<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>question Re: Ranger UI - LDAP integration for internal and external users in Archives of Support Questions (Read Only)</title>
    <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Ranger-UI-LDAP-integration-for-internal-and-external-users/m-p/130843#M34774</link>
    <description>&lt;P&gt;Hello &lt;A rel="user" href="https://community.cloudera.com/users/11856/sarahmaadawy.html" nodeid="11856"&gt;@Sarah Maadawy&lt;/A&gt;,&lt;/P&gt;&lt;P&gt;The internal users are the Linux system users which Ranger usersync syncs from the local Linux OS. They are not always allowed access to the Ranger UI portal.&lt;/P&gt;&lt;P&gt;The external users (can be from AD / LDAP) are synced by Ranger usersync to be used for policy creation.&lt;/P&gt;&lt;P&gt;Having cleared that, here are you answers:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Use LDAP to sync external users&lt;UL&gt;&lt;LI&gt;&lt;A href="http://docs.hortonworks.com/HDPDocuments/HDP2/HDP-2.3.4/bk_Ranger_Install_Guide/content/ranger_user_sync_ldap_ad.html" target="_blank"&gt;http://docs.hortonworks.com/HDPDocuments/HDP2/HDP-2.3.4/bk_Ranger_Install_Guide/content/ranger_user_sync_ldap_ad.html&lt;/A&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;UL&gt;&lt;LI&gt;User different LDAP settings to sync internal users &lt;UL&gt;&lt;LI&gt;There is nothing like LDAP to sync internal users, what you might be looking for is - using LDAP users to access the Ranger UI portal.&lt;/LI&gt;&lt;LI&gt;&lt;A href="http://docs.hortonworks.com/HDPDocuments/HDP2/HDP-2.3.4/bk_Ranger_Install_Guide/content/configure_ranger_authentication.html#configuring_ranger_ldap_authentication" target="_blank"&gt;http://docs.hortonworks.com/HDPDocuments/HDP2/HDP-2.3.4/bk_Ranger_Install_Guide/content/configure_ranger_authentication.html#configuring_ranger_ldap_authentication&lt;/A&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;So yes, there are two different LDAP sections which you can use to achieve both.&lt;/P&gt;&lt;P&gt;Hope this helps. Thanks.&lt;/P&gt;</description>
    <pubDate>Fri, 15 Jul 2016 08:24:03 GMT</pubDate>
    <dc:creator>VR46</dc:creator>
    <dc:date>2016-07-15T08:24:03Z</dc:date>
    <item>
      <title>Ranger UI - LDAP integration for internal and external users</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Ranger-UI-LDAP-integration-for-internal-and-external-users/m-p/130842#M34773</link>
      <description>&lt;P&gt;My understanding about the users list in Ranger UI portal is that:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;the internal users are the ones who are allowed to access the Ranger UI portal&lt;/LI&gt;&lt;LI&gt;the external users are only allowed to use Hadoop services according to their privilages but are not allowed to access the Ranger UI portal.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt; What I want to do is:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Use LDAP to sync external users&lt;/LI&gt;&lt;LI&gt;User different LDAP settings to sync internal users&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;It seems to me that the settings for both are read from the same place. Is that correct?&lt;/P&gt;</description>
      <pubDate>Fri, 15 Jul 2016 08:10:38 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Ranger-UI-LDAP-integration-for-internal-and-external-users/m-p/130842#M34773</guid>
      <dc:creator>sarah_maadawy</dc:creator>
      <dc:date>2016-07-15T08:10:38Z</dc:date>
    </item>
    <item>
      <title>Re: Ranger UI - LDAP integration for internal and external users</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Ranger-UI-LDAP-integration-for-internal-and-external-users/m-p/130843#M34774</link>
      <description>&lt;P&gt;Hello &lt;A rel="user" href="https://community.cloudera.com/users/11856/sarahmaadawy.html" nodeid="11856"&gt;@Sarah Maadawy&lt;/A&gt;,&lt;/P&gt;&lt;P&gt;The internal users are the Linux system users which Ranger usersync syncs from the local Linux OS. They are not always allowed access to the Ranger UI portal.&lt;/P&gt;&lt;P&gt;The external users (can be from AD / LDAP) are synced by Ranger usersync to be used for policy creation.&lt;/P&gt;&lt;P&gt;Having cleared that, here are you answers:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Use LDAP to sync external users&lt;UL&gt;&lt;LI&gt;&lt;A href="http://docs.hortonworks.com/HDPDocuments/HDP2/HDP-2.3.4/bk_Ranger_Install_Guide/content/ranger_user_sync_ldap_ad.html" target="_blank"&gt;http://docs.hortonworks.com/HDPDocuments/HDP2/HDP-2.3.4/bk_Ranger_Install_Guide/content/ranger_user_sync_ldap_ad.html&lt;/A&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;UL&gt;&lt;LI&gt;User different LDAP settings to sync internal users &lt;UL&gt;&lt;LI&gt;There is nothing like LDAP to sync internal users, what you might be looking for is - using LDAP users to access the Ranger UI portal.&lt;/LI&gt;&lt;LI&gt;&lt;A href="http://docs.hortonworks.com/HDPDocuments/HDP2/HDP-2.3.4/bk_Ranger_Install_Guide/content/configure_ranger_authentication.html#configuring_ranger_ldap_authentication" target="_blank"&gt;http://docs.hortonworks.com/HDPDocuments/HDP2/HDP-2.3.4/bk_Ranger_Install_Guide/content/configure_ranger_authentication.html#configuring_ranger_ldap_authentication&lt;/A&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;So yes, there are two different LDAP sections which you can use to achieve both.&lt;/P&gt;&lt;P&gt;Hope this helps. Thanks.&lt;/P&gt;</description>
      <pubDate>Fri, 15 Jul 2016 08:24:03 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Ranger-UI-LDAP-integration-for-internal-and-external-users/m-p/130843#M34774</guid>
      <dc:creator>VR46</dc:creator>
      <dc:date>2016-07-15T08:24:03Z</dc:date>
    </item>
    <item>
      <title>Re: Ranger UI - LDAP integration for internal and external users</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Ranger-UI-LDAP-integration-for-internal-and-external-users/m-p/130844#M34775</link>
      <description>&lt;P&gt;So, &lt;A href="https://community.hortonworks.com/users/740/vrathor.html"&gt;@Vipin Rathor&lt;/A&gt; does that mean that a user who is allowed to access Ranger UI is (always) an internal user while not every internal user is allowed to access the web UI?&lt;/P&gt;</description>
      <pubDate>Fri, 15 Jul 2016 08:53:37 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Ranger-UI-LDAP-integration-for-internal-and-external-users/m-p/130844#M34775</guid>
      <dc:creator>sarah_maadawy</dc:creator>
      <dc:date>2016-07-15T08:53:37Z</dc:date>
    </item>
    <item>
      <title>Re: Ranger UI - LDAP integration for internal and external users</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Ranger-UI-LDAP-integration-for-internal-and-external-users/m-p/130845#M34776</link>
      <description>&lt;P&gt;&lt;A rel="user" href="https://community.cloudera.com/users/11856/sarahmaadawy.html" nodeid="11856"&gt;@Sarah Maadawy&lt;/A&gt; No. That means that the external users can be allowed to access Ranger UI and not every internal user is allowed the access by default.  &lt;/P&gt;</description>
      <pubDate>Fri, 15 Jul 2016 10:20:31 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Ranger-UI-LDAP-integration-for-internal-and-external-users/m-p/130845#M34776</guid>
      <dc:creator>VR46</dc:creator>
      <dc:date>2016-07-15T10:20:31Z</dc:date>
    </item>
    <item>
      <title>Re: Ranger UI - LDAP integration for internal and external users</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Ranger-UI-LDAP-integration-for-internal-and-external-users/m-p/130846#M34777</link>
      <description>&lt;P&gt;So, if my target is to "set LDAP connection to allow users to use their LDAP credentials to login to Ranger UI":&lt;/P&gt;&lt;P&gt; If I used the link that you provided (&lt;A href="http://docs.hortonworks.com/HDPDocuments/HDP2/HDP-2.3.4/bk_Ranger_Install_Guide/content/configure_ranger_authentication.html#configuring_ranger_ldap_authentication"&gt;http://docs.hortonworks.com/HDPDocuments/HDP2/HDP-2.3.4/bk_Ranger_Install_Guide/content/configure_ranger_authentication.html#configuring_ranger_ldap_authentication&lt;/A&gt;). The users will still not be allowed to access the Ranger portal and there will still be an extra step to give them enough privileges to do that (i.e. add them to a group or something?)&lt;/P&gt;&lt;P&gt;And if both internal and external users can eventually have privileges to login to the portal, why would I use one link instead of the other?&lt;/P&gt;&lt;P&gt;Sorry, I am a newbie and trying to understand all this &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt; &lt;/P&gt;</description>
      <pubDate>Fri, 15 Jul 2016 11:08:57 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Ranger-UI-LDAP-integration-for-internal-and-external-users/m-p/130846#M34777</guid>
      <dc:creator>sarah_maadawy</dc:creator>
      <dc:date>2016-07-15T11:08:57Z</dc:date>
    </item>
  </channel>
</rss>

