<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>question Re: Not able to login to Ranger as AD user, however, UserSync works fine. in Archives of Support Questions (Read Only)</title>
    <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Not-able-to-login-to-Ranger-as-AD-user-however-UserSync/m-p/186261#M58882</link>
    <description>&lt;P&gt;&lt;A rel="user" href="https://community.cloudera.com/users/16175/ekanthb.html" nodeid="16175"&gt;@Ekantheshwara  Basappa&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Ranger admin in HDP 2.5 has a new property for a truststore. So if using ldaps, you need to import the ldapserver cert to the ranger admin truststore , property name &lt;B&gt;ranger.truststore.file&lt;/B&gt;&lt;EM&gt;. Although no log is being showed for failed connection to ldapserver, setting ranger debug will show that ranger admin is not able to establish ssl connection to ldap server and there by not able to validate the user login. &lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;For ranger usersync has similar property &lt;/EM&gt;ranger.usersync.truststore.file which must already have ldap server cert in it as you have mentioned usersync is working fine. Use the same truststore file for ranger.truststore.file and see if it works. &lt;/P&gt;&lt;P&gt;Make sure that you set the UserSerachFilter as sAMAccountName={0} if using AD for ldap accounts. &lt;/P&gt;</description>
    <pubDate>Thu, 06 Apr 2017 11:29:42 GMT</pubDate>
    <dc:creator>rguruvannagari</dc:creator>
    <dc:date>2017-04-06T11:29:42Z</dc:date>
    <item>
      <title>Not able to login to Ranger as AD user, however, UserSync works fine.</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Not-able-to-login-to-Ranger-as-AD-user-however-UserSync/m-p/186259#M58880</link>
      <description>&lt;P&gt;I am using AD authentication for Ranger in HDP 2.5.0. The UserSync works fine and I am able to see the AD Users and Groups in Ranger.&lt;/P&gt;&lt;P&gt;
However, I am not able to login as an AD User. The UI says "The username or password you entered is incorrect". The log says:&lt;/P&gt;&lt;P&gt;
2017-03-31 12:20:22,008 [http-bio-6080-exec-4] INFO  org.apache.ranger.security.listener.SpringEventListener (SpringEventListener.java:87) - Login Unsuccessful:d786090 | Ip Address:10.60.179.195 | Bad Credentials&lt;/P&gt;&lt;P&gt;
I have tried the suggestions mentioned in the below URLs: &lt;/P&gt;&lt;P&gt;&lt;A href="https://community.hortonworks.com/questions/27382/can-not-login-to-ranger-using-ldap-or-ad-user-afte.html" target="_blank"&gt;https://community.hortonworks.com/questions/27382/can-not-login-to-ranger-using-ldap-or-ad-user-afte.html&lt;/A&gt;
and
&lt;A href="https://community.hortonworks.com/questions/21800/can-not-login-to-ranger-using-ldap-user-after-user.html" target="_blank"&gt;https://community.hortonworks.com/questions/21800/can-not-login-to-ranger-using-ldap-user-after-user.html&lt;/A&gt; &lt;/P&gt;&lt;P&gt;As mentioned in the above URLs, I have tried the below mentioned values for the "User Search Filter":&lt;/P&gt;&lt;P&gt;
(uid=*) &lt;/P&gt;&lt;P&gt;sAMAccountName={0} &lt;/P&gt;&lt;P&gt;space&lt;/P&gt;&lt;P&gt;
But that did not help. Can anyone help ? &lt;/P&gt;&lt;P&gt;Please note I am using "ldaps" i.e. my AD URL is of the format "ldaps://&amp;lt;AD Host&amp;gt;:636"&lt;/P&gt;&lt;P&gt;
Thanks, &lt;/P&gt;&lt;P&gt;Ekantheshwara&lt;/P&gt;</description>
      <pubDate>Tue, 04 Apr 2017 09:54:46 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Not-able-to-login-to-Ranger-as-AD-user-however-UserSync/m-p/186259#M58880</guid>
      <dc:creator>ekanthb</dc:creator>
      <dc:date>2017-04-04T09:54:46Z</dc:date>
    </item>
    <item>
      <title>Re: Not able to login to Ranger as AD user, however, UserSync works fine.</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Not-able-to-login-to-Ranger-as-AD-user-however-UserSync/m-p/186260#M58881</link>
      <description>&lt;P&gt;&lt;A href="https://community.hortonworks.com/users/16174/santoshjuly14.html"&gt;@santosh nukala&lt;/A&gt; @&lt;A href="https://community.hortonworks.com/users/11016/avijeetd.html"&gt;Avijeet Dash @&lt;/A&gt;&lt;A href="https://community.hortonworks.com/users/537/spolavarapu.html"&gt;spolavarapu&lt;/A&gt;&lt;A href="https://community.hortonworks.com/users/11016/avijeetd.html"&gt; &lt;/A&gt; @&lt;A href="https://community.hortonworks.com/users/2648/sshimpi.html"&gt;Sagar Shimpi&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Any ideas ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 06 Apr 2017 05:52:21 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Not-able-to-login-to-Ranger-as-AD-user-however-UserSync/m-p/186260#M58881</guid>
      <dc:creator>ekanthb</dc:creator>
      <dc:date>2017-04-06T05:52:21Z</dc:date>
    </item>
    <item>
      <title>Re: Not able to login to Ranger as AD user, however, UserSync works fine.</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Not-able-to-login-to-Ranger-as-AD-user-however-UserSync/m-p/186261#M58882</link>
      <description>&lt;P&gt;&lt;A rel="user" href="https://community.cloudera.com/users/16175/ekanthb.html" nodeid="16175"&gt;@Ekantheshwara  Basappa&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Ranger admin in HDP 2.5 has a new property for a truststore. So if using ldaps, you need to import the ldapserver cert to the ranger admin truststore , property name &lt;B&gt;ranger.truststore.file&lt;/B&gt;&lt;EM&gt;. Although no log is being showed for failed connection to ldapserver, setting ranger debug will show that ranger admin is not able to establish ssl connection to ldap server and there by not able to validate the user login. &lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;For ranger usersync has similar property &lt;/EM&gt;ranger.usersync.truststore.file which must already have ldap server cert in it as you have mentioned usersync is working fine. Use the same truststore file for ranger.truststore.file and see if it works. &lt;/P&gt;&lt;P&gt;Make sure that you set the UserSerachFilter as sAMAccountName={0} if using AD for ldap accounts. &lt;/P&gt;</description>
      <pubDate>Thu, 06 Apr 2017 11:29:42 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Not-able-to-login-to-Ranger-as-AD-user-however-UserSync/m-p/186261#M58882</guid>
      <dc:creator>rguruvannagari</dc:creator>
      <dc:date>2017-04-06T11:29:42Z</dc:date>
    </item>
    <item>
      <title>Re: Not able to login to Ranger as AD user, however, UserSync works fine.</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Not-able-to-login-to-Ranger-as-AD-user-however-UserSync/m-p/186262#M58883</link>
      <description>&lt;P&gt;@rguruvannagari &lt;/P&gt;&lt;P&gt;Thanks for responding to my question. &lt;/P&gt;&lt;P&gt;You are right. The usersync config was pointing to the right trust store file while ranger admin was pointing to a wrong one. I pointed ranger admin to the right one. And I set the User Search Filter with the value sAMAccountName={0}. However, I continue to get the same error. &lt;/P&gt;&lt;P&gt;Also, when I set the root Logger to debug mode(under Advanced admin-log4j), the generated logs are not very helpful. This is what I get: &lt;/P&gt;&lt;P&gt;2017-04-03 09:29:58,710 [http-bio-6080-exec-3] DEBUG org.springframework.security.web.authentication.AbstractAuthenticationProcessingFilter (AbstractAuthenticationProcessingFilter.java:346) - Authentication request failed: org.springframework.security.authentication.BadCredentialsException: Bad credentials
2017-04-03 09:29:58,710 [http-bio-6080-exec-3] DEBUG org.springframework.security.web.authentication.AbstractAuthenticationProcessingFilter (AbstractAuthenticationProcessingFilter.java:347) - Updated SecurityContextHolder to contain null Authentication
2017-04-03 09:29:58,711 [http-bio-6080-exec-3] DEBUG org.springframework.security.web.authentication.AbstractAuthenticationProcessingFilter (AbstractAuthenticationProcessingFilter.java:348) - Delegating to authentication failure handler org.apache.ranger.security.web.authentication.RangerAuthFailureHandler@22c447dd
2017-04-03 09:29:58,711 [http-bio-6080-exec-3] DEBUG apache.ranger.security.web.authentication.RangerAuthFailureHandler (RangerAuthFailureHandler.java:74) - commence() X-Requested-With=XMLHttpRequest
2017-04-03 09:29:58,714 [http-bio-6080-exec-3] DEBUG apache.ranger.security.web.authentication.RangerAuthFailureHandler (RangerAuthFailureHandler.java:114) - Sending login failed response : {"statusCode":401,"msgDesc":"The username or password you entered is incorrect.."}&lt;/P&gt;&lt;P&gt;
How do I get the detailed log so that I know what exactly is the problem ? &lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;
Ekanth &lt;/P&gt;</description>
      <pubDate>Thu, 06 Apr 2017 14:09:00 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Not-able-to-login-to-Ranger-as-AD-user-however-UserSync/m-p/186262#M58883</guid>
      <dc:creator>ekanthb</dc:creator>
      <dc:date>2017-04-06T14:09:00Z</dc:date>
    </item>
    <item>
      <title>Re: Not able to login to Ranger as AD user, however, UserSync works fine.</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Not-able-to-login-to-Ranger-as-AD-user-however-UserSync/m-p/186263#M58884</link>
      <description>&lt;P&gt;This is not the complete log, generally if the authentication denied is from the ldap server end, you must see the ldap related exception before the one you pasted above. Please review complete debug log to find actual error. &lt;/P&gt;&lt;P&gt;And is it AD or ldap for authentication? You can modify the UserSearchFilter and set it same as you have in UserSync configuration.&lt;/P&gt;</description>
      <pubDate>Thu, 06 Apr 2017 14:24:57 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Not-able-to-login-to-Ranger-as-AD-user-however-UserSync/m-p/186263#M58884</guid>
      <dc:creator>rguruvannagari</dc:creator>
      <dc:date>2017-04-06T14:24:57Z</dc:date>
    </item>
    <item>
      <title>Re: Not able to login to Ranger as AD user, however, UserSync works fine.</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Not-able-to-login-to-Ranger-as-AD-user-however-UserSync/m-p/186264#M58885</link>
      <description>&lt;P&gt;@rguruvannagari&lt;/P&gt;&lt;P&gt;I changed all the 'info' and 'warn' values under 'Advanced admin-log4j' to 'debug' (not just the root logger). Only then I started seeing detailed exceptions. After I pointed ranger admin to the right truststore file, I had not updated the password. The debug enabled logs clearly showed that the trust store password was wrong. I updated the correct password and now I am able to login as AD user.&lt;/P&gt;&lt;P&gt;Thanks a lot !&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Ekantheshwara Basappa&lt;/P&gt;</description>
      <pubDate>Fri, 07 Apr 2017 05:50:31 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Not-able-to-login-to-Ranger-as-AD-user-however-UserSync/m-p/186264#M58885</guid>
      <dc:creator>ekanthb</dc:creator>
      <dc:date>2017-04-07T05:50:31Z</dc:date>
    </item>
    <item>
      <title>Re: Not able to login to Ranger as AD user, however, UserSync works fine.</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Not-able-to-login-to-Ranger-as-AD-user-however-UserSync/m-p/186265#M58886</link>
      <description>&lt;P&gt;Great, this was actually my case.&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Tue, 28 Aug 2018 17:10:17 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Not-able-to-login-to-Ranger-as-AD-user-however-UserSync/m-p/186265#M58886</guid>
      <dc:creator>rsg</dc:creator>
      <dc:date>2018-08-28T17:10:17Z</dc:date>
    </item>
  </channel>
</rss>

