&gt;@Krishna Pandey&lt;/A&gt;. Was able to use the default ones to Sync up the users. However I was not sure where there attributes are attached to my users/groups since I could not see anything called &lt;STRONG&gt;dn&lt;/STRONG&gt; using jxplorer. &lt;/P&gt;</description>
      <pubDate>Thu, 25 Aug 2016 02:07:16 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/IPA-ldap-Ambari-Sync/m-p/118401#M81184</guid>
      <dc:creator>arunak</dc:creator>
      <dc:date>2016-08-25T02:07:16Z</dc:date>
    </item>
    <item>
      <title>Re: IPA  ldap Ambari Sync</title>
      <link>https://community.cloudera.com/t5/Support-Questions/IPA-ldap-Ambari-Sync/m-p/118402#M81185</link>
      <description>&lt;P&gt;&lt;A rel="user" href="https://community.cloudera.com/users/10529/akeezhadath.html" nodeid="10529"&gt;@Arun A K&lt;/A&gt; If you have existing admin user in your AD/LDAP, it will be override the existing Ambari admin user. This is known behaviour.&lt;/P&gt;</description>
      <pubDate>Thu, 25 Aug 2016 02:12:00 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/IPA-ldap-Ambari-Sync/m-p/118402#M81185</guid>
      <dc:creator>WhiteHa</dc:creator>
      <dc:date>2016-08-25T02:12:00Z</dc:date>
    </item>
    <item>
      <title>Re: IPA  ldap Ambari Sync</title>
      <link>https://community.cloudera.com/t5/Support-Questions/IPA-ldap-Ambari-Sync/m-p/118403#M81186</link>
      <description>&lt;P&gt;&lt;A rel="user" href="https://community.cloudera.com/users/2755/kpandey.html" nodeid="2755"&gt;@Krishna Pandey&lt;/A&gt;. In anticipation of this,  I had created an ambari_admin before the sync and granted the admin role to this new user. However, after sync, I am not able to see the user management option in ambari after logging in as ambari_admin. Is this some configuration issue at my end? &lt;/P&gt;</description>
      <pubDate>Thu, 25 Aug 2016 02:12:01 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/IPA-ldap-Ambari-Sync/m-p/118403#M81186</guid>
      <dc:creator>arunak</dc:creator>
      <dc:date>2016-08-25T02:12:01Z</dc:date>
    </item>
    <item>
      <title>Re: IPA  ldap Ambari Sync</title>
      <link>https://community.cloudera.com/t5/Support-Questions/IPA-ldap-Ambari-Sync/m-p/118404#M81187</link>
      <description>&lt;P&gt;&lt;A rel="user" href="https://community.cloudera.com/users/10529/akeezhadath.html" nodeid="10529"&gt;@Arun A K&lt;/A&gt;, first let's fix your admin.  Simply go into the database and do:&lt;/P&gt;&lt;P&gt;update users set ldap_user = 0 where user_name = 'admin';&lt;/P&gt;&lt;P&gt;then reset the password as follows:&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.hortonworks.com/questions/449/how-to-reset-ambari-admin-password.html" target="_blank"&gt;https://community.hortonworks.com/questions/449/how-to-reset-ambari-admin-password.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Here is the output of an ldapsearch on a user in my IPA, to show you where dn is:&lt;/P&gt;&lt;PRE&gt;# orlando, users, accounts, ipa.example.com
dn: uid=orlando,cn=users,cn=accounts,dc=ipa,dc=example,dc=com
displayName: Orlando Teixeira
cn: Orlando Teixeira
objectClass: top
objectClass: person
objectClass: organizationalperson
objectClass: inetorgperson
objectClass: inetuser
objectClass: posixaccount
objectClass: krbprincipalaux
objectClass: krbticketpolicyaux
objectClass: ipaobject
objectClass: ipasshuser
objectClass: ipaSshGroupOfPubKeys
objectClass: mepOriginEntry
loginShell: /bin/sh
sn: Teixeira
gecos: Orlando Teixeira
homeDirectory: /home/orlando
krbPwdPolicyReference: cn=global_policy,cn=IPA.EXAMPLE.COM,cn=kerberos,dc=ipa,
 dc=example,dc=com
mail: orlando@ipa.example.com
krbPrincipalName: orlando@IPA.EXAMPLE.COM
givenName: Orlando
uid: orlando
initials: OT
ipaUniqueID: 3b9308de-895c-11e5-a188-0800274e577d
uidNumber: 1690200001
gidNumber: 1690200001
memberOf: cn=ipausers,cn=groups,cn=accounts,dc=ipa,dc=example,dc=com
memberOf: cn=test,cn=groups,cn=accounts,dc=ipa,dc=example,dc=com
memberOf: cn=test2,cn=groups,cn=accounts,dc=ipa,dc=example,dc=com
mepManagedEntry: cn=orlando,cn=groups,cn=accounts,dc=ipa,dc=example,dc=com
krbLoginFailedCount: 6
krbLastFailedAuth: 20160601185034Z


# orlando, groups, accounts, ipa.example.com
dn: cn=orlando,cn=groups,cn=accounts,dc=ipa,dc=example,dc=com
objectClass: posixgroup
objectClass: ipaobject
objectClass: mepManagedEntry
objectClass: top
cn: orlando
gidNumber: 1690200001
description: User private group for orlando
mepManagedBy: uid=orlando,cn=users,cn=accounts,dc=ipa,dc=example,dc=com
ipaUniqueID: 3b9b8388-895c-11e5-a188-0800274e577d
&lt;/PRE&gt;</description>
      <pubDate>Thu, 25 Aug 2016 02:15:02 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/IPA-ldap-Ambari-Sync/m-p/118404#M81187</guid>
      <dc:creator>orlandoteixeira</dc:creator>
      <dc:date>2016-08-25T02:15:02Z</dc:date>
    </item>
    <item>
      <title>Re: IPA  ldap Ambari Sync</title>
      <link>https://community.cloudera.com/t5/Support-Questions/IPA-ldap-Ambari-Sync/m-p/118405#M81188</link>
      <description>&lt;P&gt;The earlier created &lt;STRONG&gt;local&lt;/STRONG&gt; Ambari "ambari_admin" user should exist even after ldap sync. Please select "All" as &lt;STRONG&gt;Type&lt;/STRONG&gt; in &lt;STRONG&gt;Manage Ambari&lt;/STRONG&gt; -&amp;gt; &lt;STRONG&gt;User+Group Management &lt;/STRONG&gt;section, your user should show up there.&lt;/P&gt;</description>
      <pubDate>Thu, 25 Aug 2016 02:24:03 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/IPA-ldap-Ambari-Sync/m-p/118405#M81188</guid>
      <dc:creator>WhiteHa</dc:creator>
      <dc:date>2016-08-25T02:24:03Z</dc:date>
    </item>
    <item>
      <title>Re: IPA  ldap Ambari Sync</title>
      <link>https://community.cloudera.com/t5/Support-Questions/IPA-ldap-Ambari-Sync/m-p/118406#M81189</link>
      <description>&lt;P&gt;Thanks &lt;A rel="user" href="https://community.cloudera.com/users/215/oteixeira.html" nodeid="215"&gt;@Orlando Teixeira&lt;/A&gt;. 
One last question - what tool do you use to add users to the directory? I have been using &lt;STRONG&gt;ipa user-add&lt;/STRONG&gt; and &lt;STRONG&gt;ipa group-add&lt;/STRONG&gt; and as a result, if I do a ldap search, I don't find any values for krbPwdPolicyReference: and krbPrincipalName. Is there something I am doing wrong here. 

&lt;/P&gt;&lt;PRE&gt;[admin@ipa ec2-user]$ ldapsearch -x  -W "uid=jsmith"
Enter LDAP Password: 
# extended LDIF
#
# LDAPv3
# base &amp;lt;dc=example,dc=com&amp;gt; (default) with scope subtree
# filter: uid=jsmith
# requesting: ALL
#
# jsmith, users, compat, arunak.com
dn: uid=jsmith,cn=users,cn=compat,dc=example,dc=com
cn: James Smith
objectClass: posixAccount
objectClass: ipaOverrideTarget
objectClass: top
ipaAnchorUUID:: OklQQTphcnVuYWsuY29tOmVhMzk5OGEwLTY2NDAtMTFlNi05NTExLTEyNzY0N2
 ZhZThlOQ==
gidNumber: 443400011
gecos: James Smith
uidNumber: 443400011
loginShell: /bin/sh
homeDirectory: /home/jsmith
uid: jsmith
# jsmith, users, accounts, example.com
dn: uid=jsmith,cn=users,cn=accounts,dc=example,dc=com
displayName: James Smith
uid: tutui
objectClass: ipaobject
objectClass: person
objectClass: top
objectClass: ipasshuser
objectClass: inetorgperson
objectClass: organizationalperson
objectClass: krbticketpolicyaux
objectClass: krbprincipalaux
objectClass: inetuser
objectClass: posixaccount
objectClass: ipaSshGroupOfPubKeys
objectClass: mepOriginEntry
loginShell: /bin/sh
initials: SA
gecos: James Smith
sn: Smith
homeDirectory: /home/jsmith
givenName: James
cn: James Smith
uidNumber: 443400011
gidNumber: 443400011
# search result
search: 2
result: 0 Success
# numResponses: 3
# numEntries: 2&lt;/PRE&gt;</description>
      <pubDate>Thu, 25 Aug 2016 02:40:01 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/IPA-ldap-Ambari-Sync/m-p/118406#M81189</guid>
      <dc:creator>arunak</dc:creator>
      <dc:date>2016-08-25T02:40:01Z</dc:date>
    </item>
    <item>
      <title>Re: IPA  ldap Ambari Sync</title>
      <link>https://community.cloudera.com/t5/Support-Questions/IPA-ldap-Ambari-Sync/m-p/118407#M81190</link>
      <description>&lt;P&gt;&lt;A rel="user" href="https://community.cloudera.com/users/10529/akeezhadath.html" nodeid="10529"&gt;@Arun A K&lt;/A&gt; I just use the Web Gui that comes with IPA ldap.  Keep in mind I am not managing a large user base, but rather just doing small recreations to help customers.  I would think the GUI would get cumbersome if you were doing an entire enterprise.&lt;/P&gt;</description>
      <pubDate>Thu, 25 Aug 2016 02:42:33 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/IPA-ldap-Ambari-Sync/m-p/118407#M81190</guid>
      <dc:creator>orlandoteixeira</dc:creator>
      <dc:date>2016-08-25T02:42:33Z</dc:date>
    </item>
    <item>
      <title>Re: IPA  ldap Ambari Sync</title>
      <link>https://community.cloudera.com/t5/Support-Questions/IPA-ldap-Ambari-Sync/m-p/118408#M81191</link>
      <description>&lt;P&gt;Thanks Again!!. I was prototyping, and hence wasn't looking for something at an enterprise level. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 25 Aug 2016 02:44:51 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/IPA-ldap-Ambari-Sync/m-p/118408#M81191</guid>
      <dc:creator>arunak</dc:creator>
      <dc:date>2016-08-25T02:44:51Z</dc:date>
    </item>
  </channel>
</rss>

