[ 
https://issues.apache.org/jira/browse/RANGER-1919?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=16346173#comment-16346173
 ] 

Don Bosco Durai commented on RANGER-1919:
-----------------------------------------

[~Ronald van de Kuil] , user sync in Ranger is generic and can support 
different sources. In addition to AD/LDAP, linux users, it also supports 
importing users from flat files. With Kerberos users, if it is not backed with 
AD or OpenLDAP, then you could download the principals to a file and do the 
translation as it is configured in HDFS auth rules and then you should be able 
to load into Ranger. If this works, we should be able to convert it in a 
scheduled job.

 

> kerberos sync
> -------------
>
>                 Key: RANGER-1919
>                 URL: https://issues.apache.org/jira/browse/RANGER-1919
>             Project: Ranger
>          Issue Type: Improvement
>          Components: plugins
>            Reporter: Ronald van de Kuil
>            Priority: Minor
>
> In my understanding usersync, AD, LDAP configs are there to sync identities 
> into ranger so that access policies can be attached to them.
> It would make sense then to do the same for identities in a kerberos realm. 



--
This message was sent by Atlassian JIRA
(v7.6.3#76005)

Reply via email to