Member since
05-17-2016
190
Posts
46
Kudos Received
11
Solutions
My Accepted Solutions
Title | Views | Posted |
---|---|---|
1388 | 09-07-2017 06:24 PM | |
1793 | 02-24-2017 06:33 AM | |
2596 | 02-10-2017 09:18 PM | |
7080 | 01-11-2017 08:55 PM | |
4725 | 12-15-2016 06:16 PM |
08-26-2016
06:41 AM
@pankaj singh Thank You Pankaj, I will try that and let you know.
... View more
08-26-2016
05:39 AM
@Predrag Minovic I did verify that. There is only 1 user arun within the directory. Tried restarting the server, still the same.
... View more
08-26-2016
02:55 AM
Hi All,
I synced some users from IPA LDAP to Ambari. However I am not able to login to ambari using any of the LDAP users.
On the web UI I get the below error, Unable to connect to Ambari Server.
Confirm Ambari Server is running and you can reach Ambari Server from this machine. ambari-server.txt
Also attached the exception trace.
... View more
Labels:
- Labels:
-
Apache Ambari
08-26-2016
02:22 AM
Hi All,
I am doing a small prototype trying to sync the IPA ldap groups to Ambari. I am able to sync the users and groups individually. However, when I sync a group, the relations/users under the group are not copied, but only an empty group. Could you point out where I could be going wrong? Below is my configuration used for the set up.
Primary URL* {host:port} (ipa.arunak.com:636):
Secondary URL {host:port} :
Use SSL* [true/false] (true):
User object class* (mepManagedEntry):
User name attribute* (cn):
Group object class* (posixGroup):
Group name attribute* (cn):
Group member attribute* (member):
Distinguished name attribute* (dn):
Base DN* (dc=arunak,dc=com):
Referral method [follow/ignore] :
Bind anonymously* [true/false] (false):
Manager DN* (arun): uid=arun,cn=users,cn=accounts,dc=arunak,dc=com
Enter Manager Password* :
Re-enter password:
Do you want to provide custom TrustStore for Ambari [y/n] (y)?
TrustStore type [jks/jceks/pkcs12] (jks):
Path to TrustStore file (/etc/ambari-server/keys/ldaps-keystore.jks):
Password for TrustStore:
Re-enter password:
====================Review Settings====================
authentication.ldap.managerDn: uid=arun,cn=users,cn=accounts,dc=arunak,dc=com
authentication.ldap.managerPassword: *****
ssl.trustStore.type: jks
ssl.trustStore.path: /etc/ambari-server/keys/ldaps-keystore.jks
ssl.trustStore.password: *****
Save settings [y/n] (y)?
Saving...done
Ambari Server 'setup-ldap' completed successfully.
I synced the group as below, but no users were copied to ambari, but just an empty group got created. ambari-server sync-ldap --groups grp.lst
Using python /usr/bin/python2.6
Syncing with LDAP...
Enter Ambari Admin login: ipaadmin
Enter Ambari Admin password:
Syncing specified users and groups...
Completed LDAP Sync.
Summary:
memberships:
removed = 0
created = 0
users:
updated = 0
removed = 0
created = 0
groups:
updated = 0
removed = 0
created = 2
Ambari Server 'sync-ldap' completed successfully.
... View more
Labels:
- Labels:
-
Apache Ambari
08-24-2016
07:44 PM
Thanks Again!!. I was prototyping, and hence wasn't looking for something at an enterprise level. 🙂
... View more
08-24-2016
07:40 PM
Thanks @Orlando Teixeira.
One last question - what tool do you use to add users to the directory? I have been using ipa user-add and ipa group-add and as a result, if I do a ldap search, I don't find any values for krbPwdPolicyReference: and krbPrincipalName. Is there something I am doing wrong here.
[admin@ipa ec2-user]$ ldapsearch -x -W "uid=jsmith"
Enter LDAP Password:
# extended LDIF
#
# LDAPv3
# base <dc=example,dc=com> (default) with scope subtree
# filter: uid=jsmith
# requesting: ALL
#
# jsmith, users, compat, arunak.com
dn: uid=jsmith,cn=users,cn=compat,dc=example,dc=com
cn: James Smith
objectClass: posixAccount
objectClass: ipaOverrideTarget
objectClass: top
ipaAnchorUUID:: OklQQTphcnVuYWsuY29tOmVhMzk5OGEwLTY2NDAtMTFlNi05NTExLTEyNzY0N2
ZhZThlOQ==
gidNumber: 443400011
gecos: James Smith
uidNumber: 443400011
loginShell: /bin/sh
homeDirectory: /home/jsmith
uid: jsmith
# jsmith, users, accounts, example.com
dn: uid=jsmith,cn=users,cn=accounts,dc=example,dc=com
displayName: James Smith
uid: tutui
objectClass: ipaobject
objectClass: person
objectClass: top
objectClass: ipasshuser
objectClass: inetorgperson
objectClass: organizationalperson
objectClass: krbticketpolicyaux
objectClass: krbprincipalaux
objectClass: inetuser
objectClass: posixaccount
objectClass: ipaSshGroupOfPubKeys
objectClass: mepOriginEntry
loginShell: /bin/sh
initials: SA
gecos: James Smith
sn: Smith
homeDirectory: /home/jsmith
givenName: James
cn: James Smith
uidNumber: 443400011
gidNumber: 443400011
# search result
search: 2
result: 0 Success
# numResponses: 3
# numEntries: 2
... View more
08-24-2016
07:12 PM
@Krishna Pandey. In anticipation of this, I had created an ambari_admin before the sync and granted the admin role to this new user. However, after sync, I am not able to see the user management option in ambari after logging in as ambari_admin. Is this some configuration issue at my end?
... View more
08-24-2016
07:07 PM
Thanks @Krishna Pandey. Was able to use the default ones to Sync up the users. However I was not sure where there attributes are attached to my users/groups since I could not see anything called dn using jxplorer.
... View more
08-24-2016
07:04 PM
Thanks @Orlando Teixeira. Could you share me a sample ldif file that you used for ldapadd. I was able to sync the user bases using the default specified above. I did not see a dn attribute to any of my user/group using jxplore and hence wanted to know how relevant these default values are.
After the sync, the admin user in IPA which is defaulted to admin messed up my Ambari admin user, which is also by default admin.
... View more