<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>question Re: Knox sso for ambari and ranger does not work in Support Questions</title>
    <link>https://community.cloudera.com/t5/Support-Questions/Knox-sso-for-ambari-and-ranger-does-not-work/m-p/118516#M81299</link>
    <description>&lt;P&gt;Can you provide the complete logs to debug further.&lt;/P&gt;</description>
    <pubDate>Wed, 22 Feb 2017 17:03:37 GMT</pubDate>
    <dc:creator>Anishkumarv</dc:creator>
    <dc:date>2017-02-22T17:03:37Z</dc:date>
    <item>
      <title>Knox sso for ambari and ranger does not work</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Knox-sso-for-ambari-and-ranger-does-not-work/m-p/118514#M81297</link>
      <description>&lt;P&gt;hi all:&lt;/P&gt;&lt;P&gt;i config the knox sso for ambari use this doc,&lt;A href="https://docs.hortonworks.com/HDPDocuments/HDP2/HDP-2.5.0/bk_security/content/setting_up_knox_sso_for_ambari.html" rel="nofollow noopener noreferrer" target="_blank"&gt;https://docs.hortonworks.com/HDPDocuments/HDP2/HDP-2.5.0/bk_security/content/setting_up_knox_sso_for_ambari.html&lt;/A&gt;, but when i submit the login page, then the page redirect to the ambari login page,and the redirect back again.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="11816-knox-sso.png" style="width: 554px;"&gt;&lt;img src="https://community.cloudera.com/t5/image/serverpage/image-id/22976i50D805B675323DFD/image-size/medium?v=v2&amp;amp;px=400" role="button" title="11816-knox-sso.png" alt="11816-knox-sso.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt; here is the amabri-server.log:&lt;/P&gt;&lt;P&gt;User(null), RemoteIp(192.168.XX.XX), Operation(User login), Roles(
), Status(Failed), Reason(Authentication required).&lt;/P&gt;&lt;P&gt;and knox gateway.log:&lt;/P&gt;&lt;P&gt;ed310ab8-e377-4781-adfb-27f94d472e90|audit|KNOXSSO||||access|uri|/gateway/knoxsso/api/v1/websso?originalUrl=http%3A%2F%2Fbigdata%3A8080%2F%23%2Flogin?redirected=true|success|Response status: 401&lt;/P&gt;</description>
      <pubDate>Mon, 19 Aug 2019 10:45:17 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Knox-sso-for-ambari-and-ranger-does-not-work/m-p/118514#M81297</guid>
      <dc:creator>leezy</dc:creator>
      <dc:date>2019-08-19T10:45:17Z</dc:date>
    </item>
    <item>
      <title>Re: Knox sso for ambari and ranger does not work</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Knox-sso-for-ambari-and-ranger-does-not-work/m-p/118515#M81298</link>
      <description>&lt;P&gt;Can you provide KnoxSSO topology from Knox configuration? Also try to authenticate using an User in Knox, as you are getting 401.&lt;/P&gt;</description>
      <pubDate>Wed, 22 Feb 2017 16:52:15 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Knox-sso-for-ambari-and-ranger-does-not-work/m-p/118515#M81298</guid>
      <dc:creator>WhiteHa</dc:creator>
      <dc:date>2017-02-22T16:52:15Z</dc:date>
    </item>
    <item>
      <title>Re: Knox sso for ambari and ranger does not work</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Knox-sso-for-ambari-and-ranger-does-not-work/m-p/118516#M81299</link>
      <description>&lt;P&gt;Can you provide the complete logs to debug further.&lt;/P&gt;</description>
      <pubDate>Wed, 22 Feb 2017 17:03:37 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Knox-sso-for-ambari-and-ranger-does-not-work/m-p/118516#M81299</guid>
      <dc:creator>Anishkumarv</dc:creator>
      <dc:date>2017-02-22T17:03:37Z</dc:date>
    </item>
    <item>
      <title>Re: Knox sso for ambari and ranger does not work</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Knox-sso-for-ambari-and-ranger-does-not-work/m-p/118517#M81300</link>
      <description>&lt;P&gt; &amp;lt;topology&amp;gt;
          &amp;lt;gateway&amp;gt;
              &amp;lt;provider&amp;gt;
                  &amp;lt;role&amp;gt;webappsec&amp;lt;/role&amp;gt;
                  &amp;lt;name&amp;gt;WebAppSec&amp;lt;/name&amp;gt;
                  &amp;lt;enabled&amp;gt;true&amp;lt;/enabled&amp;gt;
                  &amp;lt;param&amp;gt;&amp;lt;name&amp;gt;xframe.options.enabled&amp;lt;/name&amp;gt;&amp;lt;value&amp;gt;true&amp;lt;/value&amp;gt;&amp;lt;/param&amp;gt;
              &amp;lt;/provider&amp;gt;
              &amp;lt;provider&amp;gt;
                  &amp;lt;role&amp;gt;authentication&amp;lt;/role&amp;gt;
                  &amp;lt;name&amp;gt;ShiroProvider&amp;lt;/name&amp;gt;
                  &amp;lt;enabled&amp;gt;true&amp;lt;/enabled&amp;gt;
                  &amp;lt;param&amp;gt;
                      &amp;lt;name&amp;gt;sessionTimeout&amp;lt;/name&amp;gt;
                      &amp;lt;value&amp;gt;30&amp;lt;/value&amp;gt;
                  &amp;lt;/param&amp;gt;
                  &amp;lt;param&amp;gt;
                      &amp;lt;name&amp;gt;redirectToUrl&amp;lt;/name&amp;gt;
                      &amp;lt;value&amp;gt;/gateway/knoxsso/knoxauth/login.html&amp;lt;/value&amp;gt;
                  &amp;lt;/param&amp;gt;
                  &amp;lt;param&amp;gt;
                      &amp;lt;name&amp;gt;restrictedCookies&amp;lt;/name&amp;gt;
                      &amp;lt;value&amp;gt;rememberme,WWW-Authenticate&amp;lt;/value&amp;gt;
                  &amp;lt;/param&amp;gt;
                  &amp;lt;param&amp;gt;
                      &amp;lt;name&amp;gt;main.ldapRealm&amp;lt;/name&amp;gt;
                      &amp;lt;value&amp;gt;org.apache.hadoop.gateway.shirorealm.KnoxLdapRealm&amp;lt;/value&amp;gt;
                  &amp;lt;/param&amp;gt;
                  &amp;lt;param&amp;gt;
                      &amp;lt;name&amp;gt;main.ldapContextFactory&amp;lt;/name&amp;gt;
                      &amp;lt;value&amp;gt;org.apache.hadoop.gateway.shirorealm.KnoxLdapContextFactory&amp;lt;/value&amp;gt;
                  &amp;lt;/param&amp;gt;&amp;lt;param&amp;gt;
                      &amp;lt;name&amp;gt;main.ldapRealm.contextFactory&amp;lt;/name&amp;gt;
                      &amp;lt;value&amp;gt;$ldapContextFactory&amp;lt;/value&amp;gt;
                  &amp;lt;/param&amp;gt;
                  &amp;lt;param&amp;gt;
                      &amp;lt;name&amp;gt;main.ldapRealm.userDnTemplate&amp;lt;/name&amp;gt;
                      &amp;lt;value&amp;gt;uid={0},ou=people,dc=VENUS,dc=COM&amp;lt;/value&amp;gt;
                  &amp;lt;/param&amp;gt;
                  &amp;lt;param&amp;gt;
                      &amp;lt;name&amp;gt;main.ldapRealm.contextFactory.url&amp;lt;/name&amp;gt;
                      &amp;lt;value&amp;gt;ldap://bigdata7:389&amp;lt;/value&amp;gt;
                  &amp;lt;/param&amp;gt;
                  &amp;lt;param&amp;gt;
                      &amp;lt;name&amp;gt;main.ldapRealm.authenticationCachingEnabled&amp;lt;/name&amp;gt;
                      &amp;lt;value&amp;gt;false&amp;lt;/value&amp;gt;
                  &amp;lt;/param&amp;gt;
                  &amp;lt;param&amp;gt;
                      &amp;lt;name&amp;gt;main.ldapRealm.contextFactory.authenticationMechanism&amp;lt;/name&amp;gt;
                      &amp;lt;value&amp;gt;simple&amp;lt;/value&amp;gt;
                  &amp;lt;/param&amp;gt;
                  &amp;lt;param&amp;gt;
                      &amp;lt;name&amp;gt;urls./**&amp;lt;/name&amp;gt;
                      &amp;lt;value&amp;gt;authcBasic&amp;lt;/value&amp;gt;
                  &amp;lt;/param&amp;gt;
              &amp;lt;/provider&amp;gt;
              &amp;lt;provider&amp;gt;
                  &amp;lt;role&amp;gt;identity-assertion&amp;lt;/role&amp;gt;
                  &amp;lt;name&amp;gt;Default&amp;lt;/name&amp;gt;
                  &amp;lt;enabled&amp;gt;true&amp;lt;/enabled&amp;gt;
              &amp;lt;/provider&amp;gt;
          &amp;lt;/gateway&amp;gt;        &amp;lt;application&amp;gt;
            &amp;lt;name&amp;gt;knoxauth&amp;lt;/name&amp;gt;
          &amp;lt;/application&amp;gt;
          &amp;lt;service&amp;gt;
              &amp;lt;role&amp;gt;KNOXSSO&amp;lt;/role&amp;gt;
              &amp;lt;param&amp;gt;
                  &amp;lt;name&amp;gt;knoxsso.cookie.secure.only&amp;lt;/name&amp;gt;
                  &amp;lt;value&amp;gt;false&amp;lt;/value&amp;gt;
              &amp;lt;/param&amp;gt;
              &amp;lt;param&amp;gt;
                  &amp;lt;name&amp;gt;knoxsso.token.ttl&amp;lt;/name&amp;gt;
                  &amp;lt;value&amp;gt;30000&amp;lt;/value&amp;gt;
              &amp;lt;/param&amp;gt;
              &amp;lt;param&amp;gt;
                 &amp;lt;name&amp;gt;knoxsso.redirect.whitelist.regex&amp;lt;/name&amp;gt;
                 &amp;lt;value&amp;gt;^https?:\/\/(bigdata[0-9]|localhost|127\.0\.0\.1|0:0:0:0:0:0:0:1|::1):[0-9].*{replace15}lt;/value&amp;gt;
             &amp;lt;/param&amp;gt;&amp;lt;/service&amp;gt;
      &amp;lt;/topology&amp;gt;&lt;/P&gt;&lt;P&gt;this is my knox sso topology， and my knox and ambari-server is not in the same machine.&lt;/P&gt;</description>
      <pubDate>Wed, 22 Feb 2017 17:27:57 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Knox-sso-for-ambari-and-ranger-does-not-work/m-p/118517#M81300</guid>
      <dc:creator>leezy</dc:creator>
      <dc:date>2017-02-22T17:27:57Z</dc:date>
    </item>
    <item>
      <title>Re: Knox sso for ambari and ranger does not work</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Knox-sso-for-ambari-and-ranger-does-not-work/m-p/118518#M81301</link>
      <description>&lt;P&gt;17/02/22 17:46:07 ||f67516cd-e553-43c8-9666-4dfd95b63a3c|audit|KNOXSSO||||access|uri|/gateway/knoxsso/api/v1/websso?originalUrl=http://bigdata6:8080/|unavailable|Request method: POST
17/02/22 17:46:07 ||f67516cd-e553-43c8-9666-4dfd95b63a3c|audit|KNOXSSO|venus|||authentication|uri|/gateway/knoxsso/api/v1/websso?originalUrl=http://bigdata6:8080/|success|
17/02/22 17:46:07 ||f67516cd-e553-43c8-9666-4dfd95b63a3c|audit|KNOXSSO|venus|||authentication|uri|/gateway/knoxsso/api/v1/websso?originalUrl=http://bigdata6:8080/|success|Groups: []
17/02/22 17:46:07 ||f67516cd-e553-43c8-9666-4dfd95b63a3c|audit|KNOXSSO|venus|||access|uri|/gateway/knoxsso/api/v1/websso?originalUrl=http://bigdata6:8080/|success|Response status: 303
17/02/22 17:46:07 ||cc006ac5-1b98-4d20-bbdd-03a30f26fda4|audit|knoxauth||||access|uri|/gateway/knoxsso/knoxauth/redirecting.html?originalUrl=http://bigdata6:8080/|unavailable|Request method: GET
17/02/22 17:46:07 ||cc006ac5-1b98-4d20-bbdd-03a30f26fda4|audit|knoxauth||||access|uri|/gateway/knoxsso/knoxauth/redirecting.html?originalUrl=http://bigdata6:8080/|success|Response status: 200
17/02/22 17:46:07 ||2f023049-55b3-4bd9-879d-2430bde60f1f|audit|knoxauth||||access|uri|/gateway/knoxsso/knoxauth/styles/bootstrap.min.css|unavailable|Request method: GET
17/02/22 17:46:07 ||2f023049-55b3-4bd9-879d-2430bde60f1f|audit|knoxauth||||access|uri|/gateway/knoxsso/knoxauth/styles/bootstrap.min.css|success|Response status: 200
17/02/22 17:46:07 ||a0848c4b-637b-4699-8cec-efc85f425f6f|audit|knoxauth||||access|uri|/gateway/knoxsso/knoxauth/styles/knox.css|unavailable|Request method: GET
17/02/22 17:46:07 ||a0848c4b-637b-4699-8cec-efc85f425f6f|audit|knoxauth||||access|uri|/gateway/knoxsso/knoxauth/styles/knox.css|success|Response status: 200
17/02/22 17:46:07 ||cd5a3a24-5332-45c2-80b6-edbb8298cd07|audit|knoxauth||||access|uri|/gateway/knoxsso/knoxauth/images/loading.gif|unavailable|Request method: GET
17/02/22 17:46:07 ||cd5a3a24-5332-45c2-80b6-edbb8298cd07|audit|knoxauth||||access|uri|/gateway/knoxsso/knoxauth/images/loading.gif|success|Response status: 200
17/02/22 17:46:08 ||ded2eb86-5184-4c17-bfe2-ca557ae16fac|audit|KNOXSSO||||access|uri|/gateway/knoxsso/api/v1/websso?originalUrl=http%3A%2F%2Fbigdata6%3A8080%2F%23%2Flogin?redirected=true|unavailable|Request method: GET
17/02/22 17:46:08 ||ded2eb86-5184-4c17-bfe2-ca557ae16fac|audit|KNOXSSO||||access|uri|/gateway/knoxsso/api/v1/websso?originalUrl=http%3A%2F%2Fbigdata6%3A8080%2F%23%2Flogin?redirected=true|success|Response status: 401
17/02/22 17:46:08 ||6eb6e25a-4321-4c69-a7f5-aa7ea15ceb57|audit|knoxauth||||access|uri|/gateway/knoxsso/knoxauth/login.html?originalUrl=http%3A%2F%2Fbigdata6%3A8080%2F%23%2Flogin?redirected=true|unavailable|Request method: GET 17/02/22 17:46:08 ||6eb6e25a-4321-4c69-a7f5-aa7ea15ceb57|audit|knoxauth||||access|uri|/gateway/knoxsso/knoxauth/login.html?originalUrl=http%3A%2F%2Fbigdata6%3A8080%2F%23%2Flogin?redirected=true|success|Response status: 200
17/02/22 17:46:08 ||6e3bca36-1991-40bc-9587-fe35c3ecc61d|audit|knoxauth||||access|uri|/gateway/knoxsso/knoxauth/styles/bootstrap.min.css|unavailable|Request method: GET
17/02/22 17:46:08 ||f355e30a-2159-42b9-8659-043dc3ef9496|audit|knoxauth||||access|uri|/gateway/knoxsso/knoxauth/styles/knox.css|unavailable|Request method: GET
17/02/22 17:46:08 ||f355e30a-2159-42b9-8659-043dc3ef9496|audit|knoxauth||||access|uri|/gateway/knoxsso/knoxauth/styles/knox.css|success|Response status: 200
17/02/22 17:46:08 ||6e3bca36-1991-40bc-9587-fe35c3ecc61d|audit|knoxauth||||access|uri|/gateway/knoxsso/knoxauth/styles/bootstrap.min.css|success|Response status: 200&lt;/P&gt;&lt;P&gt;this is log that visit one time&lt;/P&gt;</description>
      <pubDate>Wed, 22 Feb 2017 17:29:28 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Knox-sso-for-ambari-and-ranger-does-not-work/m-p/118518#M81301</guid>
      <dc:creator>leezy</dc:creator>
      <dc:date>2017-02-22T17:29:28Z</dc:date>
    </item>
    <item>
      <title>Re: Knox sso for ambari and ranger does not work</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Knox-sso-for-ambari-and-ranger-does-not-work/m-p/118519#M81302</link>
      <description>&lt;P&gt;the ambari and knox sso use the same user, and knox use ldap&lt;/P&gt;</description>
      <pubDate>Wed, 22 Feb 2017 17:31:13 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Knox-sso-for-ambari-and-ranger-does-not-work/m-p/118519#M81302</guid>
      <dc:creator>leezy</dc:creator>
      <dc:date>2017-02-22T17:31:13Z</dc:date>
    </item>
    <item>
      <title>Re: Knox sso for ambari and ranger does not work</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Knox-sso-for-ambari-and-ranger-does-not-work/m-p/118520#M81303</link>
      <description>&lt;P&gt;I think the problem is your hostname which does not have FQDN. e.g. somehost.abc.com , Try putting /etc/hosts entries with FQDN for your "bigdata[0-9]" hosts.
KnoxSSO requires host TLD to set cookies for that domain.&lt;/P&gt;</description>
      <pubDate>Wed, 22 Feb 2017 17:43:08 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Knox-sso-for-ambari-and-ranger-does-not-work/m-p/118520#M81303</guid>
      <dc:creator>WhiteHa</dc:creator>
      <dc:date>2017-02-22T17:43:08Z</dc:date>
    </item>
    <item>
      <title>Re: Knox sso for ambari and ranger does not work</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Knox-sso-for-ambari-and-ranger-does-not-work/m-p/118521#M81304</link>
      <description>&lt;P&gt;yes,thank you,the knox host and ambari host should be the same domain suffix. i've solve this. &lt;/P&gt;</description>
      <pubDate>Thu, 23 Feb 2017 10:18:07 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Knox-sso-for-ambari-and-ranger-does-not-work/m-p/118521#M81304</guid>
      <dc:creator>leezy</dc:creator>
      <dc:date>2017-02-23T10:18:07Z</dc:date>
    </item>
    <item>
      <title>Re: Knox sso for ambari and ranger does not work</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Knox-sso-for-ambari-and-ranger-does-not-work/m-p/118522#M81305</link>
      <description>&lt;P&gt;I have meet the same problem,but I don`t know how to setup my own domain.&lt;/P&gt;&lt;P&gt;May you have solved this problem,If you have some suggest will be will kind for me.&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Mon, 20 Mar 2017 16:35:46 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Knox-sso-for-ambari-and-ranger-does-not-work/m-p/118522#M81305</guid>
      <dc:creator>minskychen</dc:creator>
      <dc:date>2017-03-20T16:35:46Z</dc:date>
    </item>
  </channel>
</rss>

