Uploaded image for project: 'Ambari'
  1. Ambari
  2. AMBARI-21873

Grant admin privileges to users belonging to specific LDAP groups during LDAP sync

    XMLWordPrintableJSON

Details

    • Improvement
    • Status: Resolved
    • Major
    • Resolution: Fixed
    • 2.5.0
    • 2.6.0
    • ambari-server
    • None

    Description

      This feature adds the possibility to handle users belonging to a defined LDAP groups as ambari administrators during the LDAP sync.

      The list of the groups that need to be considered is stored in the ambari property:

      authorization.ldap.adminGroupMappingRules
      

      The solution is to grant admin privileges to users belonging to these groups on LDPA sync.

      Warning:

      • changes in the LDAP group memberships will not be reflected in Ambari after the sync (eg.: administrator privileges won't be automatically revoked if users are removed from the groups listed in the property)
      • administrator privileges can be granted/removed by another administrator, thus these actions can interfere
      • if groups are not synced, this property is not taken into account

      Attachments

        1. AMBARI-21873.branch-2.6.v1.patch
          7 kB
          Laszlo Puskas
        2. AMBARI-21873.trunk.v2.patch
          7 kB
          Laszlo Puskas

        Issue Links

          Activity

            People

              lpuskas Laszlo Puskas
              lpuskas Laszlo Puskas
              Votes:
              0 Vote for this issue
              Watchers:
              2 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved:

                Time Tracking

                  Estimated:
                  Original Estimate - 48h
                  48h
                  Remaining:
                  Remaining Estimate - 48h
                  48h
                  Logged:
                  Time Spent - Not Specified
                  Not Specified