<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>question sentry doesnt work based on AD in Archives of Support Questions (Read Only)</title>
    <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/sentry-doesnt-work-based-on-AD/m-p/56421#M63602</link>
    <description>&lt;P&gt;&amp;nbsp;hi, i actually met an issue when configure sentry with hive.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;basically if i&amp;nbsp;configure hue security with&amp;nbsp;desktop.auth.backend.AllowFirstUserDjangoBackend, and use a local user to query hive, it would be succesful to query the right database.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;but if i configure hue with AD server, and use an AD user to logon hue, it would not load any database that the user was supposed to have&amp;nbsp;privileges on.&lt;/P&gt;&lt;P&gt;the AD user looks have more gourps:&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;[root@ ~]# id jjiang&lt;BR /&gt;uid=16777217(jjiang) gid=16777216(domain users) groups=16777216(domain users),502(db_admin),16777225,16777217(apacsysadmin),16777218(apac),16777226,16777239(apac_connectivity),16777227,16777219(itsystems),16777220(apac_it),16777228,16777247(apac_marketing_services),16777229,16777221(nantong office),16777230,16777222(ap_all_okta_users),16777223(okta_o365_users),16777224(ap-fp-general-users),16777231(ap_slack_itops)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;is it a problem with so many groups? the actual group i granted permission is&amp;nbsp;&lt;SPAN&gt;db_admin.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 16 Sep 2022 11:49:20 GMT</pubDate>
    <dc:creator>jjiang</dc:creator>
    <dc:date>2022-09-16T11:49:20Z</dc:date>
    <item>
      <title>sentry doesnt work based on AD</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/sentry-doesnt-work-based-on-AD/m-p/56421#M63602</link>
      <description>&lt;P&gt;&amp;nbsp;hi, i actually met an issue when configure sentry with hive.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;basically if i&amp;nbsp;configure hue security with&amp;nbsp;desktop.auth.backend.AllowFirstUserDjangoBackend, and use a local user to query hive, it would be succesful to query the right database.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;but if i configure hue with AD server, and use an AD user to logon hue, it would not load any database that the user was supposed to have&amp;nbsp;privileges on.&lt;/P&gt;&lt;P&gt;the AD user looks have more gourps:&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;[root@ ~]# id jjiang&lt;BR /&gt;uid=16777217(jjiang) gid=16777216(domain users) groups=16777216(domain users),502(db_admin),16777225,16777217(apacsysadmin),16777218(apac),16777226,16777239(apac_connectivity),16777227,16777219(itsystems),16777220(apac_it),16777228,16777247(apac_marketing_services),16777229,16777221(nantong office),16777230,16777222(ap_all_okta_users),16777223(okta_o365_users),16777224(ap-fp-general-users),16777231(ap_slack_itops)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;is it a problem with so many groups? the actual group i granted permission is&amp;nbsp;&lt;SPAN&gt;db_admin.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 16 Sep 2022 11:49:20 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/sentry-doesnt-work-based-on-AD/m-p/56421#M63602</guid>
      <dc:creator>jjiang</dc:creator>
      <dc:date>2022-09-16T11:49:20Z</dc:date>
    </item>
    <item>
      <title>Re: sentry doesnt work based on AD</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/sentry-doesnt-work-based-on-AD/m-p/56444#M63603</link>
      <description>&lt;P&gt;i just noticed the error from sentry log:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;2017-06-23 12:57:19,513 WARN org.apache.hadoop.security.ShellBasedUnixGroupsMapping: unable to return groups for user jjiang&lt;BR /&gt;PartialGroupNameException can't execute the shell command to get the list of group id for user 'jjiang'&lt;BR /&gt;at org.apache.hadoop.security.ShellBasedUnixGroupsMapping.resolvePartialGroupNames(ShellBasedUnixGroupsMapping.java:228)&lt;BR /&gt;at org.apache.hadoop.security.ShellBasedUnixGroupsMapping.getUnixGroups(ShellBasedUnixGroupsMapping.java:133)&lt;BR /&gt;at org.apache.hadoop.security.ShellBasedUnixGroupsMapping.getGroups(ShellBasedUnixGroupsMapping.java:72)&lt;BR /&gt;at org.apache.hadoop.security.Groups$GroupCacheLoader.fetchGroupList(Groups.java:356)&lt;BR /&gt;at org.apache.hadoop.security.Groups$GroupCacheLoader.load(Groups.java:299)&lt;BR /&gt;at org.apache.hadoop.security.Groups$GroupCacheLoader.load(Groups.java:257)&lt;BR /&gt;at com.google.common.cache.LocalCache$LoadingValueReference.loadFuture(LocalCache.java:3568)&lt;BR /&gt;at com.google.common.cache.LocalCache$Segment.loadSync(LocalCache.java:2350)&lt;BR /&gt;at com.google.common.cache.LocalCache$Segment.lockedGetOrLoad(LocalCache.java:2313)&lt;BR /&gt;at com.google.common.cache.LocalCache$Segment.get(LocalCache.java:2228)&lt;BR /&gt;at com.google.common.cache.LocalCache.get(LocalCache.java:3965)&lt;BR /&gt;at com.google.common.cache.LocalCache.getOrLoad(LocalCache.java:3969)&lt;BR /&gt;at com.google.common.cache.LocalCache$LocalManualCache.get(LocalCache.java:4829)&lt;BR /&gt;at org.apache.hadoop.security.Groups.getGroups(Groups.java:215)&lt;BR /&gt;at org.apache.sentry.provider.common.HadoopGroupMappingService.getGroups(HadoopGroupMappingService.java:60)&lt;BR /&gt;at org.apache.sentry.provider.db.service.thrift.SentryPolicyStoreProcessor.getGroupsFromUserName(SentryPolicyStoreProcessor.java:717)&lt;BR /&gt;at org.apache.sentry.provider.db.service.thrift.SentryPolicyStoreProcessor.getRequestorGroups(SentryPolicyStoreProcessor.java:684)&lt;BR /&gt;at org.apache.sentry.provider.db.service.thrift.SentryPolicyStoreProcessor.list_sentry_roles_by_group(SentryPolicyStoreProcessor.java:552)&lt;BR /&gt;at org.apache.sentry.provider.db.service.thrift.SentryPolicyService$Processor$list_sentry_roles_by_group.getResult(SentryPolicyService.java:1017)&lt;BR /&gt;at org.apache.sentry.provider.db.service.thrift.SentryPolicyService$Processor$list_sentry_roles_by_group.getResult(SentryPolicyService.java:1002)&lt;BR /&gt;at org.apache.thrift.ProcessFunction.process(ProcessFunction.java:39)&lt;BR /&gt;at org.apache.thrift.TBaseProcessor.process(TBaseProcessor.java:39)&lt;BR /&gt;at org.apache.sentry.provider.db.service.thrift.SentryProcessorWrapper.process(SentryProcessorWrapper.java:35)&lt;BR /&gt;at org.apache.thrift.TMultiplexedProcessor.process(TMultiplexedProcessor.java:123)&lt;BR /&gt;at org.apache.thrift.server.TThreadPoolServer$WorkerProcess.run(TThreadPoolServer.java:286)&lt;BR /&gt;at java.util.concurrent.ThreadPoolExecutor.runWorker(ThreadPoolExecutor.java:1145)&lt;BR /&gt;at java.util.concurrent.ThreadPoolExecutor$Worker.run(ThreadPoolExecutor.java:615)&lt;BR /&gt;at java.lang.Thread.run(Thread.java:745)&lt;BR /&gt;Caused by: PartialGroupNameException Number of group names and ids do not match.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;could anyone help ?&lt;/P&gt;</description>
      <pubDate>Sun, 25 Jun 2017 06:12:11 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/sentry-doesnt-work-based-on-AD/m-p/56444#M63603</guid>
      <dc:creator>jjiang</dc:creator>
      <dc:date>2017-06-25T06:12:11Z</dc:date>
    </item>
    <item>
      <title>Re: sentry doesnt work based on AD</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/sentry-doesnt-work-based-on-AD/m-p/56543#M63604</link>
      <description>&lt;P&gt;this is sloved with building up with a new AD. the problem was some goup id cant be resolved.&lt;/P&gt;</description>
      <pubDate>Tue, 27 Jun 2017 08:33:06 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/sentry-doesnt-work-based-on-AD/m-p/56543#M63604</guid>
      <dc:creator>jjiang</dc:creator>
      <dc:date>2017-06-27T08:33:06Z</dc:date>
    </item>
    <item>
      <title>Re: sentry doesnt work based on AD</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/sentry-doesnt-work-based-on-AD/m-p/63002#M63605</link>
      <description>&lt;P&gt;Hi there.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have the same problem but I didn't understand the solution. What did you do? Sorry but I'm a little desperate here... &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 22 Dec 2017 12:32:41 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/sentry-doesnt-work-based-on-AD/m-p/63002#M63605</guid>
      <dc:creator>JoaoBarreto</dc:creator>
      <dc:date>2017-12-22T12:32:41Z</dc:date>
    </item>
    <item>
      <title>Re: sentry doesnt work based on AD</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/sentry-doesnt-work-based-on-AD/m-p/63040#M63606</link>
      <description>&lt;P&gt;i built up a brand new AD environment instead of using the old one. the actual problem was it cant be resolved with group id for users.&lt;/P&gt;</description>
      <pubDate>Mon, 25 Dec 2017 08:22:39 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/sentry-doesnt-work-based-on-AD/m-p/63040#M63606</guid>
      <dc:creator>jjiang</dc:creator>
      <dc:date>2017-12-25T08:22:39Z</dc:date>
    </item>
    <item>
      <title>Re: sentry doesnt work based on AD</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/sentry-doesnt-work-based-on-AD/m-p/63080#M63607</link>
      <description>I can't actually do that, cause the AD comes from a major company... and it's managed by them. &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;Thanks for the reply!</description>
      <pubDate>Wed, 27 Dec 2017 09:33:20 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/sentry-doesnt-work-based-on-AD/m-p/63080#M63607</guid>
      <dc:creator>JoaoBarreto</dc:creator>
      <dc:date>2017-12-27T09:33:20Z</dc:date>
    </item>
  </channel>
</rss>

