[ https://issues.apache.org/jira/browse/HIVE-7193?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=14592984#comment-14592984 ]
Naveen Gangam commented on HIVE-7193: ------------------------------------- Thank you for the review. Q. Also, why is the example a comma-separated list when the description says colon-separated? A. The example shows a single pattern for users for LDAP. Each attribute in LDAP DN is separated by COMMA "CN=%s,CN=Users,DC=subdomain,DC=domain,DC=com" However, it is possible that a ldap directory could have users in different trees. The pattern for baseDN for each tree is separated by COLON. For example "CN=%s,CN=Users,DC=subdomain,DC=domain,DC=com:CN=%s,OU=IT,DC=domain,DC=com" The same is true for group patterns. Does this help? Thanks > Hive should support additional LDAP authentication parameters > ------------------------------------------------------------- > > Key: HIVE-7193 > URL: https://issues.apache.org/jira/browse/HIVE-7193 > Project: Hive > Issue Type: Bug > Affects Versions: 0.10.0 > Reporter: Mala Chikka Kempanna > Assignee: Naveen Gangam > Attachments: HIVE-7193.2.patch, HIVE-7193.3.patch, HIVE-7193.4.patch, > HIVE-7193.patch, LDAPAuthentication_Design_Doc.docx, > LDAPAuthentication_Design_Doc_V2.docx > > > Currently hive has only following authenticator parameters for LDAP > authentication for hiveserver2: > {code:xml} > <property> > <name>hive.server2.authentication</name> > <value>LDAP</value> > </property> > <property> > <name>hive.server2.authentication.ldap.url</name> > <value>ldap://our_ldap_address</value> > </property> > {code} > We need to include other LDAP properties as part of hive-LDAP authentication > like below: > {noformat} > a group search base -> dc=domain,dc=com > a group search filter -> member={0} > a user search base -> dc=domain,dc=com > a user search filter -> sAMAAccountName={0} > a list of valid user groups -> group1,group2,group3 > {noformat} -- This message was sent by Atlassian JIRA (v6.3.4#6332)