Supported Authentication Methods¶
Hadoop外部データラッパーは、 NOSASL および LDAP 認証モードをサポートしています。 NOSASL を使用するには、ユーザマッピングの作成中に OPTIONS を指定しないでください。 LDAP 認証モードの場合、ユーザマッピングの作成時に OPTIONS に username および password を指定します。
LDAP認証を使用する¶
LDAP 認証でHadoop外部データラッパーを使用する場合、最初に Hive Server または Spark Server を設定してLDAP認証を使用する必要があります。構成されたサーバーは、LDAPサーバーの接続詳細を含む hive-site.xml ファイルを提供する必要があります。例:
<property>
<name>hive.server2.authentication</name>
<value>LDAP</value>
<description>
Expects one of [nosasl, none, ldap, kerberos, pam, custom].
Client authentication types.
NONE: no authentication check
LDAP: LDAP/AD based authentication
KERBEROS: Kerberos/GSSAPI authentication
CUSTOM: Custom authentication provider
(Use with property hive.server2.custom.authentication.class)
PAM: Pluggable authentication module
NOSASL: Raw transport
</description>
</property>
<property>
<name>hive.server2.authentication.ldap.url</name>
<value>ldap://localhost</value>
<description>LDAP connection URL</description>
</property>
<property>
<name>hive.server2.authentication.ldap.baseDN</name>
<value>ou=People,dc=itzgeek,dc=local</value>
<description>LDAP base DN</description>
</property>
次に、ハイブサーバーを起動するときに、コマンドに hive-site.xml ファイルへのパスを含めます。例:
./hive --config path_to_hive-site.xml_file --service hiveServer2
path_to_hive-site.xml_file は、 hive‑site.xml ファイルへの完全なパスを指定します。
ユーザマッピングを作成するときは、登録済みLDAPユーザの名前と対応するパスワードをオプションとして指定する必要があります。詳細については、 ユーザーマッピングの作成 を参照してください。
NOSASL認証の使用¶
Hadoop外部データラッパーで NOSASL 認証を使用する場合、 Hive Server または Spark Server で認証を None に、認証メソッドを NOSASL に設定します。あなたは、コマンドラインで Hive Server をスタートた場合、コマンドで hive.server2.authentication 設定パラメータが含まれます。
hive --service hiveserver2 --hiveconf hive.server2.authentication=NOSASL