<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>question Re: Hadoop backup with distcp: org.apache.hadoop.security.AccessControlException: Permission denied: user=XXXX, access=EXECUTE in Support Questions</title>
    <link>https://community.cloudera.com/t5/Support-Questions/Hadoop-backup-with-distcp-org-apache-hadoop-security/m-p/304070#M221867</link>
    <description>&lt;P&gt;Thank you for your answers, but we have been doing som digging and it looks like the operation with distcp bypass the Ranger policy and use HDFS ACL instead.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have a Ranger allow policy that says that the user XXXXX can read and execute&amp;nbsp; in /* . But in the audit log we get an EXECUTE access denied to:&lt;/P&gt;&lt;P&gt;/databank&lt;/P&gt;&lt;P&gt;Access enforcer:hadoop-acl&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;and a READ access denied to:&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;/databank/.snapshot/databank_201...&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Access enforcer: hadoop-acl&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Moreover, we have a directory where the backup succeed because it has POSIX permissions read and execute for others and other with rwx permissions for the owner only that fail equally.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;But should it not Ranger Policy apply and override the HDFS POSIX permissions? It looks like that what happens is the opposite, HDFS permissions override Ranger policy.&lt;/P&gt;&lt;P&gt;Brgds, Paz&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 08 Oct 2020 11:48:34 GMT</pubDate>
    <dc:creator>pazufst</dc:creator>
    <dc:date>2020-10-08T11:48:34Z</dc:date>
  </channel>
</rss>

