This topic describes how to integrate RangerUserSync with an LDAP server. This allows you to create Ranger policies that authorize users and user groups from the LDAP server to access components.
Prerequisites
You have an EMR cluster that runs a version earlier than EMR-5.11.0 or EMR-3.45.0, with both the Ranger and OpenLDAP services installed. For more information, see Create a cluster.
For clusters that run EMR-5.11.0 or later and EMR-3.45.0 or later, RangerUserSync automatically integrates with LDAP if the OpenLDAP service is installed. To check the current user source for RangerUserSync, go to the Configure tab of the Ranger service and search for the ranger.usersync.sync.source configuration item. The value is either 'unix' or 'ldap'.
Procedure
-
Go to the Services page of the cluster.
-
Log on to the E-MapReduce console.
-
In the top navigation bar, select a region and a resource group.
-
In the Actions column of the target cluster, click Services.
-
-
Enable LDAP for RangerUserSync.
-
On the Services page, click Status in the Ranger service section.
-
In the Components section, find RangerUserSync. In the Actions column, click the
icon and select enableRangerUserSyncLDAP. -
In the dialog box, enter an Execution Reason and click OK.
-
In the Confirm dialog box, click OK.
-
-
Restart RangerUserSync to apply the changes.
-
On the Services page, click Status in the Ranger service section.
-
In the Components section, find RangerUserSync and, in the Actions column, click .
-
In the dialog box, enter an Execution Reason and click OK.
-
In the Confirm dialog box, click OK.
-