Support Questions

Find answers, ask questions, and share your expertise
Announcements
Celebrating as our community reaches 100,000 members! Thank you!

Can multiple LDAP servers be configured on apache knox/ranger

avatar
Explorer

We use multiple LDAP servers separated based on geographic location. Is it possible to configure multiple LDAP servers in apache knox/Ranger.

1 ACCEPTED SOLUTION

avatar
Master Guru

In Knox, you can create two or more topology files, and specify different LDAP seraver in each of them. End users can select which LDAP server to use by specifying one of those file names in the Knox URL. Specifiying two or more LDAP or any other authentication providers in the same topology file is not supported, for more details see here. Ranger also supports only one LDAP provider. For initial user-sync you can sync with one LDAP server, and then change settings and sync with the other. However, for subsequent user-syncs Ranger will use only the single LDAP server currently set.

View solution in original post

3 REPLIES 3

avatar
Super Guru

@Jay Kumar

I wont think this is supported as off now.

For HUE its supported from HDP 2.2.0.0

avatar
Super Guru

Not sure if you are looking for something like referral -

+  <property>
+    <name>ranger.ldap.referral</name>
+    <value>ignore</value>
+    <description>Set to follow if multiple LDAP servers are configured to return continuation
references for results. Set to ignore (default) if no referrals should be followed</description>
+  </property>

avatar
Master Guru

In Knox, you can create two or more topology files, and specify different LDAP seraver in each of them. End users can select which LDAP server to use by specifying one of those file names in the Knox URL. Specifiying two or more LDAP or any other authentication providers in the same topology file is not supported, for more details see here. Ranger also supports only one LDAP provider. For initial user-sync you can sync with one LDAP server, and then change settings and sync with the other. However, for subsequent user-syncs Ranger will use only the single LDAP server currently set.