<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>question Re: Setting up LDAP/AD in Knox in Archives of Support Questions (Read Only)</title>
    <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Setting-up-LDAP-AD-in-Knox/m-p/142076#M27994</link>
    <description>&lt;P&gt;Thank you very much &lt;A rel="user" href="https://community.cloudera.com/users/63/amiller.html" nodeid="63"&gt;@Alex Miller&lt;/A&gt; for your quick response. According to doc that you linked and log I found out that I had misconfigured &lt;EM&gt;userDnTemplate&lt;/EM&gt;.&lt;/P&gt;&lt;P&gt;I have another problem. In my AD/LDAP I am using &lt;EM&gt;sAMAccountName&lt;/EM&gt; to identify user, so I need to type at the begging of &lt;EM&gt;userDnTemplate&lt;/EM&gt; something like: &lt;EM&gt;sAMAccountName={0},ou=&lt;/EM&gt;... so on, but it does not recognize users. I cant use &lt;EM&gt;cn={0}&lt;/EM&gt; because as a &lt;EM&gt;cn&lt;/EM&gt; I use two separate words - so I will not work. I dont use &lt;EM&gt;uid&lt;/EM&gt;, and I am not AD admin to add or edit anything.&lt;/P&gt;</description>
    <pubDate>Thu, 12 May 2016 01:57:45 GMT</pubDate>
    <dc:creator>frank93</dc:creator>
    <dc:date>2016-05-12T01:57:45Z</dc:date>
    <item>
      <title>Setting up LDAP/AD in Knox</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Setting-up-LDAP-AD-in-Knox/m-p/142074#M27992</link>
      <description>&lt;P&gt;
	Hi,&lt;/P&gt;&lt;P&gt;
	I have a problem with configuring LDAP/AD with Knox. The DEMO LDAP works great for both: sandbox and my own cluster. I am configuring LDAP connection using this document: &lt;A href="https://docs.hortonworks.com/HDPDocuments/HDP2/HDP-2.3.2/bk_Knox_Gateway_Admin_Guide/content/setting_up_ldap_authentication.html"&gt;Setting Up LDAP Authentication&lt;/A&gt;. I configured main.ldapRealm.userDnTemplate and main.ldapRealm.contextFactory.url. I tried both classes in main.ldapRealm (KnoxLdapRealm and Jndi...) I am using Ambari to make changes. The versions I use is: sandbox - 2.4.0 and my cluster 2.3.2. When I configure my LDAP - Knox keeps saying that I am unauthorized (401). The credentials are correct because I can use them to log in beeline which is also configured with LDAP + AD.&lt;/P&gt;&lt;P&gt;Do I need to change Advanced users-ldif section in Ambari as well?&lt;/P&gt;&lt;P&gt;Thank you in advance.&lt;/P&gt;</description>
      <pubDate>Wed, 11 May 2016 21:28:25 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Setting-up-LDAP-AD-in-Knox/m-p/142074#M27992</guid>
      <dc:creator>frank93</dc:creator>
      <dc:date>2016-05-11T21:28:25Z</dc:date>
    </item>
    <item>
      <title>Re: Setting up LDAP/AD in Knox</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Setting-up-LDAP-AD-in-Knox/m-p/142075#M27993</link>
      <description>&lt;P&gt;If your users belong to different branches of the LDAP directory you'll need to use &lt;A href="http://knox.apache.org/books/knox-0-6-0/user-guide.html#Advanced+LDAP+Authentication"&gt;Advanced LDAP Authentication&lt;/A&gt; in the Knox topology. Review the linked doc to understand the limitations of userDnTemplate, and refer to the "Example provider config" section to understand the additional properties available.&lt;/P&gt;&lt;P&gt;There should be log messages in gateway.log corresponding to the 401. Those might provide more insight into the reason for the error, so please provide them if possible.&lt;/P&gt;</description>
      <pubDate>Wed, 11 May 2016 22:10:18 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Setting-up-LDAP-AD-in-Knox/m-p/142075#M27993</guid>
      <dc:creator>amiller</dc:creator>
      <dc:date>2016-05-11T22:10:18Z</dc:date>
    </item>
    <item>
      <title>Re: Setting up LDAP/AD in Knox</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Setting-up-LDAP-AD-in-Knox/m-p/142076#M27994</link>
      <description>&lt;P&gt;Thank you very much &lt;A rel="user" href="https://community.cloudera.com/users/63/amiller.html" nodeid="63"&gt;@Alex Miller&lt;/A&gt; for your quick response. According to doc that you linked and log I found out that I had misconfigured &lt;EM&gt;userDnTemplate&lt;/EM&gt;.&lt;/P&gt;&lt;P&gt;I have another problem. In my AD/LDAP I am using &lt;EM&gt;sAMAccountName&lt;/EM&gt; to identify user, so I need to type at the begging of &lt;EM&gt;userDnTemplate&lt;/EM&gt; something like: &lt;EM&gt;sAMAccountName={0},ou=&lt;/EM&gt;... so on, but it does not recognize users. I cant use &lt;EM&gt;cn={0}&lt;/EM&gt; because as a &lt;EM&gt;cn&lt;/EM&gt; I use two separate words - so I will not work. I dont use &lt;EM&gt;uid&lt;/EM&gt;, and I am not AD admin to add or edit anything.&lt;/P&gt;</description>
      <pubDate>Thu, 12 May 2016 01:57:45 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Setting-up-LDAP-AD-in-Knox/m-p/142076#M27994</guid>
      <dc:creator>frank93</dc:creator>
      <dc:date>2016-05-12T01:57:45Z</dc:date>
    </item>
    <item>
      <title>Re: Setting up LDAP/AD in Knox</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Setting-up-LDAP-AD-in-Knox/m-p/142077#M27995</link>
      <description>&lt;P&gt;I found the solution. If anyone else is facing the same problem, review this &lt;A href="https://community.hortonworks.com/questions/1783/does-knox-support-active-directory-searches-using.html"&gt;link&lt;/A&gt; and use &lt;A rel="user" href="https://community.cloudera.com/users/191/bsaini.html" nodeid="191"&gt;@bsaini&lt;/A&gt; topology. Thanks!&lt;/P&gt;</description>
      <pubDate>Thu, 12 May 2016 02:24:46 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Setting-up-LDAP-AD-in-Knox/m-p/142077#M27995</guid>
      <dc:creator>frank93</dc:creator>
      <dc:date>2016-05-12T02:24:46Z</dc:date>
    </item>
  </channel>
</rss>

