[ 
https://issues.apache.org/jira/browse/HIVE-7193?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=14592984#comment-14592984
 ] 

Naveen Gangam commented on HIVE-7193:
-------------------------------------

Thank you for the review.
Q. Also, why is the example a comma-separated list when the description says 
colon-separated?
A. The example shows a single pattern for users for LDAP. Each attribute in 
LDAP DN is separated by COMMA
    "CN=%s,CN=Users,DC=subdomain,DC=domain,DC=com"
    However, it is possible that a ldap directory could have users in different 
trees. The pattern for baseDN for each tree is separated by COLON.
   For example 
"CN=%s,CN=Users,DC=subdomain,DC=domain,DC=com:CN=%s,OU=IT,DC=domain,DC=com"

The same is true for group patterns. Does this help? Thanks

> Hive should support additional LDAP authentication parameters
> -------------------------------------------------------------
>
>                 Key: HIVE-7193
>                 URL: https://issues.apache.org/jira/browse/HIVE-7193
>             Project: Hive
>          Issue Type: Bug
>    Affects Versions: 0.10.0
>            Reporter: Mala Chikka Kempanna
>            Assignee: Naveen Gangam
>         Attachments: HIVE-7193.2.patch, HIVE-7193.3.patch, HIVE-7193.4.patch, 
> HIVE-7193.patch, LDAPAuthentication_Design_Doc.docx, 
> LDAPAuthentication_Design_Doc_V2.docx
>
>
> Currently hive has only following authenticator parameters for LDAP 
> authentication for hiveserver2:
> {code:xml}
> <property> 
>   <name>hive.server2.authentication</name> 
>   <value>LDAP</value> 
> </property> 
> <property> 
>   <name>hive.server2.authentication.ldap.url</name> 
>   <value>ldap://our_ldap_address</value> 
> </property> 
> {code}
> We need to include other LDAP properties as part of hive-LDAP authentication 
> like below:
> {noformat}
> a group search base -> dc=domain,dc=com 
> a group search filter -> member={0} 
> a user search base -> dc=domain,dc=com 
> a user search filter -> sAMAAccountName={0} 
> a list of valid user groups -> group1,group2,group3 
> {noformat}



--
This message was sent by Atlassian JIRA
(v6.3.4#6332)

Reply via email to