<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>question Re: Rangersync with LDAP : user lookup criteria in Archives of Support Questions (Read Only)</title>
    <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Rangersync-with-LDAP-user-lookup-criteria/m-p/117534#M42913</link>
    <description>&lt;P&gt;&lt;A rel="user" href="https://community.cloudera.com/users/13562/houssammanik.html" nodeid="13562"&gt;@Houssam Manik&lt;/A&gt; this is configurable within the Ranger User Sync configuration. In particular, the User Configs tab contains the User Group Name Attribute setting (which defaults to memberof,ismemberof) and the Group Configs tab contains the Group Filter settings (which defaults to uniqueMember={0}, where the substituted parameter is the full distinguished name of the user).&lt;/P&gt;&lt;P&gt;Please see &lt;A href="https://docs.hortonworks.com/HDPDocuments/HDP2/HDP-2.3.4/bk_Ranger_Install_Guide/content/ranger_user_sync_ldap_ad.html"&gt;this doc&lt;/A&gt;. The LDAP Connection Check Tool is helpful when configuring LDAP properties for Ranger User Sync.&lt;/P&gt;</description>
    <pubDate>Thu, 06 Oct 2016 22:43:44 GMT</pubDate>
    <dc:creator>slachterman</dc:creator>
    <dc:date>2016-10-06T22:43:44Z</dc:date>
    <item>
      <title>Rangersync with LDAP : user lookup criteria</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Rangersync-with-LDAP-user-lookup-criteria/m-p/117533#M42912</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;What criteria Ranger usses to look up for user in LDAP? &lt;/P&gt;&lt;P&gt;Which attribute (memberof, uniquemember) ?&lt;/P&gt;</description>
      <pubDate>Thu, 06 Oct 2016 18:04:59 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Rangersync-with-LDAP-user-lookup-criteria/m-p/117533#M42912</guid>
      <dc:creator>houssam_manik</dc:creator>
      <dc:date>2016-10-06T18:04:59Z</dc:date>
    </item>
    <item>
      <title>Re: Rangersync with LDAP : user lookup criteria</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Rangersync-with-LDAP-user-lookup-criteria/m-p/117534#M42913</link>
      <description>&lt;P&gt;&lt;A rel="user" href="https://community.cloudera.com/users/13562/houssammanik.html" nodeid="13562"&gt;@Houssam Manik&lt;/A&gt; this is configurable within the Ranger User Sync configuration. In particular, the User Configs tab contains the User Group Name Attribute setting (which defaults to memberof,ismemberof) and the Group Configs tab contains the Group Filter settings (which defaults to uniqueMember={0}, where the substituted parameter is the full distinguished name of the user).&lt;/P&gt;&lt;P&gt;Please see &lt;A href="https://docs.hortonworks.com/HDPDocuments/HDP2/HDP-2.3.4/bk_Ranger_Install_Guide/content/ranger_user_sync_ldap_ad.html"&gt;this doc&lt;/A&gt;. The LDAP Connection Check Tool is helpful when configuring LDAP properties for Ranger User Sync.&lt;/P&gt;</description>
      <pubDate>Thu, 06 Oct 2016 22:43:44 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Rangersync-with-LDAP-user-lookup-criteria/m-p/117534#M42913</guid>
      <dc:creator>slachterman</dc:creator>
      <dc:date>2016-10-06T22:43:44Z</dc:date>
    </item>
    <item>
      <title>Re: Rangersync with LDAP : user lookup criteria</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Rangersync-with-LDAP-user-lookup-criteria/m-p/117535#M42914</link>
      <description>&lt;P&gt;Thanks &lt;A rel="user" href="https://community.cloudera.com/users/11295/slachterman.html" nodeid="11295"&gt;@slachterman&lt;/A&gt; &lt;/P&gt;&lt;P&gt;So by default we use memberof,ismemberof to get the user group. Can we set it to other value such as uniquemember ?&lt;/P&gt;</description>
      <pubDate>Fri, 07 Oct 2016 03:37:18 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Rangersync-with-LDAP-user-lookup-criteria/m-p/117535#M42914</guid>
      <dc:creator>houssam_manik</dc:creator>
      <dc:date>2016-10-07T03:37:18Z</dc:date>
    </item>
    <item>
      <title>Re: Rangersync with LDAP : user lookup criteria</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Rangersync-with-LDAP-user-lookup-criteria/m-p/117536#M42915</link>
      <description>&lt;P&gt;Yes, &lt;A rel="user" href="https://community.cloudera.com/users/13562/houssammanik.html" nodeid="13562"&gt;@Houssam Manik&lt;/A&gt; the values are configurable in the Ambari UI. Please accept this answer if it helps to address this question for you.&lt;/P&gt;</description>
      <pubDate>Fri, 07 Oct 2016 03:52:43 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Rangersync-with-LDAP-user-lookup-criteria/m-p/117536#M42915</guid>
      <dc:creator>slachterman</dc:creator>
      <dc:date>2016-10-07T03:52:43Z</dc:date>
    </item>
    <item>
      <title>Re: Rangersync with LDAP : user lookup criteria</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Rangersync-with-LDAP-user-lookup-criteria/m-p/117537#M42916</link>
      <description>&lt;P&gt;&lt;A rel="user" href="https://community.cloudera.com/users/13562/houssammanik.html" nodeid="13562"&gt;@Houssam Manik&lt;/A&gt;&lt;/P&gt;&lt;P&gt;As &lt;A rel="user" href="https://community.cloudera.com/users/11295/slachterman.html" nodeid="11295"&gt;@slachterman&lt;/A&gt; says, the LDAP attributes that map to a user's username, group membership, etc., are configurable. The reason for this is because an administrator can modify the directory schema, or the schema may have evolved over time. For Active Directory 2012, the default values you'll want to user are:&lt;/P&gt;&lt;PRE&gt;User Object Type: person
Username Attribute: sAMAccountName
Use Group Name Attribute: sAMAccountName
Group Member Attribute: member
Group Name Attribute: sAMAccountName
Group Object Class: group&lt;/PRE&gt;&lt;P&gt;For FreeIPA, these change to:&lt;/P&gt;&lt;PRE&gt;User Object Class: posixaccount
Username Attribute: uid
Use Group Name Attribute: memberOf
Group Member Attribute: member
Group Name Attribute: cn
Group Object Class: posixgroup&lt;/PRE&gt;&lt;P&gt;The base of the directory where Ranger starts to look for users and groups are specified by the User Search Base and Group Search Base parameters. For AD, you'd want to use something like:&lt;/P&gt;&lt;PRE&gt;User Search Base: CN=Users,DC=example,DC=com
Group Search Gase: CN=Groups,DC=example,DC=com&lt;/PRE&gt;&lt;P&gt;And for FreeIPA, something similar to:&lt;/P&gt;&lt;PRE&gt;User Search Base: cn=users,cn=accounts,dc=example,dc=com
Group Search Gase: cn=groups,cn=accounts,dc=example,dc=com&lt;/PRE&gt;&lt;P&gt;You can also specify search filters with syntax similar to:&lt;/P&gt;&lt;PRE&gt;(|(memberOf=hadoop-admins)(memberOf=hadoop-users))&lt;/PRE&gt;&lt;P&gt;Here is a guide to &lt;A href="https://www.centos.org/docs/5/html/CDS/ag/8.0/Finding_Directory_Entries-LDAP_Search_Filters.html"&gt;LDAP Search Filters&lt;/A&gt; for more information.&lt;/P&gt;</description>
      <pubDate>Sat, 08 Oct 2016 10:17:28 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Rangersync-with-LDAP-user-lookup-criteria/m-p/117537#M42916</guid>
      <dc:creator>emaxwell</dc:creator>
      <dc:date>2016-10-08T10:17:28Z</dc:date>
    </item>
  </channel>
</rss>

