<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>question Re: How to create a role admin user / priviledge in Support Questions</title>
    <link>https://community.cloudera.com/t5/Support-Questions/How-to-create-a-role-admin-user-priviledge/m-p/59177#M14447</link>
    <description>&lt;P&gt;Using cloudera manager goto Sentry-&amp;gt;Configurations&lt;/P&gt;&lt;P&gt;Add users/groups to following property to allow them create/show roles. Smaller fonts are property name in the configuration file while regular fonts are display name of the property in the CM.&lt;/P&gt;&lt;DIV class="param-spec-property"&gt;&lt;DIV class="header-column"&gt;&lt;DIV class="display-name"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class="display-name"&gt;Admin Groups&lt;/DIV&gt;&lt;DIV class="property-name"&gt;&lt;FONT size="2"&gt;sentry.service.admin.group&lt;/FONT&gt;&lt;/DIV&gt;&lt;DIV class="property-name"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class="property-name"&gt;&lt;DIV class="param-spec-property"&gt;&lt;DIV class="header-column"&gt;&lt;DIV class="display-name"&gt;Allowed Connecting Users&lt;/DIV&gt;&lt;DIV class="property-name"&gt;&lt;FONT size="2"&gt;sentry.service.allow.connect&lt;/FONT&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class="property-name"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
    <pubDate>Thu, 24 Aug 2017 16:36:55 GMT</pubDate>
    <dc:creator>sunilosunil</dc:creator>
    <dc:date>2017-08-24T16:36:55Z</dc:date>
    <item>
      <title>How to create a role admin user / priviledge</title>
      <link>https://community.cloudera.com/t5/Support-Questions/How-to-create-a-role-admin-user-priviledge/m-p/58721#M14443</link>
      <description>&lt;P&gt;Even though user has ALL priviledges with grant option set to true, can not create /show roles.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;How to create a role/ assign priviledge to create/show roles to a user/group ?&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My set up CDH 5.12. Impala with Sentry (service) enabled.&lt;/P&gt;&lt;PRE&gt;[myserver.com:21000] &amp;gt; version;

Shell version: Impala Shell v2.9.0-cdh5.12.0 (03c6ddb) built on Thu Jun 29 04:17:31 PDT 2017
Server version: impalad version 2.9.0-cdh5.12.0 RELEASE (build 03c6ddbdcec39238be4f5b14a300d5c4f576097e)&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Roles and users set up&lt;/P&gt;&lt;PRE&gt;[myserver.com:21000] &amp;gt; show grant role admin;
Query: show grant role admin
+--------+----------+-------+--------+-----+-----------+--------------+-------------------------------+
| scope  | database | table | column | uri | privilege | grant_option | create_time                   |
+--------+----------+-------+--------+-----+-----------+--------------+-------------------------------+
| SERVER |          |       |        |     | ALL       | true         | Fri, Aug 11 2017 05:55:28.694 |
+--------+----------+-------+--------+-----+-----------+--------------+-------------------------------+
Fetched 1 row(s) in 0.01s&lt;BR /&gt;&lt;BR /&gt;[myserver.com:21000] &amp;gt; show current roles;&lt;BR /&gt;Query: show current roles&lt;BR /&gt;+--------------+&lt;BR /&gt;| role_name&amp;nbsp;&amp;nbsp;&amp;nbsp; |&lt;BR /&gt;+--------------+&lt;BR /&gt;| admin&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; |&lt;BR /&gt;+--------------+&lt;BR /&gt;Fetched 1 row(s) in 0.01s&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;FONT color="#993300"&gt;&lt;STRONG&gt;Exception when user tries to run show roles or create roles.&lt;BR /&gt;&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;PRE&gt;[myserver.com:21000] &amp;gt;show roles;
Query: show roles
&lt;FONT color="#993300"&gt;ERROR: &lt;STRONG&gt;AuthorizationException&lt;/STRONG&gt;: User 'sunil' does not have privileges to access the requested policy metadata or Sentry Service is unavailable.&lt;/FONT&gt;&lt;/PRE&gt;</description>
      <pubDate>Fri, 16 Sep 2022 12:04:49 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/How-to-create-a-role-admin-user-priviledge/m-p/58721#M14443</guid>
      <dc:creator>sunilosunil</dc:creator>
      <dc:date>2022-09-16T12:04:49Z</dc:date>
    </item>
    <item>
      <title>Re: How to create a role admin user / priviledge</title>
      <link>https://community.cloudera.com/t5/Support-Questions/How-to-create-a-role-admin-user-priviledge/m-p/58786#M14444</link>
      <description>&lt;P&gt;We're blocked here. Is there a way to make any other users besides Impala, Hive role admin ? i.e. grant access to&amp;nbsp; show and create roles ?&lt;/P&gt;</description>
      <pubDate>Sat, 12 Aug 2017 06:13:25 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/How-to-create-a-role-admin-user-priviledge/m-p/58786#M14444</guid>
      <dc:creator>sunilosunil</dc:creator>
      <dc:date>2017-08-12T06:13:25Z</dc:date>
    </item>
    <item>
      <title>Re: How to create a role admin user / priviledge</title>
      <link>https://community.cloudera.com/t5/Support-Questions/How-to-create-a-role-admin-user-priviledge/m-p/58795#M14445</link>
      <description>&lt;P&gt;1 . Check the policy file&amp;nbsp;&lt;/P&gt;&lt;P&gt;2 . Check if the user "sunil " is in Impala group .&lt;/P&gt;&lt;P&gt;if nothing helps&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;to dig more use the safety valve to enable log4j root logger&amp;nbsp;&lt;/P&gt;&lt;P&gt;and share the logs if you can&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;log4j.logger.org.apache.sentry=DEBUG&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 12 Aug 2017 12:20:31 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/How-to-create-a-role-admin-user-priviledge/m-p/58795#M14445</guid>
      <dc:creator>csguna</dc:creator>
      <dc:date>2017-08-12T12:20:31Z</dc:date>
    </item>
    <item>
      <title>Re: How to create a role admin user / priviledge</title>
      <link>https://community.cloudera.com/t5/Support-Questions/How-to-create-a-role-admin-user-priviledge/m-p/58994#M14446</link>
      <description>&lt;P&gt;I'm using Sentry service using Cloudera manager. I just realized that I can other users / groups to sentry config in cloudera manager and allow them to run Grant / Create role commands.&lt;/P&gt;</description>
      <pubDate>Fri, 18 Aug 2017 07:31:07 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/How-to-create-a-role-admin-user-priviledge/m-p/58994#M14446</guid>
      <dc:creator>sunilosunil</dc:creator>
      <dc:date>2017-08-18T07:31:07Z</dc:date>
    </item>
    <item>
      <title>Re: How to create a role admin user / priviledge</title>
      <link>https://community.cloudera.com/t5/Support-Questions/How-to-create-a-role-admin-user-priviledge/m-p/59177#M14447</link>
      <description>&lt;P&gt;Using cloudera manager goto Sentry-&amp;gt;Configurations&lt;/P&gt;&lt;P&gt;Add users/groups to following property to allow them create/show roles. Smaller fonts are property name in the configuration file while regular fonts are display name of the property in the CM.&lt;/P&gt;&lt;DIV class="param-spec-property"&gt;&lt;DIV class="header-column"&gt;&lt;DIV class="display-name"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class="display-name"&gt;Admin Groups&lt;/DIV&gt;&lt;DIV class="property-name"&gt;&lt;FONT size="2"&gt;sentry.service.admin.group&lt;/FONT&gt;&lt;/DIV&gt;&lt;DIV class="property-name"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class="property-name"&gt;&lt;DIV class="param-spec-property"&gt;&lt;DIV class="header-column"&gt;&lt;DIV class="display-name"&gt;Allowed Connecting Users&lt;/DIV&gt;&lt;DIV class="property-name"&gt;&lt;FONT size="2"&gt;sentry.service.allow.connect&lt;/FONT&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class="property-name"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Thu, 24 Aug 2017 16:36:55 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/How-to-create-a-role-admin-user-priviledge/m-p/59177#M14447</guid>
      <dc:creator>sunilosunil</dc:creator>
      <dc:date>2017-08-24T16:36:55Z</dc:date>
    </item>
  </channel>
</rss>

