<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>question Re: Problem with refresh HDFS User-Group mappings with AD on Kerberized cluster in Archives of Support Questions (Read Only)</title>
    <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Problem-with-refresh-HDFS-User-Group-mappings-with-AD-on/m-p/162625#M45183</link>
    <description>&lt;P&gt;It seems that HDFS is not synching your groups.  Try restarting the cluster to see if that helps.&lt;/P&gt;</description>
    <pubDate>Tue, 27 Dec 2016 00:21:03 GMT</pubDate>
    <dc:creator>dvillarreal</dc:creator>
    <dc:date>2016-12-27T00:21:03Z</dc:date>
    <item>
      <title>Problem with refresh HDFS User-Group mappings with AD on Kerberized cluster</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Problem-with-refresh-HDFS-User-Group-mappings-with-AD-on/m-p/162624#M45182</link>
      <description>&lt;P&gt;Following the security lab and reach the following step&lt;/P&gt;&lt;P&gt;&lt;A href="https://github.com/HortonworksUniversity/Security_Labs#refresh-hdfs-user-group-mappings" target="_blank"&gt;https://github.com/HortonworksUniversity/Security_Labs#refresh-hdfs-user-group-mappings&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Run into problem refresh the user-group mapping from AD&lt;/P&gt;&lt;PRE&gt;[root@qwang-hdp0 ~]# sudo sudo -u hdfs kinit -kt /etc/security/keytabs/hdfs.headless.keytab hdfs-qi
[root@qwang-hdp0 ~]# sudo sudo -u hdfs hdfs dfsadmin -refreshUserToGroupsMappings
Refresh user to groups mapping successful
&lt;/PRE&gt;&lt;P&gt;Then kinit to hr1 user and check the user-group mapping, it doesn't seems to sync correctly for hdfs, hdfs group command not returning the rigth group, where yarn rmadmin is fine.&lt;/P&gt;&lt;PRE&gt;[root@qwang-hdp0 ~]# kinit hr1
Password for hr1@EXAMPLE.COM:
[root@qwang-hdp0 ~]# hdfs groups
hr1@EXAMPLE.COM :
[root@qwang-hdp0 ~]# yarn rmadmin -getGroups hr1
16/11/03 01:30:36 INFO client.RMProxy: Connecting to ResourceManager at hdp1.example.com/172.xx.xxx.xxx:8141
hr1 : domain_users hadoop-users hr
[root@qwang-hdp0 ~]# id hr1
uid=1960401170(hr1) gid=1960400513(domain_users) groups=1960400513(domain_users),1960401154(hr),1960401151(hadoop-users)
&lt;/PRE&gt;&lt;P&gt;The hdfs group is not matching to the AD settings. and ldapsearch confirm the AD setting is there&lt;/P&gt;&lt;PRE&gt;[root@qwang-hdp0 ~]# ldapsearch -h ad01.field.hortonworks.com -p 389 -D "binduser@example.com" -W -b "DC=field,DC=my_org,DC=com" "(sAMAccountName=hr1)"
Enter LDAP Password:
...
memberOf: CN=hr,OU=CorpUsers,DC=field,DC=my_org,DC=com
memberOf: CN=hadoop-users,OU=CorpUsers,DC=field,DC=&lt;/PRE&gt;&lt;P&gt;my_org,DC=com&lt;/P&gt;...
&lt;P&gt;Could you suggest what is going wrong and what to do to trouble shoot/correct the issue&lt;/P&gt;</description>
      <pubDate>Thu, 03 Nov 2016 11:09:08 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Problem-with-refresh-HDFS-User-Group-mappings-with-AD-on/m-p/162624#M45182</guid>
      <dc:creator>qiwang</dc:creator>
      <dc:date>2016-11-03T11:09:08Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with refresh HDFS User-Group mappings with AD on Kerberized cluster</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Problem-with-refresh-HDFS-User-Group-mappings-with-AD-on/m-p/162625#M45183</link>
      <description>&lt;P&gt;It seems that HDFS is not synching your groups.  Try restarting the cluster to see if that helps.&lt;/P&gt;</description>
      <pubDate>Tue, 27 Dec 2016 00:21:03 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Problem-with-refresh-HDFS-User-Group-mappings-with-AD-on/m-p/162625#M45183</guid>
      <dc:creator>dvillarreal</dc:creator>
      <dc:date>2016-12-27T00:21:03Z</dc:date>
    </item>
  </channel>
</rss>

