Hi Fabien,
Can you provide more details on waht doesn't work ? I mean, you create a
policy, but it is not enforced, right ?
Can you see in HiveServer logs that Hive asks Ranger for an authorization
to execute your request ?
Thanks,
Loïc
Loïc CHANEL
System Big Data engineer
MS - Worldline
Hello,
Just to be clear, Ranger pull user data from LDAP. Therefore, the problem
should be at that level. Did you configure Ranger UserSync to pull
informations from your LDAP ?
Regards,
Loïc
Loïc CHANEL
System Big Data engineer
Vision 360 Degrés (Lyon, France)
2018-05-15 7:51 GMT+02:00 Taher
than I do so I'll let him confirm.
Best regards,
Loïc CHANEL
System Big Data engineer
Vision 360 Degrés (Lyon, France)
Le mer. 16 janv. 2019 à 14:58, Odon Copon a écrit :
> Oh true, didn't see that Hadoop column.
> But this is just for Hortonworks distribution, right? I can see per
>
Hi Nicolas,
Do you see in the logs that Spark is able to pull the policies from Ranger
API ?
Either way, could you please share the policies you defined in Ranger for
your user ?
Thanks,
Loïc CHANEL
System Big Data engineer
Vision 360 Degrés (Lyon, France)
Le lun. 9 mars 2020 à 13:41
is not aware of your activities.
Best regards,
Loïc CHANEL
System Big Data engineer
Vision 360 Degrés (Lyon, France)
Le lun. 9 mars 2020 à 15:46, Nicolas Paris a
écrit :
>
> Loïc Chanel writes:
> > Do you see in the logs that Spark is able to pull the policies from
> Ranger
> >
e/last name/email fields ?
Thanks for your help,
Loïc CHANEL
Technical leader Big Data
Capgemini (Lyon, France)
;. The thing is, I get an installation
error when I leave this field blank. Therefore I'm wondering if there is a
way to make usersync work with anonymous bind.
Thanks for your help,
Loïc CHANEL
Technical leader Big Data
Capgemini (Lyon, France)
to enrich the
first name/last name/email fields (manually or with an API) ?
Thanks for your help,
Loïc CHANEL
Technical leader Big Data
Capgemini (Lyon, France)
Le jeu. 8 févr. 2024 à 12:30, Loïc CHANEL a
écrit :
> Hi guys,
>
> As I'm pulling Ranger users from LDAP, I would like
Hi Sailaja,
>From the look of it, I'd say it could work for my use case. Do you know
where I could find some documentation about using that feature ?
Thanks,
Loïc
Le mer. 14 févr. 2024 à 18:05, Sailaja Polavarapu
a écrit :
> Hi Loïc CHANEL,
> Syncing extra attributes from AD/LDAP
g user/group source and sink
15 Feb 2024 16:57:02 DEBUG o.a.r.u.UserGroupSync [UnixUserSyncThread] -
Sleeping for [360] milliSeconds
Could you help me identify what's wrong ?
Thanks,
Loïc CHANEL
Technical leader Big Data
Capgemini (Lyon, France)
,
Loïc CHANEL
Technical leader Big Data
Capgemini (Lyon, France)
Le jeu. 15 févr. 2024 à 09:38, Loïc CHANEL a
écrit :
> Hi Sailaja,
> From the look of it, I'd say it could work for my use case. Do you know
> where I could find some documentation about using that feature ?
> Thanks,
>
in the install.properties file.
Maybe it's a bug ?
Best regards,
Loïc CHANEL
Technical leader Big Data
Capgemini (Lyon, France)
Le ven. 16 févr. 2024 à 11:53, Loïc CHANEL a
écrit :
> Adding more details to this : I provided usersync with a wrong password
> for LDAP, but it's still s
Adding more details to this : I provided usersync with a wrong password for
LDAP, but it's still showing the exact same logs. Therefore I'm wondering
where I would be able to get more details about the LDAP connection from
usersync, because the logs are clearly not enough.
Thanks,
Loïc CHANEL
: member,
groupNameAttribute: cn, groupSearchAttributes: [uSNChanged, displayname,
member, cn, modifytimestamp, objectid], groupSearchFirstEnabled: true,
userSearchEnabled: true, ldapReferral: ignore
But in Ranger, my user is created without any group. What am I missing ?
Thanks,
Loïc CHANEL
Hi Sailaja,
I already restarted usersync since I deleted the user, but nothing
happened. Where is this cache supposed to be stored ?
By the way, SYNC_LDAP_DELTASYNC is set to false in my case, so I guess it
could change the behaviour ?
Thanks,
Loïc CHANEL
Technical leader Big Data
Capgemini
a shame not making it available
to the community).
What's your opinion on this?
Thanks,
Loïc CHANEL
Technical leader Big Data
Capgemini (Lyon, France)
Le ven. 16 févr. 2024 à 16:43, Loïc CHANEL a
écrit :
> Hi Sailaja,
>
> I was finally able to understand what's been developed.
is minor, it would be a major
improvement on my Ranger usage.
Thanks for your help,
Loïc CHANEL
Technical leader Big Data
Capgemini (Lyon, France)
I'm using the 2.4.0 release. You will find the ranger-ugsync-site.xml config
file in attachment, feel free to let me know if you need more.
Best regards,
Loïc CHANEL
Technical leader Big Data
Capgemini (Lyon, France)
Le ven. 8 mars 2024 à 17:24, Sailaja Polavarapu
a écrit :
> Which bra
Missed the attachment before sending the email ... rookie mistake. Here is
the actual file (sorry for the spam).
Best regards,
Loïc CHANEL
Technical leader Big Data
Capgemini (Lyon, France)
Le ven. 8 mars 2024 à 17:33, Loïc CHANEL a
écrit :
> I'm using the 2.4.0 release. You will f
"-" "Java/1.8.0_275"
10.18.1.43 - - [08/Mar/2024:12:26:54 +] "GET
/service/xusers/ugsync/groupusers?startIndex=0=1000 HTTP/1.1" 200
4429925 2553 "-" "Java/1.8.0_275"
Looks like usersync isn't even trying to create the users. Anything I'm
missing ?
s
?
Thanks,
Loïc CHANEL
Technical leader Big Data
Capgemini (Lyon, France)
Le ven. 8 mars 2024 à 16:00, Sailaja Polavarapu
a écrit :
> This is strange as I don't see any logs from updateSink() method
> <https://github.com/apache/ranger/blob/master/ugsync/src/main/java/org/apache/
You're right, I definitely missed this (and feel like a complete idiot).
Now it works as expected.
Thanks a lot for your help,
Loïc CHANEL
Technical leader Big Data
Capgemini (Lyon, France)
Le ven. 8 mars 2024 à 17:59, Sailaja Polavarapu
a écrit :
> I see that the below property is
Hi team,
Am I the only one experiencing this issue ?
Thanks,
Loïc
Le lun. 19 févr. 2024 à 12:38, Loïc CHANEL a
écrit :
> Hi guys,
>
> Since 2.4, LDAP information retrieval to create groups seems broken. My
> sync issues are solved for users, but I'm still unable to pull groups
true, groupSearchBase: [dc=cmb,dc=blabla,dc=org],
> groupSearchScope: 2, groupObjectClass: groupofnames,
> May be if you provide usersync logs, that can help to analyze further
>
> Thanks,
> Sailaja.
>
> On Thu, Mar 21, 2024 at 8:00 AM Loïc CHANEL
> wrote:
>
>> Hi team,
>
for [30] milliSeconds
Am I missing something ?
Thanks for your help,
Loïc CHANEL
Technical leader Big Data
Capgemini (Lyon, France)
Le ven. 22 mars 2024 à 15:34, Sailaja Polavarapu
a écrit :
> Oh ok. In this case can you try setting
> ranger.usersync.group.searchenabled to false?
>
> On Fri, Mar 22, 2024 at 1:27 AM Loïc CHANEL
> wrote:
>
>> Hi Sailaja,
>>
>> Actually, the groups are
in the
XML file, but when Ranger starts I can see in the logs that the default
value ( ldap:// ) is loaded by Ranger instead of what I defined.
Is there something I'm missing ? How can I see where the values are loaded
from ?
Thanks for your help,
Loïc CHANEL
Technical leader Big Data
Capgemini
Hi Vipin,
Already did this but didn't see the file name as I was expecting them to be
before the properties but not after.
By finding the loaded file in the logs I've been able to troubleshoot my
issue.
Thanks a lot for your help,
Loïc CHANEL
Technical leader Big Data
Capgemini (Lyon, France
=org and I want LDAP
authentication to work for both.
Best regards,
Loïc CHANEL
Technical leader Big Data
Capgemini (Lyon, France)
Le jeu. 18 avr. 2024 à 13:39, Loïc CHANEL a
écrit :
> Hi Vipin,
>
> Already did this but didn't see the file name as I was expecting them to
&g
is
org.springframework.ldap.core.TokenMgrError: Lexical error at line 1,
column 10. Encountered: "(" (40), after : ""
I tried to escape the character with a backslash but got the exact same
result. Any other ideas ?
Best regards,
Loïc CHANEL
Technical leader Big Data
Capgemini
pes,DC=blabla,DC=org))
And it's still KO. What am I missing ? Is there a way I can make it work ?
Thanks,
Loïc CHANEL
Technical leader Big Data
Capgemini (Lyon, France)
Le ven. 19 avr. 2024 à 05:08, Vipin Rathor a écrit :
> Thank Sailaja for the reply. I was about to reply that
> Spr
31 matches
Mail list logo