<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>question Can someone help me understand Knox impersonation in Support Questions</title>
    <link>https://community.cloudera.com/t5/Support-Questions/Can-someone-help-me-understand-Knox-impersonation/m-p/232628#M194466</link>
    <description>&lt;P&gt;I have user as 'knox' on hadoop cluster (Kerberos enabled). I am running Demo LDAP for Knox authentication. &lt;/P&gt;&lt;P&gt;My proxy settings in core-site.xml:&lt;/P&gt;&lt;P&gt;hadoop.proxyuser.knox.groups = users&lt;/P&gt;&lt;P&gt;hadoop.proxyuser.knox.hosts = [myhadoopMasterNode_Hostname]&lt;/P&gt;&lt;P&gt;Now I am trying to run curl command using username 'guest' and pwd 'guest-password' from users.ldif file. &lt;/P&gt;&lt;P&gt;This is giving error: knox is not able to impersonate guest.&lt;/P&gt;&lt;P&gt;Then I changed this property: hadoop.proxyuser.knox.groups=*.  I am able to run curl command successfully.&lt;/P&gt;&lt;P&gt;Please help me understand two things:&lt;/P&gt;&lt;P&gt;1) How this property(hadoop.proxyuser.knox.groups) setting is working&amp;gt;&lt;/P&gt;&lt;P&gt;2) Can identity-assertion property in topology file can help resolving this same issue?&lt;/P&gt;</description>
    <pubDate>Wed, 25 Oct 2017 01:57:05 GMT</pubDate>
    <dc:creator>nhgodwal</dc:creator>
    <dc:date>2017-10-25T01:57:05Z</dc:date>
    <item>
      <title>Can someone help me understand Knox impersonation</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Can-someone-help-me-understand-Knox-impersonation/m-p/232628#M194466</link>
      <description>&lt;P&gt;I have user as 'knox' on hadoop cluster (Kerberos enabled). I am running Demo LDAP for Knox authentication. &lt;/P&gt;&lt;P&gt;My proxy settings in core-site.xml:&lt;/P&gt;&lt;P&gt;hadoop.proxyuser.knox.groups = users&lt;/P&gt;&lt;P&gt;hadoop.proxyuser.knox.hosts = [myhadoopMasterNode_Hostname]&lt;/P&gt;&lt;P&gt;Now I am trying to run curl command using username 'guest' and pwd 'guest-password' from users.ldif file. &lt;/P&gt;&lt;P&gt;This is giving error: knox is not able to impersonate guest.&lt;/P&gt;&lt;P&gt;Then I changed this property: hadoop.proxyuser.knox.groups=*.  I am able to run curl command successfully.&lt;/P&gt;&lt;P&gt;Please help me understand two things:&lt;/P&gt;&lt;P&gt;1) How this property(hadoop.proxyuser.knox.groups) setting is working&amp;gt;&lt;/P&gt;&lt;P&gt;2) Can identity-assertion property in topology file can help resolving this same issue?&lt;/P&gt;</description>
      <pubDate>Wed, 25 Oct 2017 01:57:05 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Can-someone-help-me-understand-Knox-impersonation/m-p/232628#M194466</guid>
      <dc:creator>nhgodwal</dc:creator>
      <dc:date>2017-10-25T01:57:05Z</dc:date>
    </item>
    <item>
      <title>Re: Can someone help me understand Knox impersonation</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Can-someone-help-me-understand-Knox-impersonation/m-p/232629#M194467</link>
      <description>&lt;P&gt;This is because 'guest' user in the Demo Ldap does not belong to group "users". For this to work you should create a group "users" in the demo ldap (users.ldif) and add guest user to it. You could try to impersonate 'guest' to a user who belongs to 'users' group on the machine.&lt;/P&gt;</description>
      <pubDate>Thu, 26 Oct 2017 01:28:58 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Can-someone-help-me-understand-Knox-impersonation/m-p/232629#M194467</guid>
      <dc:creator>smore</dc:creator>
      <dc:date>2017-10-26T01:28:58Z</dc:date>
    </item>
  </channel>
</rss>

