<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>question Has anyone integrated (for demo purposes only) the Knox LDAP demo server with the Ambari 2.1.1 Server? I am not sure that it can be done, but need the instructions if it can be done. I only need to be able to log in to Ambari using the LDAP users. in Archives of Support Questions (Read Only)</title>
    <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Has-anyone-integrated-for-demo-purposes-only-the-Knox-LDAP/m-p/96609#M10028</link>
    <description />
    <pubDate>Thu, 05 Nov 2015 07:37:03 GMT</pubDate>
    <dc:creator>sbradshaw</dc:creator>
    <dc:date>2015-11-05T07:37:03Z</dc:date>
    <item>
      <title>Has anyone integrated (for demo purposes only) the Knox LDAP demo server with the Ambari 2.1.1 Server? I am not sure that it can be done, but need the instructions if it can be done. I only need to be able to log in to Ambari using the LDAP users.</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Has-anyone-integrated-for-demo-purposes-only-the-Knox-LDAP/m-p/96609#M10028</link>
      <description />
      <pubDate>Thu, 05 Nov 2015 07:37:03 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Has-anyone-integrated-for-demo-purposes-only-the-Knox-LDAP/m-p/96609#M10028</guid>
      <dc:creator>sbradshaw</dc:creator>
      <dc:date>2015-11-05T07:37:03Z</dc:date>
    </item>
    <item>
      <title>Re: Has anyone integrated (for demo purposes only) the Knox LDAP demo server with the Ambari 2.1.1 Server? I am not sure that it can be done, but need the instructions if it can be done. I only need to be able to log in to Ambari using the LDAP users.</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Has-anyone-integrated-for-demo-purposes-only-the-Knox-LDAP/m-p/96610#M10029</link>
      <description>&lt;P&gt;Please refer to this doc note on how to disable pagination in Ambari 2.1.1+: &lt;A target="_blank" href="http://docs.hortonworks.com/HDPDocuments/Ambari-2.1.2.0/bk_Ambari_Security_Guide/content/_configuring_ambari_for_ldap_or_active_directory_authentication.html"&gt;http://docs.hortonworks.com/HDPDocuments/Ambari-2.1.2.0/bk_Ambari_Security_Guide/content/_configuring_ambari_for_ldap_or_active_directory_authentication.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 06 Nov 2015 23:10:43 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Has-anyone-integrated-for-demo-purposes-only-the-Knox-LDAP/m-p/96610#M10029</guid>
      <dc:creator>pcodding</dc:creator>
      <dc:date>2015-11-06T23:10:43Z</dc:date>
    </item>
    <item>
      <title>Re: Has anyone integrated (for demo purposes only) the Knox LDAP demo server with the Ambari 2.1.1 Server? I am not sure that it can be done, but need the instructions if it can be done. I only need to be able to log in to Ambari using the LDAP users.</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Has-anyone-integrated-for-demo-purposes-only-the-Knox-LDAP/m-p/96611#M10030</link>
      <description>&lt;P&gt;Wow, good catch. Unfortunately I'm still getting the same error with pagination disabled, so maybe it's a different feature that ApacheDS doesn't support:&lt;/P&gt;&lt;PRE&gt;REASON: Caught exception running LDAP sync. [LDAP: error code 12 - Unsupport critical control: 1.2.840.113556.1.4.319]; nested exception is javax.naming.OperationNotSupportedException: [LDAP: error code 12 - Unsupport critical control: 1.2.840.113556.1.4.319]; remaining name 'dc=hadoop,dc=apache,dc=org'&lt;/PRE&gt;</description>
      <pubDate>Sat, 07 Nov 2015 01:15:16 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Has-anyone-integrated-for-demo-purposes-only-the-Knox-LDAP/m-p/96611#M10030</guid>
      <dc:creator>amiller</dc:creator>
      <dc:date>2015-11-07T01:15:16Z</dc:date>
    </item>
    <item>
      <title>Re: Has anyone integrated (for demo purposes only) the Knox LDAP demo server with the Ambari 2.1.1 Server? I am not sure that it can be done, but need the instructions if it can be done. I only need to be able to log in to Ambari using the LDAP users.</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Has-anyone-integrated-for-demo-purposes-only-the-Knox-LDAP/m-p/96612#M10031</link>
      <description>&lt;P&gt;This looks familiar: &lt;A href="https://jira.atlassian.com/browse/CWD-1109" target="_blank"&gt;https://jira.atlassian.com/browse/CWD-1109&lt;/A&gt;&lt;/P&gt;&lt;P&gt;What Ambari version are you using Alex?&lt;/P&gt;</description>
      <pubDate>Sat, 07 Nov 2015 01:53:02 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Has-anyone-integrated-for-demo-purposes-only-the-Knox-LDAP/m-p/96612#M10031</guid>
      <dc:creator>pcodding</dc:creator>
      <dc:date>2015-11-07T01:53:02Z</dc:date>
    </item>
    <item>
      <title>Re: Has anyone integrated (for demo purposes only) the Knox LDAP demo server with the Ambari 2.1.1 Server? I am not sure that it can be done, but need the instructions if it can be done. I only need to be able to log in to Ambari using the LDAP users.</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Has-anyone-integrated-for-demo-purposes-only-the-Knox-LDAP/m-p/96613#M10032</link>
      <description>&lt;P&gt;Here's a complete guide, thanks to &lt;A rel="user" href="https://community.cloudera.com/users/32/paul.html" nodeid="32"&gt;@Paul Codding&lt;/A&gt;'s advice to disable pagination. Requires &lt;STRONG&gt;HDP Sandbox 2.3.2 or later&lt;/STRONG&gt; (Ambari 2.1.1+)&lt;/P&gt;&lt;P&gt;1. In Ambari, start the demo LDAP server (Knox gateway is not required):&lt;/P&gt;&lt;UL&gt;
&lt;LI&gt;Knox &amp;gt; Service Actions &amp;gt; Start Demo LDAP&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;2. Follow the &lt;A href="http://docs.hortonworks.com/HDPDocuments/Ambari-2.1.2.0/bk_Ambari_Security_Guide/content/_configure_ambari_to_use_ldap_server.html"&gt;Ambari Security Guide&lt;/A&gt; to enable LDAP (press Enter for blank values)...&lt;/P&gt;&lt;PRE&gt;[root@sandbox ~]# ambari-server setup-ldap
Using python  /usr/bin/python2.6
Setting up LDAP properties...
Primary URL* {host:port} : sandbox.hortonworks.com:33389
Secondary URL {host:port} :
Use SSL* [true/false] (false): false
User object class* (posixAccount): person
User name attribute* (uid): uid
Group object class* (posixGroup): groupofnames
Group name attribute* (cn): cn
Group member attribute* (memberUid): member
Distinguished name attribute* (dn): dn
Base DN* : dc=hadoop,dc=apache,dc=org
Referral method [follow/ignore] :
Bind anonymously* [true/false] (false): false
Manager DN* : uid=guest,ou=people,dc=hadoop,dc=apache,dc=org
Enter Manager Password* : guest-password
Re-enter password: guest-password
====================
Review Settings
====================
authentication.ldap.managerDn: uid=guest,ou=people,dc=hadoop,dc=apache,dc=org
authentication.ldap.managerPassword: *****
Save settings [y/n] (y)? y
Saving...done
Ambari Server 'setup-ldap' completed successfully.
&lt;/PRE&gt;&lt;P&gt;3. Configure Ambari to &lt;A href="http://docs.hortonworks.com/HDPDocuments/Ambari-2.1.2.0/bk_Ambari_Security_Guide/content/_configuring_ambari_for_ldap_or_active_directory_authentication.html"&gt;disable pagination&lt;/A&gt;, and restart Ambari Server:&lt;/P&gt;&lt;PRE&gt;[root@sandbox ~]# echo "authentication.ldap.pagination.enabled=false" &amp;gt;&amp;gt; /etc/ambari-server/conf/ambari.properties
[root@sandbox ~]# ambari-server restart
&lt;/PRE&gt;&lt;P&gt;4. When Ambari startup completes, the objects in &lt;STRONG&gt;/etc/knox/conf/users.ldif&lt;/STRONG&gt; are available in Ambari. Here’s a quick reference:&lt;/P&gt;&lt;UL&gt;
&lt;LI&gt;admin / admin-password&lt;/LI&gt;&lt;LI&gt;guest / guest-password&lt;/LI&gt;&lt;LI&gt;sam / sam-password&lt;/LI&gt;&lt;LI&gt;tom / tom-password&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;STRONG&gt;Note: &lt;/STRONG&gt;LDAP accounts with the same names as local accounts will replace the local accounts. The &lt;STRONG&gt;admin password will now be 'admin-password'&lt;/STRONG&gt; instead of 'admin'&lt;/P&gt;&lt;P&gt;5. To customize the demo LDAP directory:&lt;/P&gt;&lt;UL&gt;
&lt;LI&gt;In Ambari: Knox &amp;gt; Service Actions &amp;gt; Stop Demo LDAP&lt;/LI&gt;&lt;LI&gt;Edit /etc/knox/conf/users.ldif&lt;/LI&gt;&lt;LI&gt;Start the LDAP server manually (Ambari will overwrite users.ldif)&lt;/LI&gt;&lt;/UL&gt;&lt;PRE&gt;nohup su - knox -c 'java -jar /usr/hdp/current/knox-server/bin/ldap.jar /usr/hdp/current/knox-server/conf' &amp;amp;&lt;/PRE&gt;&lt;UL&gt;
&lt;LI&gt;&lt;A href="http://docs.hortonworks.com/HDPDocuments/Ambari-2.1.2.0/bk_Ambari_Security_Guide/content/_synchronizing_ldap_users_and_groups.html"&gt;Synchronize LDAP Users &amp;amp; Groups&lt;/A&gt; (see console output below)...&lt;/LI&gt;&lt;/UL&gt;&lt;PRE&gt;[root@sandbox ~]# ambari-server sync-ldap --all
Using python  /usr/bin/python2.6
Syncing with LDAP...
Enter Ambari Admin login: admin
Enter Ambari Admin password: admin-password
Syncing all...

Completed LDAP Sync.
Summary:
  memberships:
    removed = 0
    created = 2
  users:
    updated = 0
    removed = 1
    created = 3
  groups:
    updated = 2
    removed = 0
    created = 0

Ambari Server 'sync-ldap' completed successfully.
&lt;/PRE&gt;</description>
      <pubDate>Tue, 10 Nov 2015 10:56:22 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Has-anyone-integrated-for-demo-purposes-only-the-Knox-LDAP/m-p/96613#M10032</guid>
      <dc:creator>amiller</dc:creator>
      <dc:date>2015-11-10T10:56:22Z</dc:date>
    </item>
    <item>
      <title>Re: Has anyone integrated (for demo purposes only) the Knox LDAP demo server with the Ambari 2.1.1 Server? I am not sure that it can be done, but need the instructions if it can be done. I only need to be able to log in to Ambari using the LDAP users.</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Has-anyone-integrated-for-demo-purposes-only-the-Knox-LDAP/m-p/96614#M10033</link>
      <description>&lt;P&gt;Ambari attempts to determine whether the demo LDAP server supports paged results, which it does not, so it responds with UNAVAILABLE_CRITICAL_EXTENSION.&lt;/P&gt;&lt;P&gt;The demo LDAP server in &lt;A href="https://github.com/apache/knox/blob/v0.6.0/pom.xml"&gt;Knox 0.6.0&lt;/A&gt; (HDP 2.3.0) is based on ApacheDS 2.0.0-M15. Support for paged results was added in version 2.0.0-M13 (&lt;A href="https://issues.apache.org/jira/browse/DIRSERVER-434"&gt;DIRSERVER-434&lt;/A&gt;), so I'm not sure why this wouldn't work. It's unlikely to be solved by configuration though.&lt;/P&gt;</description>
      <pubDate>Tue, 10 Nov 2015 10:56:23 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Has-anyone-integrated-for-demo-purposes-only-the-Knox-LDAP/m-p/96614#M10033</guid>
      <dc:creator>amiller</dc:creator>
      <dc:date>2015-11-10T10:56:23Z</dc:date>
    </item>
    <item>
      <title>Re: Has anyone integrated (for demo purposes only) the Knox LDAP demo server with the Ambari 2.1.1 Server? I am not sure that it can be done, but need the instructions if it can be done. I only need to be able to log in to Ambari using the LDAP users.</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Has-anyone-integrated-for-demo-purposes-only-the-Knox-LDAP/m-p/96615#M10034</link>
      <description>&lt;P&gt;I was mistakenly using the HDP 2.3.0 Sandbox, which uses Ambari 2.1.0. Your advice worked perfectly in the latest version. Thanks!&lt;/P&gt;</description>
      <pubDate>Tue, 10 Nov 2015 10:58:25 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Has-anyone-integrated-for-demo-purposes-only-the-Knox-LDAP/m-p/96615#M10034</guid>
      <dc:creator>amiller</dc:creator>
      <dc:date>2015-11-10T10:58:25Z</dc:date>
    </item>
    <item>
      <title>Re: Has anyone integrated (for demo purposes only) the Knox LDAP demo server with the Ambari 2.1.1 Server? I am not sure that it can be done, but need the instructions if it can be done. I only need to be able to log in to Ambari using the LDAP users.</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Has-anyone-integrated-for-demo-purposes-only-the-Knox-LDAP/m-p/96616#M10035</link>
      <description>&lt;P&gt;&lt;A rel="user" href="https://community.cloudera.com/users/63/amiller.html" nodeid="63"&gt;@Alex Miller&lt;/A&gt; I am having trouble with syncing ldap, getting 403 bad credentials but I am able to login using same credentials to the dashboard. Note: Now admin password is changed to ldap's admin password. Exact error below:
"Syncing all.ERROR: Exiting with exit code 1.
REASON: Sync event creation failed. Error details: HTTP Error 403: You do not have permissions to access this resource."&lt;/P&gt;</description>
      <pubDate>Wed, 22 Jun 2016 16:07:52 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Has-anyone-integrated-for-demo-purposes-only-the-Knox-LDAP/m-p/96616#M10035</guid>
      <dc:creator>WhiteHa</dc:creator>
      <dc:date>2016-06-22T16:07:52Z</dc:date>
    </item>
    <item>
      <title>Re: Has anyone integrated (for demo purposes only) the Knox LDAP demo server with the Ambari 2.1.1 Server? I am not sure that it can be done, but need the instructions if it can be done. I only need to be able to log in to Ambari using the LDAP users.</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Has-anyone-integrated-for-demo-purposes-only-the-Knox-LDAP/m-p/96617#M10036</link>
      <description>&lt;P&gt;Hi Pandey,&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Have you identified the root cause for this issue? Do you remember?&lt;/P&gt;&lt;P&gt;The error is same for Ambari 2.6.1.5.&lt;/P&gt;</description>
      <pubDate>Sun, 04 Aug 2019 11:28:54 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Has-anyone-integrated-for-demo-purposes-only-the-Knox-LDAP/m-p/96617#M10036</guid>
      <dc:creator>lakshmi_jammu</dc:creator>
      <dc:date>2019-08-04T11:28:54Z</dc:date>
    </item>
  </channel>
</rss>

