All Products
Search
Document Center

E-MapReduce:Integrate RangerUserSync with LDAP

Last Updated:Sep 16, 2026

This topic describes how to integrate RangerUserSync with an LDAP server. This allows you to create Ranger policies that authorize users and user groups from the LDAP server to access components.

Prerequisites

You have an EMR cluster that runs a version earlier than EMR-5.11.0 or EMR-3.45.0, with both the Ranger and OpenLDAP services installed. For more information, see Create a cluster.

Note

For clusters that run EMR-5.11.0 or later and EMR-3.45.0 or later, RangerUserSync automatically integrates with LDAP if the OpenLDAP service is installed. To check the current user source for RangerUserSync, go to the Configure tab of the Ranger service and search for the ranger.usersync.sync.source configuration item. The value is either 'unix' or 'ldap'.

Procedure

  1. Go to the Services page of the cluster.

    1. Log on to the E-MapReduce console.

    2. In the top navigation bar, select a region and a resource group.

    3. In the Actions column of the target cluster, click Services.

  2. Enable LDAP for RangerUserSync.

    1. On the Services page, click Status in the Ranger service section.

    2. In the Components section, find RangerUserSync. In the Actions column, click the image..png icon and select enableRangerUserSyncLDAP.

    3. In the dialog box, enter an Execution Reason and click OK.

    4. In the Confirm dialog box, click OK.

  3. Restart RangerUserSync to apply the changes.

    1. On the Services page, click Status in the Ranger service section.

    2. In the Components section, find RangerUserSync and, in the Actions column, click Restart.

    3. In the dialog box, enter an Execution Reason and click OK.

    4. In the Confirm dialog box, click OK.