- Subscribe to RSS Feed
- Mark Question as New
- Mark Question as Read
- Float this Question for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
How to setup Ranger NiFi policy auth based on LDAP group ?
- Labels:
-
Apache NiFi
-
Apache Ranger
Created ‎10-19-2017 08:35 AM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi,
I setup HDF (in particular NiFi & Ranger) to fetch users&groups from AD and do auth against AD.
Defining policies in Ranger for NiFi, based on AD users, is working as expected after logging in to NiFi with AD credentials.
The only thing that is not working are the policies which grants access based on AD groups.
There is this article from almost a year ago. Does it still apply @Bryan Bende? Means, NiFi policies based on AD group membership is not working ?
Thanks in advance....
Created ‎10-19-2017 12:20 PM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
HDF 3.0 does not have support of Ranger groups or LDAP groups. This should be a new feature in the HDF release coming out early next year.
Thanks,
Matt
Created ‎10-19-2017 11:42 AM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Apperently Yes, Still this is the case with HDF 3.0, we have tried this a month back and eventually gave up after figuring out that this is not supported at this moment.
Created ‎10-19-2017 12:20 PM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
HDF 3.0 does not have support of Ranger groups or LDAP groups. This should be a new feature in the HDF release coming out early next year.
Thanks,
Matt
Created ‎10-20-2017 06:33 AM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi @Matt Clarke , thanks for your reply. Will dive back into this with the release you mentioned.
You're saying "no support of Ranger or LDAP Groups", but support of Ranger is already there, although limited to user-based policies. Or did I misunderstand something here ?!?!
Created ‎10-20-2017 12:10 PM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I edited my response to be more clear. While Ranger is supported, the use of Ranger Groups is not.
Thanks,
Matt
