Uploaded image for project: 'Ambari'
  1. Ambari
  2. AMBARI-24045

Ambari schedule LDAP user/group sync to occur periodically instead of requiring manual CLI command with admin creds

    XMLWordPrintableJSON

Details

    • Improvement
    • Status: Open
    • Major
    • Resolution: Unresolved
    • 2.6.0
    • None
    • ambari-server, security
    • None
    • HDP 2.6

    Description

      Request to add LDAP user/group sync scheduling to occur automatically periodically (eg. hourly) rather than requiring a manual external CLI ambari sync-ldap command which prompts for admin creds which is less safe to schedule (as it would require embedding admin creds somewhere and in secure audited environments without the generic 'admin' account this would mean some admin's personal credentials).

      Right now Ambari is a sticking point in environments where everything is AD integrated as it is the only thing that doesn't pick up the new user in a group - it waits until one can find somebody with the right admin creds to grant a new admin access they should automatically inherit to Ambari via group memberships.

      Attachments

        Activity

          People

            Unassigned Unassigned
            harisekhon Hari Sekhon
            Votes:
            0 Vote for this issue
            Watchers:
            2 Start watching this issue

            Dates

              Created:
              Updated: