<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>question Re: Ambari for LDAP or Active Directory Authentication in Archives of Support Questions (Read Only)</title>
    <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Ambari-for-LDAP-or-Active-Directory-Authentication/m-p/137606#M35235</link>
    <description>&lt;P&gt;&lt;A rel="user" href="https://community.cloudera.com/users/2755/kpandey.html" nodeid="2755"&gt;@Krishna Pandey&lt;/A&gt; is mostly correct, however:&lt;/P&gt;&lt;P&gt;For #1, though Ambari does store the &lt;STRONG&gt;&lt;EM&gt;manager&lt;/EM&gt;&lt;/STRONG&gt; DN and password, it &lt;STRONG&gt;does not store the synced users passwords&lt;/STRONG&gt;. Because of this, Ambari relies on the LDAP server to validate authentication for these users.&lt;/P&gt;&lt;P&gt;For #2 and #3, Ambari has no ability to manage passwords in the LDAP server. Therefore if a user wants to change their password or is required to change their password, they need to use some other facility. With this, if the user must change their password before authenticating, then authenticate will fail until the password is changed using some other facility. I assume that if the user is no longer required to change their password, authentication should work again. &lt;/P&gt;</description>
    <pubDate>Wed, 20 Jul 2016 20:10:15 GMT</pubDate>
    <dc:creator>rlevas</dc:creator>
    <dc:date>2016-07-20T20:10:15Z</dc:date>
    <item>
      <title>Ambari for LDAP or Active Directory Authentication</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Ambari-for-LDAP-or-Active-Directory-Authentication/m-p/137604#M35233</link>
      <description>&lt;P&gt;Few questions on  Ambari for LDAP or Active Directory Authentication:&lt;/P&gt;&lt;P&gt;1. When users are synced into Ambari , are the passwords also stored in the Ambari's local DB along with the usernames &lt;/P&gt;&lt;P&gt;2. When a user logs into Ambari , is there a way for the user to change his password ?
 &lt;/P&gt;&lt;P&gt;3. When we create a user in AD , we set the property that "user must change password at next logon" , however after the ldpa-sync, the user cannot login into ambari . what could be the problem ? Also, when we go back to AD and untick this option (" user must change password at next logon") , the user is now able to login into ambari ? &lt;/P&gt;&lt;P&gt;Any pointers would help&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Wed, 20 Jul 2016 16:31:23 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Ambari-for-LDAP-or-Active-Directory-Authentication/m-p/137604#M35233</guid>
      <dc:creator>hyadav</dc:creator>
      <dc:date>2016-07-20T16:31:23Z</dc:date>
    </item>
    <item>
      <title>Re: Ambari for LDAP or Active Directory Authentication</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Ambari-for-LDAP-or-Active-Directory-Authentication/m-p/137605#M35234</link>
      <description>&lt;P&gt;1. Yes, it stores the Manager DN and Manager Password. When you do "ambari-server sync-ldap --all" to sync users and groups, it will ask for just Ambari Admin credentials.&lt;/P&gt;&lt;P&gt;2. I see "cannot change password" message when I hover over Password section for ldap user in "Manage Ambari" section. I think User password should be changed via interface provided to them which will reflect in AD. Later we can sync LDAP from Ambari Server.&lt;/P&gt;&lt;P&gt;3. When in AD we check the option to change password at first logon, it will prompt user to change the password at first login and then proceed. Ambari does not facilitate/provide such interface to change password when prompted and hence it will fail as per my understanding.&lt;/P&gt;&lt;P&gt;Refer screenshot: &lt;A href="https://community.cloudera.com/legacyfs/online/attachments/5891-screen-shot-2016-07-20-at-32931-pm.png"&gt;screen-shot-2016-07-20-at-32931-pm.png&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 20 Jul 2016 16:38:48 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Ambari-for-LDAP-or-Active-Directory-Authentication/m-p/137605#M35234</guid>
      <dc:creator>WhiteHa</dc:creator>
      <dc:date>2016-07-20T16:38:48Z</dc:date>
    </item>
    <item>
      <title>Re: Ambari for LDAP or Active Directory Authentication</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Ambari-for-LDAP-or-Active-Directory-Authentication/m-p/137606#M35235</link>
      <description>&lt;P&gt;&lt;A rel="user" href="https://community.cloudera.com/users/2755/kpandey.html" nodeid="2755"&gt;@Krishna Pandey&lt;/A&gt; is mostly correct, however:&lt;/P&gt;&lt;P&gt;For #1, though Ambari does store the &lt;STRONG&gt;&lt;EM&gt;manager&lt;/EM&gt;&lt;/STRONG&gt; DN and password, it &lt;STRONG&gt;does not store the synced users passwords&lt;/STRONG&gt;. Because of this, Ambari relies on the LDAP server to validate authentication for these users.&lt;/P&gt;&lt;P&gt;For #2 and #3, Ambari has no ability to manage passwords in the LDAP server. Therefore if a user wants to change their password or is required to change their password, they need to use some other facility. With this, if the user must change their password before authenticating, then authenticate will fail until the password is changed using some other facility. I assume that if the user is no longer required to change their password, authentication should work again. &lt;/P&gt;</description>
      <pubDate>Wed, 20 Jul 2016 20:10:15 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Ambari-for-LDAP-or-Active-Directory-Authentication/m-p/137606#M35235</guid>
      <dc:creator>rlevas</dc:creator>
      <dc:date>2016-07-20T20:10:15Z</dc:date>
    </item>
  </channel>
</rss>

