Support Questions
Find answers, ask questions, and share your expertise

Ranger authorization through groups

Contributor

Hello,

I have been able to connect properly Ranger to AD with LDAPS.

  • Currently syncing all the users requires a huge amount of time, currently 4+ hours for the initial sync. What are the available options to reduce this time?
  • Regarding the access to Ranger UI, is it possible to assign roles to groups instead of users?

Thanks

1 ACCEPTED SOLUTION

Accepted Solutions

@Raffaele S

Use Group Sync portion of Ranger User Sync. Dialing into a specific group match should reduce the sync time, especially if your LDAPS contains thousands of users who do not need to be authorized in your cluster.

Yes, with Ranger Admin UI it is possible to assign roles to groups, users, and tags.

If this answer is helpful please click ACCEPT to mark the question as resolved.

View solution in original post

1 REPLY 1

@Raffaele S

Use Group Sync portion of Ranger User Sync. Dialing into a specific group match should reduce the sync time, especially if your LDAPS contains thousands of users who do not need to be authorized in your cluster.

Yes, with Ranger Admin UI it is possible to assign roles to groups, users, and tags.

If this answer is helpful please click ACCEPT to mark the question as resolved.

View solution in original post