<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>question Re: knox/Ldap integration in Archives of Support Questions (Read Only)</title>
    <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/knox-Ldap-integration/m-p/201434#M76781</link>
    <description>&lt;P&gt;&lt;EM&gt;@&lt;A href="https://community.hortonworks.com/users/19322/mishraanurag643.html"&gt;Anurag Mishra&lt;/A&gt; &lt;/EM&gt;LDAP authentication is configured by adding a "ShiroProvider" authentication provider to the cluster's topology file. When enabled, the Knox Gateway uses Apache Shiro (&lt;CODE&gt;org.apache.shiro.realm.ldap.JndiLdapRealm&lt;/CODE&gt;) to authenticate users against the configured LDAP store.&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Please go through this &lt;/EM&gt;&lt;A href="https://docs.hortonworks.com/HDPDocuments/HDP2/HDP-2.6.4/bk_security/content/setting_up_ldap_authentication.html" target="_blank"&gt;document link&lt;/A&gt;&lt;EM&gt; &lt;/EM&gt;&lt;BR /&gt;&lt;BR /&gt;1. Shiro Provider is Knox side code and integrated. You need not worry about it's internal and change admin.xml (Admin topology) i.e. for Knox Administrators to proper LDAP/AD related values. For general usage, use default topology for services integration.&lt;BR /&gt;2. Read above documentation.&lt;BR /&gt;3. Read above documentation.&lt;/P&gt;&lt;P&gt;4. Make a group of users, you want to give access and whitelist them using ACL.&lt;/P&gt;</description>
    <pubDate>Thu, 05 Apr 2018 14:30:33 GMT</pubDate>
    <dc:creator>WhiteHa</dc:creator>
    <dc:date>2018-04-05T14:30:33Z</dc:date>
    <item>
      <title>knox/Ldap integration</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/knox-Ldap-integration/m-p/201430#M76777</link>
      <description>&lt;P&gt;I am trying to integrate Knox with Ldap  but i have some doubts on the same .Please help me out . Please find below queries on the same :&lt;/P&gt;&lt;P&gt;1. I can see below property under /etc/knox/conf/topologies/admin.xml file &lt;/P&gt;&lt;P&gt;&amp;lt;role&amp;gt;authentication&amp;lt;/role&amp;gt;
&amp;lt;name&amp;gt;ShiroProvider&amp;lt;/name&amp;gt;
&amp;lt;enabled&amp;gt;true&amp;lt;/enabled&amp;gt;&lt;/P&gt;&lt;P&gt;what is shiroProvider , can we customize it ? where does it exist ldap  server end or knox ?&lt;/P&gt;&lt;P&gt;2. value of main.ldapRealm.contextFactory.authenticationMechanism is set to Simple and in documentation it is mentioned as well Apache Knox supports only simple authentication. What does it really mean , what is here contextFactory and main.ldapRealm.contextFactory.authenticationMechanism value simple ? what does simple refer to ?&lt;/P&gt;&lt;P&gt;3. urls./** :  authcBasic&lt;/P&gt;&lt;P&gt;what does it really signify &lt;/P&gt;&lt;P&gt;I have gone through below  link below but not much understanding , please help me on this .&lt;/P&gt;&lt;P&gt;&lt;A href="https://developer.ibm.com/hadoop/2016/08/03/ldap-integration-with-apache-knox/" target="_blank"&gt;https://developer.ibm.com/hadoop/2016/08/03/ldap-integration-with-apache-knox/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;4. How to deny access to the user which is present already in the main.ldapRealm.userDnTemplate .&lt;/P&gt;&lt;P&gt;Thanks in advance&lt;/P&gt;</description>
      <pubDate>Tue, 03 Apr 2018 14:27:39 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/knox-Ldap-integration/m-p/201430#M76777</guid>
      <dc:creator>amol_08</dc:creator>
      <dc:date>2018-04-03T14:27:39Z</dc:date>
    </item>
    <item>
      <title>Re: knox/Ldap integration</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/knox-Ldap-integration/m-p/201431#M76778</link>
      <description>&lt;P&gt;@Jay Kumar SenSharma&lt;/P&gt;&lt;P&gt;Hi jay could you please help me on this ?&lt;/P&gt;</description>
      <pubDate>Thu, 05 Apr 2018 01:34:02 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/knox-Ldap-integration/m-p/201431#M76778</guid>
      <dc:creator>amol_08</dc:creator>
      <dc:date>2018-04-05T01:34:02Z</dc:date>
    </item>
    <item>
      <title>Re: knox/Ldap integration</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/knox-Ldap-integration/m-p/201432#M76779</link>
      <description>&lt;P&gt;&lt;EM&gt;@&lt;A href="https://community.hortonworks.com/users/19322/mishraanurag643.html"&gt;Anurag Mishra&lt;/A&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;This is the ultimate reference for knox. I am sure you will get the above questions answered with examples &lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://knox.apache.org/books/knox-0-6-0/user-guide.html#WebHDFS+Examples" target="_blank"&gt;&lt;EM&gt;knox_ldap&lt;/EM&gt;&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 05 Apr 2018 01:57:58 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/knox-Ldap-integration/m-p/201432#M76779</guid>
      <dc:creator>Shelton</dc:creator>
      <dc:date>2018-04-05T01:57:58Z</dc:date>
    </item>
    <item>
      <title>Re: knox/Ldap integration</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/knox-Ldap-integration/m-p/201433#M76780</link>
      <description>&lt;P&gt;&lt;EM&gt; @&lt;A href="https://community.hortonworks.com/users/19322/mishraanurag643.html"&gt;Anurag Mishra&lt;/A&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;If your question got answered or resolved by that link please &lt;STRONG&gt;"Accept"&lt;/STRONG&gt; and close this thread .&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Thank you&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 05 Apr 2018 14:26:35 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/knox-Ldap-integration/m-p/201433#M76780</guid>
      <dc:creator>Shelton</dc:creator>
      <dc:date>2018-04-05T14:26:35Z</dc:date>
    </item>
    <item>
      <title>Re: knox/Ldap integration</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/knox-Ldap-integration/m-p/201434#M76781</link>
      <description>&lt;P&gt;&lt;EM&gt;@&lt;A href="https://community.hortonworks.com/users/19322/mishraanurag643.html"&gt;Anurag Mishra&lt;/A&gt; &lt;/EM&gt;LDAP authentication is configured by adding a "ShiroProvider" authentication provider to the cluster's topology file. When enabled, the Knox Gateway uses Apache Shiro (&lt;CODE&gt;org.apache.shiro.realm.ldap.JndiLdapRealm&lt;/CODE&gt;) to authenticate users against the configured LDAP store.&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Please go through this &lt;/EM&gt;&lt;A href="https://docs.hortonworks.com/HDPDocuments/HDP2/HDP-2.6.4/bk_security/content/setting_up_ldap_authentication.html" target="_blank"&gt;document link&lt;/A&gt;&lt;EM&gt; &lt;/EM&gt;&lt;BR /&gt;&lt;BR /&gt;1. Shiro Provider is Knox side code and integrated. You need not worry about it's internal and change admin.xml (Admin topology) i.e. for Knox Administrators to proper LDAP/AD related values. For general usage, use default topology for services integration.&lt;BR /&gt;2. Read above documentation.&lt;BR /&gt;3. Read above documentation.&lt;/P&gt;&lt;P&gt;4. Make a group of users, you want to give access and whitelist them using ACL.&lt;/P&gt;</description>
      <pubDate>Thu, 05 Apr 2018 14:30:33 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/knox-Ldap-integration/m-p/201434#M76781</guid>
      <dc:creator>WhiteHa</dc:creator>
      <dc:date>2018-04-05T14:30:33Z</dc:date>
    </item>
  </channel>
</rss>

