Support Questions

Find answers, ask questions, and share your expertise

Ranger, Knox integration with Multiple Forest AD's

avatar
Super Collaborator

I came to know that AD can be set up with multiple forests. Forest are AD lingo for a container at a level even higher then the Domain Controllers. This is not uncommon in large enterprise AD deployments ( see : MS_Technet)

So my question is:

-Do any of the HDP stack security features (Knox and Ranger) support this multi forest setup of AD (with the aim of synching or logging on to HDP from any one of those forests) and how?

1 ACCEPTED SOLUTION

avatar
Super Guru

@Jasper

As you mention, a Forest is just a container for multiple domains. If there is a trust relationship in place, then you should be able to authenticate from Domain1 and access resources in Domain2. You can also authenticate against Domain1 and query Domain2.

I believe the HDP stack security components can authenticate to a domain within a Forest without any issues as the Forest should be transparent to HDP.

Having said that, I believe you can only specify a single domain in the configuration options for the HDP components. While you can query multiple domains using tools like "ldapsearch", I don't think you can currently do so using HDP.

View solution in original post

2 REPLIES 2

avatar
Super Guru

@Jasper

As you mention, a Forest is just a container for multiple domains. If there is a trust relationship in place, then you should be able to authenticate from Domain1 and access resources in Domain2. You can also authenticate against Domain1 and query Domain2.

I believe the HDP stack security components can authenticate to a domain within a Forest without any issues as the Forest should be transparent to HDP.

Having said that, I believe you can only specify a single domain in the configuration options for the HDP components. While you can query multiple domains using tools like "ldapsearch", I don't think you can currently do so using HDP.

avatar
Expert Contributor

FYI.

"Multiple Forest" is supported - but not "Cross Forest" AD.

If you have "Cross Forest" AD, Ranger may able to get users from the right branch but not groups or vice versa