<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>question Re: How to restrict a hadoop user to use a hadoop commands like &amp;quot;chmod, chown or rm&amp;quot; ? (Without using ACLs, Ranger or Kerberos) in Support Questions</title>
    <link>https://community.cloudera.com/t5/Support-Questions/How-to-restrict-a-hadoop-user-to-use-a-hadoop-commands-like/m-p/211256#M173198</link>
    <description>&lt;P&gt;I use freeIPA for the hadoop user auth. It is very easy to do such things in freeIPA.&lt;/P&gt;&lt;P&gt;You can refer example-13 of this document &lt;A href="https://docs.fedoraproject.org/en-US/Fedora/17/html/FreeIPA_Guide/defining-sudorules.html" target="_blank"&gt;https://docs.fedoraproject.org/en-US/Fedora/17/html/FreeIPA_Guide/defining-sudorules.html&lt;/A&gt;&lt;/P&gt;Example 13.2. Allowing and Denying Commands&lt;P&gt;The &lt;CODE&gt;sudo&lt;/CODE&gt; rule can grant access or deny access to commands. For example, this rule would allow read access to files but prevent editing:
&lt;/P&gt;&lt;PRE&gt;$ ipa sudorule-add-allow-command --sudocmd "/usr/bin/less" readfiles
$ ipa sudorule-add-allow-command --sudocmd "/usr/bin/tail" readfiles
$ ipa sudorule-add-deny-command --sudocmd "/usr/bin/vim" readfiles&lt;/PRE&gt;</description>
    <pubDate>Tue, 07 Aug 2018 17:14:51 GMT</pubDate>
    <dc:creator>76_subhasis</dc:creator>
    <dc:date>2018-08-07T17:14:51Z</dc:date>
  </channel>
</rss>

