Support Questions

Find answers, ask questions, and share your expertise
Announcements
Celebrating as our community reaches 100,000 members! Thank you!

CompositeGroupsMapping

avatar
Explorer

CDM shows these group mapping providers (hadoop.security.group.mapping):

- jniBasedUnixGroupsMapping

- ShellBasedUnixGroupsMapping

- LdapGroupsMapping

 

In 2012 a CompositeGroupsMappings provider was created, but I don't see it in CDM (v5.7.1)

 

Is it possible to configure CDM to use the CompositeGroupsMappings provider using a safety valve?

- the LdapGroupsMapping should be used for regular users

- the ShellBasedUnixGroupsMapping should be used for system accounts, like hdfs & yarn

 

thanks

1 ACCEPTED SOLUTION

avatar
Super Collaborator
hide-solution

This problem has been solved!

Want to get a detailed solution you have to login/registered on the community

Register/Login
2 REPLIES 2

avatar
Super Collaborator
hide-solution

This problem has been solved!

Want to get a detailed solution you have to login/registered on the community

Register/Login

avatar
Explorer

the configuration works fine

 

only issue is that the bind user password is not redacted in the advanced configuration snippet and in clear text in the core-site.xml

 

According to the security guide (sensitive data redaction), v5.8.x (not documented for 5.7.x):

Redaction of Advanced Configuration Snippet parameters is based on detecting keywords explicitly defined as sensitive in the contents of these parameters. That is, parameters containing the keywords password, key, aws, or secret, will be redacted for users who do not have the required edit privileges

 

I'll open a case to check how to get this working on 5.7.1