Connect to LDAP Objects as an External Data Source using PolyBase
PolyBase for SQL Server allows you to query external data by using the same Transact-SQL syntax used to query a database table. When paired with the CData ODBC Driver for LDAP, you get access to your LDAP objects directly alongside your SQL Server data. This article describes creating an external data source and external tables to grant access to live LDAP objects using T-SQL queries.
NOTE: PolyBase is only available on SQL Server 19 and above.
CData Connect AI provides a pure SQL Server interface for LDAP, allowing you to query data from LDAP without replicating the data to a natively supported database. Using optimized data processing out of the box, CData Connect AI pushes all supported SQL operations (filters, JOINs, etc.) directly to LDAP, leveraging server-side processing to return the requested LDAP objects quickly.
Configure LDAP Connectivity for PolyBase
Connectivity to LDAP from PolyBase is made possible through CData Connect AI. To work with LDAP objects from PolyBase, we start by creating and configuring a LDAP connection.
- Log into Connect AI, click Sources, and then click Add Connection
- Select "LDAP" from the Add Connection panel
-
Enter the necessary authentication properties to connect to LDAP.
To establish a connection, the following properties under the Authentication section must be provided:
- Valid User and Password credentials (e.g., Domain\BobF or cn=Bob F,ou=Employees,dc=Domain).
- Server information, including the IP or host name of the Server, as well as the Port.
BaseDN: This will limit the scope of LDAP searches to the height of the distinguished name provided.
Note: Specifying a narrow BaseDN may greatly increase performance; for example, cn=users,dc=domain will only return results contained within cn=users and its children.
- Click Save & Test
-
Navigate to the Permissions tab in the Add LDAP Connection page and update the User-based permissions.
Add a Personal Access Token
When connecting to Connect AI through the REST API, the OData API, or the Virtual SQL Server, a Personal Access Token (PAT) is used to authenticate the connection to Connect AI. It is best practice to create a separate PAT for each service to maintain granularity of access.
- Click on the Gear icon () at the top right of the Connect AI app to open the settings page.
- On the Settings page, go to the Access Tokens section and click Create PAT.
-
Give the PAT a name and click Create.
- The personal access token is only visible at creation, so be sure to copy it and store it securely for future use.
With the connection configured and a PAT generated, you are ready to connect to LDAP objects from Polybase.
Create an External Data Source for LDAP Objects
After configuring the connection, you need to create a credential database for the external data source.
Creating a Credential Database
Execute the following SQL command to create credentials for the external data source connected to LDAP objects.
NOTE: Set IDENTITY to your Connect AI username and set SECRET to your Personal Access Token.
CREATE DATABASE SCOPED CREDENTIAL ConnectCloudCredentials WITH IDENTITY = 'yourusername', SECRET = 'yourPAT';
Create an External Data Source for LDAP
Execute a CREATE EXTERNAL DATA SOURCE SQL command to create an external data source for LDAP with PolyBase:
CREATE EXTERNAL DATA SOURCE ConnectCloudInstance WITH ( LOCATION = 'sqlserver://tds.cdata.com:14333', PUSHDOWN = ON, CREDENTIAL = ConnectCloudCredentials );
Create External Tables for LDAP
After creating the external data source, use CREATE EXTERNAL TABLE statements to link to LDAP objects from your SQL Server instance. The table column definitions must match those exposed by CData Connect AI. You can use the Data Explorer in Connect AI to see the table definition.
Sample CREATE TABLE Statement
Execute a CREATE EXTERNAL TABLE SQL command to create the external table(s), using the collation and setting the LOCATION to three-part notation for the connection, catalog, and table. The statement to create an external table based on a LDAP User would look similar to the following.
CREATE EXTERNAL TABLE User( Id COLLATE [nvarchar](255) NULL, LogonCount COLLATE [nvarchar](255) NULL, ... ) WITH ( LOCATION='LDAP1.LDAP.User', DATA_SOURCE=ConnectCloudInstance );
Having created external tables for LDAP in your SQL Server instance, you are now able to query local and remote data simultaneously. To get live data access to hundreds of SaaS, Big Data, and NoSQL sources directly from your SQL Server database, try CData Connect AI today!