<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>question Re: Does Ranger authenticate HDFS users in Support Questions</title>
    <link>https://community.cloudera.com/t5/Support-Questions/Does-Ranger-authenticate-HDFS-users/m-p/101340#M64305</link>
    <description>&lt;P&gt;Ranger is just for authorization.&lt;/P&gt;&lt;P&gt;For central authentication, you can authenticate against an LDAP or AD. 
For local authentication, you can authenticate as a local unix user.&lt;/P&gt;&lt;P&gt;For true secure authentication, you need Kerberos with either a MIT KDC or AD as your KDC.&lt;/P&gt;&lt;P&gt;Yes it is possible without Kerberos to spoof a user.&lt;/P&gt;&lt;P&gt;See also this HCC post &lt;A target="_blank" href="https://community.hortonworks.com/questions/2982/kerberos-adldap-and-ranger.html" rel="nofollow noopener noreferrer"&gt;Kerberos, AD, Range&lt;/A&gt;r&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="1191-screen-shot-2016-01-04-at-70916-pm.png" style="width: 772px;"&gt;&lt;img src="https://community.cloudera.com/t5/image/serverpage/image-id/23751i389BDA82DDAC5BF7/image-size/medium?v=v2&amp;amp;px=400" role="button" title="1191-screen-shot-2016-01-04-at-70916-pm.png" alt="1191-screen-shot-2016-01-04-at-70916-pm.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 19 Aug 2019 12:20:52 GMT</pubDate>
    <dc:creator>amcbarnett</dc:creator>
    <dc:date>2019-08-19T12:20:52Z</dc:date>
    <item>
      <title>Does Ranger authenticate HDFS users</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Does-Ranger-authenticate-HDFS-users/m-p/101339#M64304</link>
      <description>&lt;P&gt;Ok. I am very confused with this Ranger product. There is no proper documentation on this aspect. &lt;/P&gt;&lt;P&gt;Dose Ranger authenticate a user before accessing HDFS content?&lt;/P&gt;&lt;P&gt;Is it just for authorization purpose only?&lt;/P&gt;&lt;P&gt;I got some consultant say, if you just use Ranger for Hdfs, you can fake as someone else and connect to the HDFS.&lt;/P&gt;&lt;P&gt;For example, you have a user called phil and john. They have  /tenent/users/phil and /users/john respectively. Both directories has directory level permission to only that particular user and  for group owner hdfs.&lt;/P&gt;&lt;P&gt;Is it possible for Phil to create a unix account as john on a linux box. Sudo as john on that machine and access hdfs as john. There by faking himself as john. &lt;/P&gt;&lt;P&gt;Appreciate any insights on this&lt;/P&gt;</description>
      <pubDate>Tue, 05 Jan 2016 08:02:05 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Does-Ranger-authenticate-HDFS-users/m-p/101339#M64304</guid>
      <dc:creator>arun9a</dc:creator>
      <dc:date>2016-01-05T08:02:05Z</dc:date>
    </item>
    <item>
      <title>Re: Does Ranger authenticate HDFS users</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Does-Ranger-authenticate-HDFS-users/m-p/101340#M64305</link>
      <description>&lt;P&gt;Ranger is just for authorization.&lt;/P&gt;&lt;P&gt;For central authentication, you can authenticate against an LDAP or AD. 
For local authentication, you can authenticate as a local unix user.&lt;/P&gt;&lt;P&gt;For true secure authentication, you need Kerberos with either a MIT KDC or AD as your KDC.&lt;/P&gt;&lt;P&gt;Yes it is possible without Kerberos to spoof a user.&lt;/P&gt;&lt;P&gt;See also this HCC post &lt;A target="_blank" href="https://community.hortonworks.com/questions/2982/kerberos-adldap-and-ranger.html" rel="nofollow noopener noreferrer"&gt;Kerberos, AD, Range&lt;/A&gt;r&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="1191-screen-shot-2016-01-04-at-70916-pm.png" style="width: 772px;"&gt;&lt;img src="https://community.cloudera.com/t5/image/serverpage/image-id/23751i389BDA82DDAC5BF7/image-size/medium?v=v2&amp;amp;px=400" role="button" title="1191-screen-shot-2016-01-04-at-70916-pm.png" alt="1191-screen-shot-2016-01-04-at-70916-pm.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 19 Aug 2019 12:20:52 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Does-Ranger-authenticate-HDFS-users/m-p/101340#M64305</guid>
      <dc:creator>amcbarnett</dc:creator>
      <dc:date>2019-08-19T12:20:52Z</dc:date>
    </item>
    <item>
      <title>Re: Does Ranger authenticate HDFS users</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Does-Ranger-authenticate-HDFS-users/m-p/101341#M64306</link>
      <description>&lt;P&gt;Ranger provides authorization and audit functionalities. You should use KERBEROS authentication to secure the Hadoop clusters along with Ranger. If you use SIMPLE authentication, the users can impersonate as other users by setting appropriate ENV variable before invoking hdfs commands.  &lt;/P&gt;</description>
      <pubDate>Tue, 05 Jan 2016 08:07:04 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Does-Ranger-authenticate-HDFS-users/m-p/101341#M64306</guid>
      <dc:creator>sneethiraj</dc:creator>
      <dc:date>2016-01-05T08:07:04Z</dc:date>
    </item>
  </channel>
</rss>

