LDAP authentication in StarRocks

StarRocks supports authentication through an external LDAP service. It can be configured for Frontend (FE) nodes and used by StarRocks clients that connect through the MySQL protocol.

The procedure uses the following authentication flow:

  1. The client sends the StarRocks username and password to the FE.

  2. StarRocks searches the LDAP directory for the user using the configured user search attribute.

  3. StarRocks obtains the user’s DN and binds to LDAP using this DN and the password supplied by the user.

  4. If LDAP authentication succeeds, StarRocks authenticates the user and applies the privileges assigned to the corresponding StarRocks user.

Enable LDAP

To enable LDAP authentication, follow the steps below in ADCM:

  1. On the Clusters page, select your ADH cluster and proceed to the Services tab in the cluster menu.

  2. Select the StarRocks service and activate the Enable LDAP parameter group.

  3. Fill in the LDAP parameters for Active Directory and restart StarRocks.

LDAP Active Directory configuration
LDAP AD configuration

For the configuration described in this example, the following values are used:

Parameter Description Value

authentication_ldap_simple_server_host

Hostname of the Active Directory LDAP server. In this example, the server contains the ffedorov user

ad01.adsw.io

authentication_ldap_simple_server_port

LDAP service port

389

authentication_ldap_simple_ssl_conn_allow_insecure

Allows an unencrypted LDAP connection

true

authentication_ldap_simple_bind_base_dn

Base DN used to search for users

ou=Peoples,dc=ad,dc=ranger-test

authentication_ldap_simple_user_search_attr

Active Directory attribute containing the user’s login name

sAMAccountName

authentication_ldap_simple_bind_root_dn

DN of the account used by StarRocks to search for users

cn=admin,dc=ad,dc=ranger-test

authentication_ldap_simple_bind_root_pwd

Password of the LDAP bind account

<LDAP_bind_password>

IMPORTANT

Do not specify authentication_ldap_simple_bind_dn_pattern when using the Active Directory configuration above.

CAUTION

This example uses authentication_ldap_simple_ssl_conn_allow_insecure=true, which allows unencrypted communication between StarRocks and LDAP. For production environments, configure LDAP over SSL/TLS and set authentication_ldap_simple_ssl_conn_allow_insecure=false. When required, configure the LDAP server CA certificate using authentication_ldap_simple_ssl_conn_trust_store_path.

Create a StarRocks user for LDAP authentication

LDAP authentication does not automatically create a StarRocks user when using the native-user authentication model.

  1. Create the corresponding StarRocks user and specify authentication_ldap_simple as the authentication method.

    For example:

    CREATE USER 'ffedorov' IDENTIFIED WITH authentication_ldap_simple;

    The CREATE USER statement creates a StarRocks user, while the authentication_ldap_simple authentication method instructs StarRocks to authenticate this user through LDAP.

    The Active Directory password is not specified in this statement. The user provides this password when connecting to StarRocks, and StarRocks uses it to authenticate the user against LDAP.

    The StarRocks username must correspond to the value of the configured LDAP user search attribute.

    For Active Directory, the example uses sAMAccountName=ffedorov.

  2. After creating the LDAP-authenticated StarRocks user, grant the required StarRocks privileges.

    For example, to allow ffedorov to query all tables in the starrocks_demo database in StarRocks:

    GRANT SELECT ON ALL TABLES IN DATABASE starrocks_demo TO USER 'ffedorov';

Check the LDAP configuration

First, check that the StarRocks user is configured to use LDAP authentication.

  1. Connect to StarRocks using an administrative account and run:

    SHOW AUTHENTICATION;

    The output contains authentication information for StarRocks users. For an LDAP-authenticated user, the AuthPlugin column contains AUTHENTICATION_LDAP_SIMPLE.

    For example:

    ┌────────────────┬──────────┬────────────────────────────┬───────────────────┐
    │ UserIdentity   │ Password │ AuthPlugin                 │ UserForAuthPlugin │
    ├────────────────┼──────────┼────────────────────────────┼───────────────────┤
    │ 'ffedorov'@'%' │ No       │ AUTHENTICATION_LDAP_SIMPLE │ NULL              │
    └────────────────┴──────────┴────────────────────────────┴───────────────────┘
  2. Check LDAP authentication using the MySQL client.

    StarRocks LDAP authentication requires the client to provide the password using the mysql_clear_password authentication plugin. When using the MySQL client, enable this plugin as follows:

    $ mysql
        -h <host name>
        -P <mysql port>
        -u <LDAP user name>
        -p
        --default-auth mysql_clear_password
        --enable-cleartext-plugin

    For example:

    $ mysql -h starrocks-desc-1.ru-central1.internal -P 19030 -u ffedorov -p --default-auth mysql_clear_password --enable-cleartext-plugin

    Enter the Active Directory password for ffedorov when prompted.

    If authentication succeeds, the MySQL client opens a StarRocks session.

  3. Verify the authenticated user:

    SELECT CURRENT_USER();

    Verify that the user can access the database for which privileges were granted:

    USE starrocks_demo;
    SHOW TABLES;

Security integrations

The procedure in this article uses a StarRocks user explicitly created with authentication_ldap_simple. StarRocks also supports LDAP security integrations, which can authenticate external users without creating each user as a persistent StarRocks user. The security integration approach is configured separately and is intended for a different user management model.

Found a mistake? Seleсt text and press Ctrl+Enter to report it