<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>question Re: Cannot sync-ldap Ambari ​ in Archives of Support Questions (Read Only)</title>
    <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Cannot-sync-ldap-Ambari/m-p/160421#M29177</link>
    <description>&lt;A rel="user" href="https://community.cloudera.com/users/177/pminovic.html" nodeid="177"&gt;@Predrag Minovic&lt;/A&gt;&lt;P&gt;If the LDAP server is and Active Directory, you should make sure that the sync settings are similar to what is presented in this example:&lt;/P&gt;&lt;P style="margin-left: 20px;"&gt;&lt;A target="_blank" href="https://docs.hortonworks.com/HDPDocuments/Ambari-2.2.1.0/bk_Ambari_Security_Guide/content/_example_active_directory_configuration.html"&gt;https://docs.hortonworks.com/HDPDocuments/Ambari-2.2.1.0/bk_Ambari_Security_Guide/content/_example_active_directory_configuration.html&lt;/A&gt;
&lt;/P&gt;&lt;P&gt;I think the reason that you are not getting all of the users you expect is because in an Active Directory, the CN is typically auto-generated using the user's first and last name where the sAMAccountName is explicitly set as the userid (or username).  However, it is possible to manually set the CN to the username and thus this is probably why you are getting some and not all of the expected results.  &lt;/P&gt;</description>
    <pubDate>Wed, 25 May 2016 08:53:10 GMT</pubDate>
    <dc:creator>rlevas</dc:creator>
    <dc:date>2016-05-25T08:53:10Z</dc:date>
    <item>
      <title>Cannot sync-ldap Ambari ​</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Cannot-sync-ldap-Ambari/m-p/160419#M29175</link>
      <description>&lt;P&gt;"ambari-server sync-ldap --users file" against an LDAP server with more than 10,000 users fails saying one of the users in the file is not there. When I do ldapsearch from the command line without filter, that user is not returned, because I guess LDAP server returns max of 2000 entities. When I do ldapsearch with a filter I can find him. How can I tell Ambari to do such search using a filter? ldapsearch returns &lt;/P&gt;&lt;PRE&gt;distinguishedName: CN=user123456,OU=users,DC=example,DC=com&lt;/PRE&gt;&lt;P&gt;For ldapsearch I provide "(CN=user123456)" as my filter. In setup-ldap I do like below, but it doesn't work. Any ideas.&lt;/P&gt;&lt;PRE&gt;authentication.ldap.baseDn="OU=users,DC=example,DC=com"
authentication.ldap.usernameAttribute=CN
authentication.ldap.dnAttribute=distinguishedName
authentication.ldap.userObjectClass=organizationalPerson  ... have 4 classes listed: top,person,organizationlPerson, user; also tried user
authentication.ldap.referral=ignore   ... also tried follow&lt;/PRE&gt;&lt;P&gt;When I try to sync with one of the users returned using ldapserach without filter it works.&lt;/P&gt;</description>
      <pubDate>Sat, 21 May 2016 15:24:06 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Cannot-sync-ldap-Ambari/m-p/160419#M29175</guid>
      <dc:creator>pminovic</dc:creator>
      <dc:date>2016-05-21T15:24:06Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot sync-ldap Ambari ​</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Cannot-sync-ldap-Ambari/m-p/160420#M29176</link>
      <description>&lt;P&gt;Also tried to set authentication.ldap.pagination.enabled=false but to no avail. BTW, the LDAP is on AD.&lt;/P&gt;</description>
      <pubDate>Sat, 21 May 2016 18:20:02 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Cannot-sync-ldap-Ambari/m-p/160420#M29176</guid>
      <dc:creator>pminovic</dc:creator>
      <dc:date>2016-05-21T18:20:02Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot sync-ldap Ambari ​</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Cannot-sync-ldap-Ambari/m-p/160421#M29177</link>
      <description>&lt;A rel="user" href="https://community.cloudera.com/users/177/pminovic.html" nodeid="177"&gt;@Predrag Minovic&lt;/A&gt;&lt;P&gt;If the LDAP server is and Active Directory, you should make sure that the sync settings are similar to what is presented in this example:&lt;/P&gt;&lt;P style="margin-left: 20px;"&gt;&lt;A target="_blank" href="https://docs.hortonworks.com/HDPDocuments/Ambari-2.2.1.0/bk_Ambari_Security_Guide/content/_example_active_directory_configuration.html"&gt;https://docs.hortonworks.com/HDPDocuments/Ambari-2.2.1.0/bk_Ambari_Security_Guide/content/_example_active_directory_configuration.html&lt;/A&gt;
&lt;/P&gt;&lt;P&gt;I think the reason that you are not getting all of the users you expect is because in an Active Directory, the CN is typically auto-generated using the user's first and last name where the sAMAccountName is explicitly set as the userid (or username).  However, it is possible to manually set the CN to the username and thus this is probably why you are getting some and not all of the expected results.  &lt;/P&gt;</description>
      <pubDate>Wed, 25 May 2016 08:53:10 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Cannot-sync-ldap-Ambari/m-p/160421#M29177</guid>
      <dc:creator>rlevas</dc:creator>
      <dc:date>2016-05-25T08:53:10Z</dc:date>
    </item>
  </channel>
</rss>

