kylin-commits mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From billy...@apache.org
Subject kylin git commit: Modify the LDAP config in v2.3.
Date Mon, 12 Feb 2018 06:44:22 GMT
Repository: kylin
Updated Branches:
  refs/heads/document a75d7adcd -> 04a35631e


Modify the LDAP config in v2.3.

Signed-off-by: Billy Liu <billyliu@apache.org>


Project: http://git-wip-us.apache.org/repos/asf/kylin/repo
Commit: http://git-wip-us.apache.org/repos/asf/kylin/commit/04a35631
Tree: http://git-wip-us.apache.org/repos/asf/kylin/tree/04a35631
Diff: http://git-wip-us.apache.org/repos/asf/kylin/diff/04a35631

Branch: refs/heads/document
Commit: 04a35631ed73c849cd44b0c6b9adfaa589cbefed
Parents: a75d7ad
Author: Jiatao Tao <245915794@qq.com>
Authored: Mon Feb 12 14:34:57 2018 +0800
Committer: Billy Liu <billyliu@apache.org>
Committed: Mon Feb 12 14:44:09 2018 +0800

----------------------------------------------------------------------
 website/_docs23/howto/howto_ldap_and_sso.md | 12 +++++++-----
 1 file changed, 7 insertions(+), 5 deletions(-)
----------------------------------------------------------------------


http://git-wip-us.apache.org/repos/asf/kylin/blob/04a35631/website/_docs23/howto/howto_ldap_and_sso.md
----------------------------------------------------------------------
diff --git a/website/_docs23/howto/howto_ldap_and_sso.md b/website/_docs23/howto/howto_ldap_and_sso.md
index 4083da5..b1c8bb7 100644
--- a/website/_docs23/howto/howto_ldap_and_sso.md
+++ b/website/_docs23/howto/howto_ldap_and_sso.md
@@ -36,16 +36,18 @@ ldap.user.groupSearchBase=OU=Group,DC=mycompany,DC=com
 
 If you have service accounts (e.g, for system integration) which also need be authenticated,
configure them in ldap.service.*; Otherwise, leave them be empty;
 
-### Configure the administrator group and default role
+### Configure the administrator group
 
-To map an LDAP group to the admin group in Kylin, need set the "kylin.security.acl.admin-role"
to "ROLE_" + GROUP_NAME. For example, in LDAP the group "KYLIN-ADMIN-GROUP" is the list of
administrators, here need set it as:
+To map an LDAP group to the admin group in Kylin, need set the "kylin.security.acl.admin-role"
to the LDAP group name(shall keep the original case), and the users in this group will be
global admin in Kylin.
+
+For example, in LDAP the group "KYLIN-ADMIN-GROUP" is the list of administrators, here need
set it as:
 
 ```
-kylin.security.acl.admin-role=ROLE_KYLIN-ADMIN-GROUP
-kylin.security.acl.default-role=ROLE_ANALYST,ROLE_MODELER
+kylin.security.acl.admin-role=KYLIN-ADMIN-GROUP
 ```
 
-The "kylin.security.acl.default-role" is a list of the default roles that grant to everyone,
keep it as-is.
+
+*Attention: When upgrading from Kylin 2.3 ealier version to 2.3 or later, please remove the
"ROLE_" in this setting as this required in the 2.3 earlier version and keep the group name
in original case. And the kylin.security.acl.default-role is deprecated.*
 
 #### Enable LDAP
 


Mime
View raw message