Return-Path: X-Original-To: apmail-hive-issues-archive@minotaur.apache.org Delivered-To: apmail-hive-issues-archive@minotaur.apache.org Received: from mail.apache.org (hermes.apache.org [140.211.11.3]) by minotaur.apache.org (Postfix) with SMTP id D4BBD18C03 for ; Fri, 19 Jun 2015 03:56:00 +0000 (UTC) Received: (qmail 84026 invoked by uid 500); 19 Jun 2015 03:56:00 -0000 Delivered-To: apmail-hive-issues-archive@hive.apache.org Received: (qmail 84005 invoked by uid 500); 19 Jun 2015 03:56:00 -0000 Mailing-List: contact issues-help@hive.apache.org; run by ezmlm Precedence: bulk List-Help: List-Unsubscribe: List-Post: List-Id: Reply-To: dev@hive.apache.org Delivered-To: mailing list issues@hive.apache.org Received: (qmail 83994 invoked by uid 99); 19 Jun 2015 03:56:00 -0000 Received: from arcas.apache.org (HELO arcas.apache.org) (140.211.11.28) by apache.org (qpsmtpd/0.29) with ESMTP; Fri, 19 Jun 2015 03:56:00 +0000 Date: Fri, 19 Jun 2015 03:56:00 +0000 (UTC) From: "Lefty Leverenz (JIRA)" To: issues@hive.apache.org Message-ID: In-Reply-To: References: Subject: [jira] [Commented] (HIVE-7193) Hive should support additional LDAP authentication parameters MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: 7bit X-JIRA-FingerPrint: 30527f35849b9dde25b450d4833f0394 [ https://issues.apache.org/jira/browse/HIVE-7193?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=14592969#comment-14592969 ] Lefty Leverenz commented on HIVE-7193: -------------------------------------- Doc review (parameter descriptions): *hive.server2.authentication.ldap.groupDNPattern* {code} + "COLON-separated list of patterns to use to find DNs for group entities in this directory \n" + + "use %s where the actual group name is to be substituted for.\n" + + "For example: CN=%s,CN=Groups,DC=subdomain,DC=domain,DC=com."), {code} Please add a period at end of first line and start second line with initial capital "Use ...." Also, why is the example a comma-separated list when the description says colon-separated? *hive.server2.authentication.ldap.groupFilter* {code} + "COMMA-separated list of LDAP Group names (short name not full DNs) \n" + + " For example: HiveAdmins,HadoopAdmins,Administrators"), {code} Again, end the first line with a period. Remove the space at beginning of second line. *hive.server2.authentication.ldap.userDNPattern* {code} + "COLON-separated list of patterns to use to find DNs for users in this directory \n" + + "use %s where the actual group name is to be substituted for.\n" + + "For example: CN=%s,CN=Users,DC=subdomain,DC=domain,DC=com." + + "COLON-seperated list of Base DNs for User entities in the LDAP directory"), {code} Again, add period to first line and start second line "Use". Why is the list comma-separated? Does the fourth line belong somewhere else? (It misspells "separated" too.) *hive.server2.authentication.ldap.userFilter* {code} + "COMMA-separated list of LDAP usernames (just short names, not full DNs) \n" + + "For example: hiveuser,impalauser,hiveadmin,hadoopadmin"), {code} Add period at end of first line. *hive.server2.authentication.ldap.customLDAPQuery* {code} + "A full LDAP query that LDAP Atn provider uses to execute against LDAP Server \n" + + "If this query return a null resultset, the LDAP Provider fails the Authentication request \n" + + ", succeeds otherwise." + + "For example: (&(objectClass=group)(objectClass=top)(instanceType=4)(cn=Domain*)) \n" + + "(&(objectClass=person)(|(sAMAccountName=admin)(|(memberOf=CN=Domain Admins,CN=Users,DC=domain,DC=com)" + + "(memberOf=CN=Administrators,CN=Builtin,DC=domain,DC=com))))"), {code} Add a period at end of first line. Second line: "If this query returns ..." (add the s to return) and move comma from start of third line to end of second line (or move "request" to third line). > Hive should support additional LDAP authentication parameters > ------------------------------------------------------------- > > Key: HIVE-7193 > URL: https://issues.apache.org/jira/browse/HIVE-7193 > Project: Hive > Issue Type: Bug > Affects Versions: 0.10.0 > Reporter: Mala Chikka Kempanna > Assignee: Naveen Gangam > Attachments: HIVE-7193.2.patch, HIVE-7193.3.patch, HIVE-7193.4.patch, HIVE-7193.patch, LDAPAuthentication_Design_Doc.docx, LDAPAuthentication_Design_Doc_V2.docx > > > Currently hive has only following authenticator parameters for LDAP authentication for hiveserver2: > {code:xml} > > hive.server2.authentication > LDAP > > > hive.server2.authentication.ldap.url > ldap://our_ldap_address > > {code} > We need to include other LDAP properties as part of hive-LDAP authentication like below: > {noformat} > a group search base -> dc=domain,dc=com > a group search filter -> member={0} > a user search base -> dc=domain,dc=com > a user search filter -> sAMAAccountName={0} > a list of valid user groups -> group1,group2,group3 > {noformat} -- This message was sent by Atlassian JIRA (v6.3.4#6332)