Supported Authentication Methods

Hadoop外部データラッパーは、 NOSASL および LDAP 認証モードをサポートしています。 NOSASL を使用するには、ユーザマッピングの作成中に OPTIONS を指定しないでください。 LDAP 認証モードの場合、ユーザマッピングの作成時に OPTIONS に username および password を指定します。

LDAP認証を使用する

LDAP 認証でHadoop外部データラッパーを使用する場合、最初に Hive Server または Spark Server を設定してLDAP認証を使用する必要があります。構成されたサーバーは、LDAPサーバーの接続詳細を含む hive-site.xml ファイルを提供する必要があります。例:

<property>
  <name>hive.server2.authentication</name>
  <value>LDAP</value>
  <description>
    Expects one of [nosasl, none, ldap, kerberos, pam, custom].
    Client authentication types.
      NONE: no authentication check
      LDAP: LDAP/AD based authentication
      KERBEROS: Kerberos/GSSAPI authentication
      CUSTOM: Custom authentication provider
              (Use with property hive.server2.custom.authentication.class)
      PAM: Pluggable authentication module
      NOSASL:  Raw transport
  </description>
</property>
<property>
  <name>hive.server2.authentication.ldap.url</name>
  <value>ldap://localhost</value>
  <description>LDAP connection URL</description>
</property>
<property>
  <name>hive.server2.authentication.ldap.baseDN</name>
  <value>ou=People,dc=itzgeek,dc=local</value>
  <description>LDAP base DN</description>
</property>

次に、ハイブサーバーを起動するときに、コマンドに hive-site.xml ファイルへのパスを含めます。例:

./hive --config path_to_hive-site.xml_file --service hiveServer2

path_to_hive-site.xml_file は、 hive‑site.xml ファイルへの完全なパスを指定します。

ユーザマッピングを作成するときは、登録済みLDAPユーザの名前と対応するパスワードをオプションとして指定する必要があります。詳細については、 ユーザーマッピングの作成 を参照してください。

NOSASL認証の使用

Hadoop外部データラッパーで NOSASL 認証を使用する場合、 Hive Server または Spark Server で認証を None に、認証メソッドを NOSASL に設定します。あなたは、コマンドラインで Hive Server をスタートた場合、コマンドで hive.server2.authentication 設定パラメータが含まれます。

hive --service hiveserver2 --hiveconf hive.server2.authentication=NOSASL