- Subscribe to RSS Feed
- Mark Question as New
- Mark Question as Read
- Float this Question for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Ranger authorization through groups
- Labels:
-
Apache Ranger
Created ‎08-27-2018 02:23 PM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hello,
I have been able to connect properly Ranger to AD with LDAPS.
- Currently syncing all the users requires a huge amount of time, currently 4+ hours for the initial sync. What are the available options to reduce this time?
- Regarding the access to Ranger UI, is it possible to assign roles to groups instead of users?
Thanks
Created ‎08-29-2018 12:48 PM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Use Group Sync portion of Ranger User Sync. Dialing into a specific group match should reduce the sync time, especially if your LDAPS contains thousands of users who do not need to be authorized in your cluster.
Yes, with Ranger Admin UI it is possible to assign roles to groups, users, and tags.
If this answer is helpful please click ACCEPT to mark the question as resolved.
Created ‎08-29-2018 12:48 PM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Use Group Sync portion of Ranger User Sync. Dialing into a specific group match should reduce the sync time, especially if your LDAPS contains thousands of users who do not need to be authorized in your cluster.
Yes, with Ranger Admin UI it is possible to assign roles to groups, users, and tags.
If this answer is helpful please click ACCEPT to mark the question as resolved.
