<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>question Re: Ranger, Knox integration with Multiple Forest AD's in Archives of Support Questions (Read Only)</title>
    <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Ranger-Knox-integration-with-Multiple-Forest-AD-s/m-p/168042#M49861</link>
    <description>&lt;P&gt;FYI.&lt;/P&gt;&lt;P&gt;"Multiple Forest" is supported - but not "Cross Forest" AD. &lt;/P&gt;&lt;P&gt;If you have "Cross Forest" AD, Ranger may able to get users from the right branch but not groups or vice versa&lt;/P&gt;</description>
    <pubDate>Thu, 09 Feb 2017 16:33:47 GMT</pubDate>
    <dc:creator>ahallam</dc:creator>
    <dc:date>2017-02-09T16:33:47Z</dc:date>
    <item>
      <title>Ranger, Knox integration with Multiple Forest AD's</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Ranger-Knox-integration-with-Multiple-Forest-AD-s/m-p/168040#M49859</link>
      <description>&lt;P&gt;I came to know that AD can be set up with multiple forests. Forest are AD lingo for a container at a level even higher then the Domain Controllers. This is not uncommon in large enterprise AD deployments ( see : &lt;A href="https://technet.microsoft.com/nl-nl/library/cc759073%28v=ws.10%29.aspx"&gt;MS_Technet&lt;/A&gt;)&lt;/P&gt;&lt;P&gt;So my question is:&lt;/P&gt;&lt;P&gt;-Do any of the HDP stack security features (Knox and Ranger) support this multi forest setup of AD (with the aim of synching or logging on to HDP from any one of those forests) and how?&lt;/P&gt;</description>
      <pubDate>Thu, 22 Dec 2016 17:38:12 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Ranger-Knox-integration-with-Multiple-Forest-AD-s/m-p/168040#M49859</guid>
      <dc:creator>jknulst</dc:creator>
      <dc:date>2016-12-22T17:38:12Z</dc:date>
    </item>
    <item>
      <title>Re: Ranger, Knox integration with Multiple Forest AD's</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Ranger-Knox-integration-with-Multiple-Forest-AD-s/m-p/168041#M49860</link>
      <description>&lt;P&gt;&lt;A href="https://community.hortonworks.com/questions/73601/ranger-knox-integration-with-multiple-forest-ads.html#"&gt;@Jasper&lt;/A&gt;&lt;/P&gt;&lt;P&gt;As
 you mention, a Forest is just a container for multiple domains.  If there is a trust relationship in place, then you should be 
able to authenticate from Domain1 and access resources in Domain2.  You can also authenticate against Domain1 and query Domain2.&lt;/P&gt;&lt;P&gt;I 
believe the HDP stack security components can authenticate to a domain 
within a Forest without any issues as the Forest should be transparent 
to HDP. &lt;/P&gt;&lt;P&gt;Having
 said that, I believe you can only specify a single domain in the 
configuration options for the HDP components.  While you can query 
multiple domains using tools like "ldapsearch", I don't think you can 
currently do so using HDP.&lt;/P&gt;</description>
      <pubDate>Fri, 23 Dec 2016 03:06:20 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Ranger-Knox-integration-with-Multiple-Forest-AD-s/m-p/168041#M49860</guid>
      <dc:creator>myoung</dc:creator>
      <dc:date>2016-12-23T03:06:20Z</dc:date>
    </item>
    <item>
      <title>Re: Ranger, Knox integration with Multiple Forest AD's</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Ranger-Knox-integration-with-Multiple-Forest-AD-s/m-p/168042#M49861</link>
      <description>&lt;P&gt;FYI.&lt;/P&gt;&lt;P&gt;"Multiple Forest" is supported - but not "Cross Forest" AD. &lt;/P&gt;&lt;P&gt;If you have "Cross Forest" AD, Ranger may able to get users from the right branch but not groups or vice versa&lt;/P&gt;</description>
      <pubDate>Thu, 09 Feb 2017 16:33:47 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Ranger-Knox-integration-with-Multiple-Forest-AD-s/m-p/168042#M49861</guid>
      <dc:creator>ahallam</dc:creator>
      <dc:date>2017-02-09T16:33:47Z</dc:date>
    </item>
  </channel>
</rss>

