サポートされている認証方法

The Hadoop Foreign Data Wrapper supports NOSASL and LDAP authentication modes. To use NOSASL, do not specify any OPTIONS while creating user mapping. For LDAP authentication mode, specify username and password in OPTIONS while creating user mapping.

LDAP認証を使用する

HadoopForeignDataWrapperを LDAP 認証で使用する場合、最初に Hive Server または Spark Server を設定してLDAP認証を使用する必要があります。設定されたサーバーは、LDAPサーバーの接続の詳細を含む hive-site.xml ファイルを提供する必要があります。例:

<property>
  <name>hive.server2.authentication</name>
  <value>LDAP</value>
  <description>
    Expects one of [nosasl, none, ldap, kerberos, pam, custom].
    Client authentication types.
      NONE: no authentication check
      LDAP: LDAP/AD based authentication
      KERBEROS: Kerberos/GSSAPI authentication
      CUSTOM: Custom authentication provider
              (Use with property hive.server2.custom.authentication.class)
      PAM: Pluggable authentication module
      NOSASL:  Raw transport
  </description>
</property>
<property>
  <name>hive.server2.authentication.ldap.url</name>
  <value>ldap://localhost</value>
  <description>LDAP connection URL</description>
</property>
<property>
  <name>hive.server2.authentication.ldap.baseDN</name>
  <value>ou=People,dc=itzgeek,dc=local</value>
  <description>LDAP base DN</description>
</property>

次に、Hiveサーバーを起動するときに、コマンドに hive-site.xml ファイルへのパスを含めます。例:

./hive --config path_to_hive-site.xml_file --service hiveServer2

*path_to_hive-site.xml_file*は hive‑site.xml ファイルへの完全なパスを指定します。

ユーザーマッピングを作成する場合、登録済みのLDAPユーザーの名前と対応するパスワードをオプションとして指定する必要があります。詳細については、 :ref:`ユーザーマッピングの作成<create_user_mapping>`を参照してください。

NOSASL認証の使用

Hadoop外部データラッパーで NOSASL 認証を使用する場合は、 Hive Server または Spark Server で認証を None に、認証方法を NOSASL に設定します。たとえば、コマンドラインで Hive Server を起動する場合、コマンドに hive.server2.authentication 構成パラメーターを含めます。

hive --service hiveserver2 --hiveconf hive.server2.authentication=NOSASL