<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>question Re: HiveAccessControlException: Permission denied: user [...] does not have [READ] privilege on [s3a: in Support Questions</title>
    <link>https://community.cloudera.com/t5/Support-Questions/HiveAccessControlException-Permission-denied-user-does-not/m-p/336065#M232120</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/74887"&gt;@aakulov&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thanks for your reply.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In the last few days we had it fixed, thanks to CE support' help.&lt;/P&gt;&lt;P&gt;Not sure why, but he decided to reinstall Hive from scratch,&amp;nbsp; and replace it with **Hive_on_Tez**.&lt;/P&gt;&lt;P&gt;The sqoop commands now seems to run fine, after updating the --hs2-url parameter accordingly (and upon regeneration of kerberos tickets for hive)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thanks anyway for your suggestions -- hope my answer will be useful to someone&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;kind regards,&lt;/P&gt;&lt;P&gt;gr&lt;/P&gt;</description>
    <pubDate>Fri, 11 Feb 2022 09:11:14 GMT</pubDate>
    <dc:creator>grlzz</dc:creator>
    <dc:date>2022-02-11T09:11:14Z</dc:date>
    <item>
      <title>HiveAccessControlException: Permission denied: user [...] does not have [READ] privilege on [s3a:</title>
      <link>https://community.cloudera.com/t5/Support-Questions/HiveAccessControlException-Permission-denied-user-does-not/m-p/335655#M231990</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;i am having the error message in the title, but I am stuck as I have already checked the followings:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;* ranger permissions: cm_s3 / all - bucket, path -- the user in the the list for read / write / all permissions&lt;/P&gt;
&lt;P&gt;* IDBroker role: user has a cdp-datalake-admin-role, which has a cdp-datalake-admin-policy-s3access&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;any other idea and what to check?&lt;/P&gt;
&lt;P&gt;thanks&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 21 Apr 2026 08:01:33 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/HiveAccessControlException-Permission-denied-user-does-not/m-p/335655#M231990</guid>
      <dc:creator>grlzz</dc:creator>
      <dc:date>2026-04-21T08:01:33Z</dc:date>
    </item>
    <item>
      <title>Re: HiveAccessControlException: Permission denied: user [...] does not have [READ] privilege on [s3a:</title>
      <link>https://community.cloudera.com/t5/Support-Questions/HiveAccessControlException-Permission-denied-user-does-not/m-p/336024#M232104</link>
      <description>&lt;P&gt;&lt;SPAN&gt;HiveAccessControlException suggests you are accessing this s3 location through a SQL engine (Hive or Impala perhaps). Check in Ranger, under Hadoop SQL, if the policies are set properly there to access the table you are looking at.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Also, is this a &lt;A href="https://docs.cloudera.com/management-console/cloud/fine-grained-access-control-aws/topics/raz-aws-intro.html" target="_self"&gt;RAZ-enabled environment&lt;/A&gt;, by any chance? If it is, please see here for RAZ setup specific to Hive table access:&amp;nbsp;&lt;A href="https://docs.cloudera.com/management-console/cloud/fine-grained-access-control-aws/topics/raz-aws-create-ranger-policies.html" target="_blank"&gt;https://docs.cloudera.com/management-console/cloud/fine-grained-access-control-aws/topics/raz-aws-create-ranger-policies.html&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Hope this helps,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Alex&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 11 Feb 2022 00:42:18 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/HiveAccessControlException-Permission-denied-user-does-not/m-p/336024#M232104</guid>
      <dc:creator>aakulov</dc:creator>
      <dc:date>2022-02-11T00:42:18Z</dc:date>
    </item>
    <item>
      <title>Re: HiveAccessControlException: Permission denied: user [...] does not have [READ] privilege on [s3a:</title>
      <link>https://community.cloudera.com/t5/Support-Questions/HiveAccessControlException-Permission-denied-user-does-not/m-p/336065#M232120</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/74887"&gt;@aakulov&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thanks for your reply.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In the last few days we had it fixed, thanks to CE support' help.&lt;/P&gt;&lt;P&gt;Not sure why, but he decided to reinstall Hive from scratch,&amp;nbsp; and replace it with **Hive_on_Tez**.&lt;/P&gt;&lt;P&gt;The sqoop commands now seems to run fine, after updating the --hs2-url parameter accordingly (and upon regeneration of kerberos tickets for hive)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thanks anyway for your suggestions -- hope my answer will be useful to someone&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;kind regards,&lt;/P&gt;&lt;P&gt;gr&lt;/P&gt;</description>
      <pubDate>Fri, 11 Feb 2022 09:11:14 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/HiveAccessControlException-Permission-denied-user-does-not/m-p/336065#M232120</guid>
      <dc:creator>grlzz</dc:creator>
      <dc:date>2022-02-11T09:11:14Z</dc:date>
    </item>
  </channel>
</rss>

