This is the documentation for CDH 5.1.0.
Documentation for other versions is available at Cloudera Documentation.

Appendix I - Configuring LDAP Group Mappings

To Set up LDAP (AD) group mappings for Hadoop, add the following properties to the core-site.xml on the NameNode:
<property>    
<name>hadoop.security.group.mapping</name>
<value>org.apache.hadoop.security.LdapGroupsMapping</value>  
</property>  

<property>
<name>hadoop.security.group.mapping.ldap.url</name>
<value>ldap://server</value>  
</property>  

<property>
<name>hadoop.security.group.mapping.ldap.bind.user</name>
<value>Administrator@cloudera-ad.local</value>
</property>  

<property>
<name>hadoop.security.group.mapping.ldap.bind.password</name>    
<value>****</value>
</property>  

<property>
<name>hadoop.security.group.mapping.ldap.base</name>
<value>dc=cloudera-ad,dc=local</value>  
</property>  

<property>
<name>hadoop.security.group.mapping.ldap.search.filter.user</name>
<value>(&amp;(objectClass=user)(sAMAccountName={0}))</value>  
</property>  

<property>
<name>hadoop.security.group.mapping.ldap.search.filter.group</name>  
<value>(objectClass=group)</value>  
</property>  

<property>
<name>hadoop.security.group.mapping.ldap.search.attr.member</name>    
<value>member</value>
</property>  

<property>
<name>hadoop.security.group.mapping.ldap.search.attr.group.name</name>    
<value>cn</value>
</property>
Ensure all your services are registered users in LDAP.
  Note: In addition:
  • If you are using Sentry with Hive, you will also need to add these properties on the HiveServer2 node.
  • If you are using Sentry with Impala, add these properties on all hosts
See Users and Groups in Sentry for more information.