|
70 | 70 | group_filter: "(objectClass={{ auth_provider.ldap_object_class.group }})"
|
71 | 71 | group_member_attr: "{{ auth_provider.ldap_attribute.member }}"
|
72 | 72 | group_name_attr: "{{ auth_provider.ldap_attribute.group }}"
|
73 |
| - ldap_cert: "{{ auth_provider.ldap_cert | default('') }}" |
| 73 | + ldap_cert: "{{ auth_provider.ldap_cert | default(tls_chain_path) }}" |
74 | 74 | ldap_url: "{{ auth_provider.ldap_url }}"
|
75 | 75 | search_bind_authentication: true
|
76 | 76 | use_start_tls: true
|
|
90 | 90 | # SERVICEWIDE:
|
91 | 91 | # ldap.auth.url:
|
92 | 92 | # ldap.auth.user.dn.template:
|
| 93 | +NIFI: |
| 94 | + NIFI_NODE: |
| 95 | + nifi.ldap.authentication.strategy: LDAPS |
| 96 | + nifi.ldap.enabled: true |
| 97 | + nifi.ldap.manager.dn: "{{ auth_provider.ldap_bind_user_dn }}" |
| 98 | + nifi.ldap.manager.password: "{{ auth_provider.ldap_bind_password }}" |
| 99 | + nifi.ldap.tls.client.auth: NONE |
| 100 | + nifi.ldap.tls.truststore: "{{ tls_truststore_path }}" |
| 101 | + nifi.ldap.tls.truststore.password: "{{ tls_truststore_password }}" |
| 102 | + nifi.ldap.tls.truststore.type: jks |
| 103 | + nifi.ldap.url: "{{ auth_provider.ldap_url }}" |
| 104 | + nifi.ldap.user.search.base: "{{ auth_provider.ldap_search_base.user }}" |
| 105 | + nifi.ldap.tls.protocol: TLS |
| 106 | + xml.authorizers.userGroupProvider.file-user-group-provider.enabled: false |
| 107 | + xml.authorizers.authorizer.ranger-provider.property.User Group Provider: composite-user-group-provider |
| 108 | + xml.authorizers.userGroupProvider.composite-configurable-user-group-provider.enabled: false |
| 109 | + xml.authorizers.userGroupProvider.composite-user-group-provider.enabled: true |
| 110 | + xml.authorizers.userGroupProvider.composite-user-group-provider.property.User Group Provider 1: ldap-user-group-provider |
| 111 | + xml.authorizers.userGroupProvider.composite-user-group-provider.property.User Group Provider 2: cm-user-group-provider |
| 112 | + xml.authorizers.userGroupProvider.ldap-user-group-provider.property.Group Member Attribute: "{{ auth_provider.ldap_attribute.member }}" |
| 113 | + xml.authorizers.userGroupProvider.ldap-user-group-provider.property.Group Name Attribute: "{{ auth_provider.ldap_attribute.group }}" |
| 114 | + xml.authorizers.userGroupProvider.ldap-user-group-provider.property.Group Object Class: "{{ auth_provider.ldap_object_class.group }}" |
| 115 | + xml.authorizers.userGroupProvider.ldap-user-group-provider.property.Group Search Base: "{{ auth_provider.ldap_search_base.group }}" |
| 116 | + xml.authorizers.userGroupProvider.ldap-user-group-provider.property.User Group Name Attribute: "{{ auth_provider.ldap_attribute.user_member }}" |
| 117 | + xml.authorizers.userGroupProvider.ldap-user-group-provider.property.User Identity Attribute: "{{ auth_provider.ldap_attribute.user }}" |
93 | 118 | #RANGER:
|
94 | 119 | # RANGER_ADMIN:
|
95 | 120 | # ranger.ldap.ad.base.dn:
|
|
0 commit comments