<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>question Re: HUE with IMPALA with LDAP, SENTRY enabled in Archives of Support Questions (Read Only)</title>
    <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/HUE-with-IMPALA-with-LDAP-SENTRY-enabled/m-p/58969#M66746</link>
    <description>&lt;P&gt;Actualy I figured out. I had to configure Impala to allow user ldaptest to impersonate as user cloudera ( hue login).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I appended this to the cloudera manager property Proxy User Configuration ( authorized_proxy_user_config )&lt;/P&gt;&lt;P&gt;hue=*;ldaptest=cloudera&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So user hue can impersonate anyone and user 'ldaptest' can impersonate as 'cloudera'.&lt;/P&gt;</description>
    <pubDate>Thu, 17 Aug 2017 15:57:48 GMT</pubDate>
    <dc:creator>sunilosunil</dc:creator>
    <dc:date>2017-08-17T15:57:48Z</dc:date>
    <item>
      <title>HUE with IMPALA with LDAP, SENTRY enabled</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/HUE-with-IMPALA-with-LDAP-SENTRY-enabled/m-p/58928#M66744</link>
      <description>&lt;P&gt;Environment CDH 5.12, OPEN LDAP&lt;/P&gt;&lt;P&gt;We've enabled LDAP auth on Impala and it's working fine except in HUE. When I try to launch HUE/Impala Editor it fails with this error in GUI.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have configured safety valve in HUE with this.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;[desktop]&lt;BR /&gt;ldap_username=ldaptest&lt;BR /&gt;ldap_password=ldaptest&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm logging into HUE as user cloudera ( FYI ; we don't have LDAP enabled on HUE ; cloudera is just a user managed within HUE )&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV class="alert jHueNotify alert-error"&gt;&lt;DIV class="message"&gt;&lt;FONT color="#800000" face="courier new,courier"&gt;&lt;STRONG&gt;User 'ldaptest' is not authorized to delegate to 'cloudera'.&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/DIV&gt;&lt;DIV class="message"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class="message"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class="message"&gt;&lt;FONT color="#800000" face="courier new,courier"&gt;&lt;STRONG&gt;Bad status for request TOpenSessionReq(username='hue', password=None, client_protocol=6, configuration={'idle_s&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/DIV&gt;&lt;DIV class="message"&gt;&lt;FONT color="#800000" face="courier new,courier"&gt;&lt;STRONG&gt;ession_timeout': '3600', 'impala.doas.user': u'cloudera'}): TOpenSessionResp(status=TStatus(errorCode=None, errorMessage="User 'ldaptest' is not authorized to delegate to 'cloudera'.\n", sqlState='HY000', infoMessages=None, statusCode=3), sessionHandle=TSessionHandle(sessionId=THandleIdentifier(secret='\x06\xd1\xc8\xe5\xd2\xc1Ck\xbd\xc7\xc5\xdb\xc5\x12\xdb\x8b', guid='*QiZ\xb0\xc7H\x0f\x8c5\xec\x14\xdf*7H')), configuration=None, serverProtocolVersion=5)&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/DIV&gt;&lt;DIV class="message"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class="message"&gt;&lt;STRONG&gt;How can I enable user ldaptest to be able to delegate to cloudera ?&lt;/STRONG&gt;&lt;/DIV&gt;</description>
      <pubDate>Tue, 21 Apr 2026 13:45:58 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/HUE-with-IMPALA-with-LDAP-SENTRY-enabled/m-p/58928#M66744</guid>
      <dc:creator>sunilosunil</dc:creator>
      <dc:date>2026-04-21T13:45:58Z</dc:date>
    </item>
    <item>
      <title>Re: HUE with IMPALA with LDAP, SENTRY enabled</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/HUE-with-IMPALA-with-LDAP-SENTRY-enabled/m-p/58948#M66745</link>
      <description>&lt;P&gt;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/18773"&gt;@sunilosunil&lt;/a&gt;&amp;nbsp;Are you using cloudera manager:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Authentication Backend desktop.auth.backend.LdapBackend&lt;BR /&gt;LDAP URL ldap://your_ldap_url&lt;BR /&gt;LDAP Search Base&lt;BR /&gt;LDAP Bind User&lt;BR /&gt;LDAP Bind Password&lt;BR /&gt;LDAP User Filter&lt;BR /&gt;LDAP Username Attribute&lt;BR /&gt;LDAP Group Filter&lt;BR /&gt;LDAP Group Name Attribute&lt;BR /&gt;LDAP Group Membership Attribute&lt;BR /&gt;Active Directory Domain&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You need your system admin to create you a user in the LDAP and provide you with this parameters.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Then you can just restart Hue service&lt;/P&gt;</description>
      <pubDate>Thu, 17 Aug 2017 08:35:49 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/HUE-with-IMPALA-with-LDAP-SENTRY-enabled/m-p/58948#M66745</guid>
      <dc:creator>Fawze</dc:creator>
      <dc:date>2017-08-17T08:35:49Z</dc:date>
    </item>
    <item>
      <title>Re: HUE with IMPALA with LDAP, SENTRY enabled</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/HUE-with-IMPALA-with-LDAP-SENTRY-enabled/m-p/58969#M66746</link>
      <description>&lt;P&gt;Actualy I figured out. I had to configure Impala to allow user ldaptest to impersonate as user cloudera ( hue login).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I appended this to the cloudera manager property Proxy User Configuration ( authorized_proxy_user_config )&lt;/P&gt;&lt;P&gt;hue=*;ldaptest=cloudera&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So user hue can impersonate anyone and user 'ldaptest' can impersonate as 'cloudera'.&lt;/P&gt;</description>
      <pubDate>Thu, 17 Aug 2017 15:57:48 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/HUE-with-IMPALA-with-LDAP-SENTRY-enabled/m-p/58969#M66746</guid>
      <dc:creator>sunilosunil</dc:creator>
      <dc:date>2017-08-17T15:57:48Z</dc:date>
    </item>
    <item>
      <title>Re: HUE with IMPALA with LDAP, SENTRY enabled</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/HUE-with-IMPALA-with-LDAP-SENTRY-enabled/m-p/59671#M66747</link>
      <description>&lt;P&gt;Where exactly was this entry made?I am facing the same issue even after making the entry&amp;nbsp;&lt;SPAN&gt;Proxy User Configuration authorized_proxy_user_config under Impala service wide.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 07 Sep 2017 17:26:29 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/HUE-with-IMPALA-with-LDAP-SENTRY-enabled/m-p/59671#M66747</guid>
      <dc:creator>Telematics</dc:creator>
      <dc:date>2017-09-07T17:26:29Z</dc:date>
    </item>
    <item>
      <title>Re: HUE with IMPALA with LDAP, SENTRY enabled</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/HUE-with-IMPALA-with-LDAP-SENTRY-enabled/m-p/59680#M66748</link>
      <description>&lt;P&gt;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/23726"&gt;@Telematics&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In Cloudera Manager, edit&amp;nbsp;&lt;STRONG&gt;&lt;SPAN&gt;Proxy User Configuration&lt;/SPAN&gt;&lt;/STRONG&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What did you enter in the field?&lt;/P&gt;&lt;P&gt;It should look like this, for example:&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;joe=alice,bob;hue=*;admin=*&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;See the Description of&amp;nbsp;&lt;STRONG&gt;&lt;SPAN&gt;Proxy User Configuration&lt;/SPAN&gt;&lt;/STRONG&gt; in Cloudera Manager (click the question mark next to the property)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;-Ben&lt;/P&gt;</description>
      <pubDate>Thu, 07 Sep 2017 19:03:29 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/HUE-with-IMPALA-with-LDAP-SENTRY-enabled/m-p/59680#M66748</guid>
      <dc:creator>bgooley</dc:creator>
      <dc:date>2017-09-07T19:03:29Z</dc:date>
    </item>
  </channel>
</rss>

