Slackbot
03/06/2024, 3:22 AMTejas Parbat
03/06/2024, 10:30 AMdruid.auth.authenticatorChain=["ldap"]
druid.auth.authenticator.ldap.type=basic
druid.auth.authenticator.ldap.enableCacheNotifications=true
druid.auth.authenticator.ldap.credentialsValidator.type=ldap
druid.auth.authenticator.ldap.credentialsValidator.url=<ldap://xxx.35:389>
druid.auth.authenticator.ldap.credentialsValidator.bindUser=CN=admin,OU=support,DC=imply,DC=io
druid.auth.authenticator.ldap.credentialsValidator.bindPassword=Srk@1234
druid.auth.authenticator.ldap.credentialsValidator.baseDn=dc=imply,dc=io
druid.auth.authenticator.ldap.credentialsValidator.userSearch=(&(sAMAccountName=%s)(objectClass=user))
druid.auth.authenticator.ldap.credentialsValidator.userAttribute=sAMAccountName
druid.auth.authenticator.ldap.authorizerName=ldapauth
druid.escalator.type=basic
druid.escalator.internalClientUsername=admin
druid.escalator.internalClientPassword=xxx1234
druid.escalator.authorizerName=ldapauth
druid.auth.authorizers=["ldapauth"]
druid.auth.authorizer.ldapauth.type=basic
druid.auth.authorizer.ldapauth.initialAdminUser=admin
druid.auth.authorizer.ldapauth.initialAdminRole=admin
druid.auth.authorizer.ldapauth.roleProvider.type=ldap
Is there any more logs apart from 401 in coordinator logs? Also
In the above example, the Druid escalator and LDAP initial admin user are set to the same user - <mailto:internal@example.com|internal@example.com>. If the escalator is set to a different user, you must follow steps 4 and 5 to create the group mapping and allocate initial roles before the rest of the cluster can function.
As per your configs you have different internal client user and the initial admin user. Please make sure all steps followed
https://druid.apache.org/docs/latest/operations/auth-ldap/Nguyen Huynh
05/15/2024, 8:53 AMldapsearch command. But still got log
2024-05-15T08:37:32,439 DEBUG [HttpClient-Netty-Worker-0] org.apache.druid.java.util.http.client.NettyHttpClient - [GET <http://localhost:8081/druid-ext/basic-security/authentication/db/ldap/cachedSerializedUserMap>] Got response: 401 Unauthorized
2024-05-15T08:37:32,442 WARN [main] org.apache.druid.java.util.common.RetryUtils - Retrying (2 of 9) in 1,521ms.
com.fasterxml.jackson.core.JsonParseException: Input does not start with Smile format header (first byte = 0x3c) and parser has REQUIRE_HEADER enabled: can not parse
at [Source: (byte[])"<html>
<head>
<meta http-equiv="Content-Type" content="text/html;charset=ISO-8859-1"/>
<title>Error 401 Unauthorized</title>
</head>
<body><h2>HTTP ERROR 401 Unauthorized</h2>
<table>
<tr><th>URI:</th><td>/druid-ext/basic-security/authentication/db/ldap/cachedSerializedUserMap</td></tr>
<tr><th>STATUS:</th><td>401</td></tr>
<tr><th>MESSAGE:</th><td>Unauthorized</td></tr>
<tr><th>SERVLET:</th><td>default</td></tr>
</table>
</body>
</html>
I tried to request the URL:
http://localhost:8081/druid-ext/basic-security/authentication/db/ldap/cachedSerializedUserMap
and got the pop-up for username and password.
I tried to enter then username and password from druid.escalator.internalClientUsername & druid.escalator.internalClientPassword (admin, xxx1234)
But got the 401.
So I wonder is that the druid.escalator.internalClientUsername is using for Druid internal service? And do the druid.escalator.internalClientUsername need to exist in LDAP Group ?
ThanksTejas Parbat
05/15/2024, 9:01 AMdruid.escalator.type property determines what authentication scheme should be used for internal Druid cluster communications (such as when a Broker process communicates with Historical processes for query processing).
The Escalator chosen for this property must use an authentication scheme that is supported by an Authenticator in druid.auth.authenticatorChain. Authenticator extension implementers must also provide a corresponding Escalator implementation if they intend to use a particular authentication scheme for internal Druid communications.
https://docs.imply.io/latest/druid/operations/auth/#escalatorNguyen Huynh
05/16/2024, 9:02 AMdruid.auth.authenticatorChain=["MyBasicMetadataAuthenticator", "ldap"]
druid.auth.authenticator.MyBasicMetadataAuthenticator.type=basic
druid.auth.authenticator.MyBasicMetadataAuthenticator.initialAdminPassword=password1
druid.auth.authenticator.MyBasicMetadataAuthenticator.initialInternalClientPassword=password2
druid.auth.authenticator.MyBasicMetadataAuthenticator.credentialsValidator.type=metadata
druid.auth.authenticator.MyBasicMetadataAuthenticator.skipOnFailure=false
druid.auth.authenticator.MyBasicMetadataAuthenticator.authorizerName=MyBasicMetadataAuthorizer
#ldap
.........
# Escalator
druid.escalator.type=basic
druid.escalator.internalClientUsername=admin
druid.escalator.internalClientPassword=password1
druid.escalator.authorizerName=MyBasicMetadataAuthorizer
druid.auth.authorizers=["MyBasicMetadataAuthorizer"]
druid.auth.authorizer.MyBasicMetadataAuthorizer.type=basic
my purpose is only use ldap credential for allow user login to the web console.
Do my config correct ?