<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>question Re: How to restrict the groups seen in Ranger? in Archives of Support Questions (Read Only)</title>
    <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/How-to-restrict-the-groups-seen-in-Ranger/m-p/165846#M29543</link>
    <description>&lt;P&gt;@Pradeep I didn't find the delete option but found setting visibility to  "hidden" option. Not sure if you are talking about.&lt;/P&gt;</description>
    <pubDate>Wed, 25 May 2016 16:20:37 GMT</pubDate>
    <dc:creator>smartninja723</dc:creator>
    <dc:date>2016-05-25T16:20:37Z</dc:date>
    <item>
      <title>How to restrict the groups seen in Ranger?</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/How-to-restrict-the-groups-seen-in-Ranger/m-p/165842#M29539</link>
      <description>&lt;P&gt;Guys,&lt;/P&gt;&lt;P&gt;We have setup a Kerberized and A/D integrated HDP 2.3 Cluster. On the same cluster, after setting up Ranger, when I try to define policies for any components, I see all the groups available in A/D. For a larger organization, I suspect it would go in terms of hundreds.In such scenario, how can I restrict the number of groups appearing in the drop down when defining policies?&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Tue, 24 May 2016 23:23:01 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/How-to-restrict-the-groups-seen-in-Ranger/m-p/165842#M29539</guid>
      <dc:creator>smartninja723</dc:creator>
      <dc:date>2016-05-24T23:23:01Z</dc:date>
    </item>
    <item>
      <title>Re: How to restrict the groups seen in Ranger?</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/How-to-restrict-the-groups-seen-in-Ranger/m-p/165843#M29540</link>
      <description>&lt;P&gt;&lt;A rel="user" href="https://community.cloudera.com/users/3021/smartninja723.html" nodeid="3021"&gt;@Smart Solutions&lt;/A&gt; You can restrict groups to be synced using Group search filter. Refer below for detail.&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.hortonworks.com/HDPDocuments/HDP2/HDP-2.3.4/bk_Ranger_Install_Guide/content/ranger_user_sync_ldap_ad.html" target="_blank"&gt;https://docs.hortonworks.com/HDPDocuments/HDP2/HDP-2.3.4/bk_Ranger_Install_Guide/content/ranger_user_sync_ldap_ad.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;And other option would be to use Ranger FileSource.&lt;/P&gt;&lt;P&gt;&lt;A href="https://cwiki.apache.org/confluence/display/RANGER/File+Source+User+Group+Sync+process" target="_blank"&gt;https://cwiki.apache.org/confluence/display/RANGER/File+Source+User+Group+Sync+process&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 24 May 2016 23:31:03 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/How-to-restrict-the-groups-seen-in-Ranger/m-p/165843#M29540</guid>
      <dc:creator>pardeep_kumar</dc:creator>
      <dc:date>2016-05-24T23:31:03Z</dc:date>
    </item>
    <item>
      <title>Re: How to restrict the groups seen in Ranger?</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/How-to-restrict-the-groups-seen-in-Ranger/m-p/165844#M29541</link>
      <description>&lt;P&gt;Thanks I will have a look at them. What about the group which are already been imported. Can I delete for Ranger now?&lt;/P&gt;</description>
      <pubDate>Tue, 24 May 2016 23:33:52 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/How-to-restrict-the-groups-seen-in-Ranger/m-p/165844#M29541</guid>
      <dc:creator>smartninja723</dc:creator>
      <dc:date>2016-05-24T23:33:52Z</dc:date>
    </item>
    <item>
      <title>Re: How to restrict the groups seen in Ranger?</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/How-to-restrict-the-groups-seen-in-Ranger/m-p/165845#M29542</link>
      <description>&lt;P&gt;Yes, I think you can delete if you don't want those.&lt;/P&gt;</description>
      <pubDate>Tue, 24 May 2016 23:43:29 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/How-to-restrict-the-groups-seen-in-Ranger/m-p/165845#M29542</guid>
      <dc:creator>pardeep_kumar</dc:creator>
      <dc:date>2016-05-24T23:43:29Z</dc:date>
    </item>
    <item>
      <title>Re: How to restrict the groups seen in Ranger?</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/How-to-restrict-the-groups-seen-in-Ranger/m-p/165846#M29543</link>
      <description>&lt;P&gt;@Pradeep I didn't find the delete option but found setting visibility to  "hidden" option. Not sure if you are talking about.&lt;/P&gt;</description>
      <pubDate>Wed, 25 May 2016 16:20:37 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/How-to-restrict-the-groups-seen-in-Ranger/m-p/165846#M29543</guid>
      <dc:creator>smartninja723</dc:creator>
      <dc:date>2016-05-25T16:20:37Z</dc:date>
    </item>
    <item>
      <title>Re: How to restrict the groups seen in Ranger?</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/How-to-restrict-the-groups-seen-in-Ranger/m-p/165847#M29544</link>
      <description>&lt;P&gt;&lt;A rel="user" href="https://community.cloudera.com/users/3021/smartninja723.html" nodeid="3021"&gt;@Smart Solutions&lt;/A&gt; You can delete users and groups by doing this:&lt;/P&gt;&lt;P&gt;log into the ranger database, and delete
the following rows in order.&lt;/P&gt;&lt;PRE&gt;delete from x_group_users where
added_by_id in (1,2)&lt;/PRE&gt;&lt;PRE&gt;delete from x_user where added_by_id in
(1,2)&lt;/PRE&gt;&lt;PRE&gt;delete from x_group where added_by_id in
(1,2)&lt;/PRE&gt;&lt;P&gt;Then you can sync your users/groups again with your restrictions.&lt;/P&gt;</description>
      <pubDate>Wed, 25 May 2016 17:16:01 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/How-to-restrict-the-groups-seen-in-Ranger/m-p/165847#M29544</guid>
      <dc:creator>frank93</dc:creator>
      <dc:date>2016-05-25T17:16:01Z</dc:date>
    </item>
    <item>
      <title>Re: How to restrict the groups seen in Ranger?</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/How-to-restrict-the-groups-seen-in-Ranger/m-p/165848#M29545</link>
      <description>&lt;P&gt;&lt;A rel="user" href="https://community.cloudera.com/users/3241/frank93.html" nodeid="3241"&gt;@Edgar Daeds&lt;/A&gt; Thank you. I will try this.&lt;/P&gt;</description>
      <pubDate>Wed, 25 May 2016 17:36:12 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/How-to-restrict-the-groups-seen-in-Ranger/m-p/165848#M29545</guid>
      <dc:creator>smartninja723</dc:creator>
      <dc:date>2016-05-25T17:36:12Z</dc:date>
    </item>
    <item>
      <title>Re: How to restrict the groups seen in Ranger?</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/How-to-restrict-the-groups-seen-in-Ranger/m-p/165849#M29546</link>
      <description>&lt;P&gt;We came across a similar issue and our solution was to create a custom synchronization script which replaces the standard LDAP sync process.&lt;/P&gt;&lt;P&gt;We define a "super-group" whose members are all groups that are visible/relevant to Hadoop. This is helpful for several reasons:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;It limits the group selection in Ranger itself&lt;/LI&gt;&lt;LI&gt;It limits the users that are pulled into Ranger - only members of one of the relevant groups will be visible to Ranger&lt;/LI&gt;&lt;LI&gt;It limits the amount of data that needs to be transfered during synchronization. (We have around 50k users in our Active Directory.)&lt;/LI&gt;&lt;LI&gt;It gives us an efficient filter for LDAP queries. (We cannot filter by base DN because of AD policy.)&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;The synchronization process knows only the DN of the super-group - it fetches that one LDAP entry; from there it determines the members, which are the authorization groups, and then the members of each authorization group, which are th authorized users.&lt;/P&gt;</description>
      <pubDate>Tue, 07 Jun 2016 21:09:54 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/How-to-restrict-the-groups-seen-in-Ranger/m-p/165849#M29546</guid>
      <dc:creator>hellmar_becker</dc:creator>
      <dc:date>2016-06-07T21:09:54Z</dc:date>
    </item>
  </channel>
</rss>

