<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>question Re: Ranger policy malfunction in kafka in Support Questions</title>
    <link>https://community.cloudera.com/t5/Support-Questions/Ranger-policy-malfunction-in-kafka/m-p/102624#M65559</link>
    <description>&lt;P&gt;I will check for it, too&lt;/P&gt;</description>
    <pubDate>Mon, 18 Jan 2016 09:38:47 GMT</pubDate>
    <dc:creator>bensonshih</dc:creator>
    <dc:date>2016-01-18T09:38:47Z</dc:date>
    <item>
      <title>Ranger policy malfunction in kafka</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Ranger-policy-malfunction-in-kafka/m-p/102615#M65550</link>
      <description>&lt;P&gt;In kafka, I tried to execute consume/publish command with disabled all policies of Ranger, it did not deny both consume/publish behavior. Did I miss any configuration setting of kafka or misunderstanding something else?&lt;/P&gt;</description>
      <pubDate>Thu, 14 Jan 2016 15:22:57 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Ranger-policy-malfunction-in-kafka/m-p/102615#M65550</guid>
      <dc:creator>bensonshih</dc:creator>
      <dc:date>2016-01-14T15:22:57Z</dc:date>
    </item>
    <item>
      <title>Re: Ranger policy malfunction in kafka</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Ranger-policy-malfunction-in-kafka/m-p/102616#M65551</link>
      <description>&lt;P&gt;&lt;A rel="user" href="https://community.cloudera.com/users/229/bdurai.html" nodeid="229" target="_blank"&gt;@bdurai&lt;/A&gt; &lt;A rel="user" href="https://community.cloudera.com/users/306/bganesan.html" nodeid="306" target="_blank"&gt;@bganesan&lt;/A&gt;&lt;/P&gt;&lt;P&gt;I was able to reproduce this. I have only kafka user listed in Kafka policy and root can consume and produce the data "not listed in kafka policy.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="1358-screen-shot-2016-01-14-at-95432-am.png" style="width: 2778px;"&gt;&lt;img src="https://community.cloudera.com/t5/image/serverpage/image-id/23697iEFD5D4B26533AD72/image-size/medium?v=v2&amp;amp;px=400" role="button" title="1358-screen-shot-2016-01-14-at-95432-am.png" alt="1358-screen-shot-2016-01-14-at-95432-am.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;A rel="user" href="https://community.cloudera.com/users/2109/bensonshih.html" nodeid="2109" target="_blank"&gt;@Benson Shih&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 19 Aug 2019 12:14:09 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Ranger-policy-malfunction-in-kafka/m-p/102616#M65551</guid>
      <dc:creator>nsabharwal</dc:creator>
      <dc:date>2019-08-19T12:14:09Z</dc:date>
    </item>
    <item>
      <title>Re: Ranger policy malfunction in kafka</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Ranger-policy-malfunction-in-kafka/m-p/102617#M65552</link>
      <description>&lt;P&gt;Is the Ranger plugin properly installed?  For example, do you any evidence of it in Ranger Audit logs, e.g. kafaka server connecting to Ranger to download policies or access log indicating that access was allowed by ranger?&lt;/P&gt;</description>
      <pubDate>Fri, 15 Jan 2016 01:31:04 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Ranger-policy-malfunction-in-kafka/m-p/102617#M65552</guid>
      <dc:creator>alal1</dc:creator>
      <dc:date>2016-01-15T01:31:04Z</dc:date>
    </item>
    <item>
      <title>Re: Ranger policy malfunction in kafka</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Ranger-policy-malfunction-in-kafka/m-p/102618#M65553</link>
      <description>&lt;P&gt;Please check your server.properties file and ensure you have authorizer.class.name set to Ranger Authorizer's Fully Qualified class name. &lt;/P&gt;</description>
      <pubDate>Fri, 15 Jan 2016 03:34:44 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Ranger-policy-malfunction-in-kafka/m-p/102618#M65553</guid>
      <dc:creator>pbrahmbhatt</dc:creator>
      <dc:date>2016-01-15T03:34:44Z</dc:date>
    </item>
    <item>
      <title>Re: Ranger policy malfunction in kafka</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Ranger-policy-malfunction-in-kafka/m-p/102619#M65554</link>
      <description>&lt;P&gt;Also look into the Ranger Audits from the Ranger Admin. If Ranger is allowing the request, then it will have policy which gave the permission.&lt;/P&gt;</description>
      <pubDate>Fri, 15 Jan 2016 09:12:20 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Ranger-policy-malfunction-in-kafka/m-p/102619#M65554</guid>
      <dc:creator>bdurai</dc:creator>
      <dc:date>2016-01-15T09:12:20Z</dc:date>
    </item>
    <item>
      <title>Re: Ranger policy malfunction in kafka</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Ranger-policy-malfunction-in-kafka/m-p/102620#M65555</link>
      <description>&lt;A rel="user" href="https://community.cloudera.com/users/2109/bensonshih.html" nodeid="2109"&gt;@Benson Shih&lt;/A&gt;&lt;P&gt;did you turn off the global allow policy for Kafka?&lt;/P&gt;</description>
      <pubDate>Fri, 15 Jan 2016 18:45:21 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Ranger-policy-malfunction-in-kafka/m-p/102620#M65555</guid>
      <dc:creator>aervits</dc:creator>
      <dc:date>2016-01-15T18:45:21Z</dc:date>
    </item>
    <item>
      <title>Re: Ranger policy malfunction in kafka</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Ranger-policy-malfunction-in-kafka/m-p/102621#M65556</link>
      <description>&lt;P&gt;I will check for it&lt;/P&gt;</description>
      <pubDate>Mon, 18 Jan 2016 09:34:28 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Ranger-policy-malfunction-in-kafka/m-p/102621#M65556</guid>
      <dc:creator>bensonshih</dc:creator>
      <dc:date>2016-01-18T09:34:28Z</dc:date>
    </item>
    <item>
      <title>Re: Ranger policy malfunction in kafka</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Ranger-policy-malfunction-in-kafka/m-p/102622#M65557</link>
      <description>&lt;P&gt;It`s supposes to be "org.apache.ranger.authorization.kafka.authorizer.RangerKafkaAuthorizer" right?&lt;/P&gt;</description>
      <pubDate>Mon, 18 Jan 2016 09:36:28 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Ranger-policy-malfunction-in-kafka/m-p/102622#M65557</guid>
      <dc:creator>bensonshih</dc:creator>
      <dc:date>2016-01-18T09:36:28Z</dc:date>
    </item>
    <item>
      <title>Re: Ranger policy malfunction in kafka</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Ranger-policy-malfunction-in-kafka/m-p/102623#M65558</link>
      <description>&lt;P&gt;What is it mean? Could you give me an example thanks.&lt;/P&gt;</description>
      <pubDate>Mon, 18 Jan 2016 09:37:36 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Ranger-policy-malfunction-in-kafka/m-p/102623#M65558</guid>
      <dc:creator>bensonshih</dc:creator>
      <dc:date>2016-01-18T09:37:36Z</dc:date>
    </item>
    <item>
      <title>Re: Ranger policy malfunction in kafka</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Ranger-policy-malfunction-in-kafka/m-p/102624#M65559</link>
      <description>&lt;P&gt;I will check for it, too&lt;/P&gt;</description>
      <pubDate>Mon, 18 Jan 2016 09:38:47 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Ranger-policy-malfunction-in-kafka/m-p/102624#M65559</guid>
      <dc:creator>bensonshih</dc:creator>
      <dc:date>2016-01-18T09:38:47Z</dc:date>
    </item>
    <item>
      <title>Re: Ranger policy malfunction in kafka</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Ranger-policy-malfunction-in-kafka/m-p/102625#M65560</link>
      <description>&lt;P&gt;&lt;A rel="user" href="https://community.cloudera.com/users/2109/bensonshih.html" nodeid="2109"&gt;@Benson Shih&lt;/A&gt; check this &lt;A href="https://github.com/abajwa-hw/security-workshops/blob/master/Setup-ranger-23.md#setup-kafka-plugin-for-ranger" target="_blank"&gt;https://github.com/abajwa-hw/security-workshops/blob/master/Setup-ranger-23.md#setup-kafka-plugin-for-ranger&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 19 Jan 2016 10:32:42 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Ranger-policy-malfunction-in-kafka/m-p/102625#M65560</guid>
      <dc:creator>nsabharwal</dc:creator>
      <dc:date>2016-01-19T10:32:42Z</dc:date>
    </item>
    <item>
      <title>Re: Ranger policy malfunction in kafka</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Ranger-policy-malfunction-in-kafka/m-p/102626#M65561</link>
      <description>&lt;P&gt;Is this issue resolved?  I also tried to create a kafka ranger policy to exclude a select user from not creating or deleting topics.  But it doesn't get enforced.  I see the 200 response in Ranger Audits that Kafka plugin is up.  &lt;/P&gt;</description>
      <pubDate>Thu, 28 Jan 2016 03:55:07 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Ranger-policy-malfunction-in-kafka/m-p/102626#M65561</guid>
      <dc:creator>ashaver</dc:creator>
      <dc:date>2016-01-28T03:55:07Z</dc:date>
    </item>
    <item>
      <title>Re: Ranger policy malfunction in kafka</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Ranger-policy-malfunction-in-kafka/m-p/102627#M65562</link>
      <description>&lt;P&gt;Is it correct that the kafka and ranger must be in the kerberized cluster environment? &lt;/P&gt;</description>
      <pubDate>Sun, 31 Jan 2016 22:29:33 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Ranger-policy-malfunction-in-kafka/m-p/102627#M65562</guid>
      <dc:creator>bensonshih</dc:creator>
      <dc:date>2016-01-31T22:29:33Z</dc:date>
    </item>
    <item>
      <title>Re: Ranger policy malfunction in kafka</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Ranger-policy-malfunction-in-kafka/m-p/102628#M65563</link>
      <description>&lt;P&gt;&lt;A rel="user" href="https://community.cloudera.com/users/2109/bensonshih.html" nodeid="2109"&gt;@Benson Shih&lt;/A&gt; See this&lt;/P&gt;&lt;P&gt;&lt;A target="_blank" href="https://cwiki.apache.org/confluence/display/RANGER/Kafka+Plugin#KafkaPlugin-CanIauthorizeraccesstoKafkaoveranon-securechannelviaRanger?"&gt;https://cwiki.apache.org/confluence/display/RANGER/Kafka+Plugin#KafkaPlugin-CanIauthorizeraccesstoKafkaoveranon-securechannelviaRanger?&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 01 Feb 2016 00:22:42 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Ranger-policy-malfunction-in-kafka/m-p/102628#M65563</guid>
      <dc:creator>nsabharwal</dc:creator>
      <dc:date>2016-02-01T00:22:42Z</dc:date>
    </item>
    <item>
      <title>Re: Ranger policy malfunction in kafka</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Ranger-policy-malfunction-in-kafka/m-p/102629#M65564</link>
      <description>&lt;P&gt;&lt;A rel="user" href="https://community.cloudera.com/users/2109/bensonshih.html" nodeid="2109"&gt;@Benson Shih&lt;/A&gt;  Just created an article based on this &lt;A href="https://community.hortonworks.com/articles/12699/ranger-and-kafka-integration-faq.html"&gt;https://community.hortonworks.com/articles/12699/ranger-and-kafka-integration-faq.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Very useful to resolve this issue.&lt;/P&gt;</description>
      <pubDate>Mon, 01 Feb 2016 00:31:37 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Ranger-policy-malfunction-in-kafka/m-p/102629#M65564</guid>
      <dc:creator>nsabharwal</dc:creator>
      <dc:date>2016-02-01T00:31:37Z</dc:date>
    </item>
    <item>
      <title>Re: Ranger policy malfunction in kafka</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Ranger-policy-malfunction-in-kafka/m-p/102630#M65565</link>
      <description>&lt;P&gt;&lt;A rel="user" href="https://community.cloudera.com/users/2418/ashaver.html" nodeid="2418"&gt;@Anna Shaverdian&lt;/A&gt;  see this &lt;A href="https://community.hortonworks.com/articles/12699/ranger-and-kafka-integration-faq.html"&gt;https://community.hortonworks.com/articles/12699/ranger-and-kafka-integration-faq.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 01 Feb 2016 00:35:19 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Ranger-policy-malfunction-in-kafka/m-p/102630#M65565</guid>
      <dc:creator>nsabharwal</dc:creator>
      <dc:date>2016-02-01T00:35:19Z</dc:date>
    </item>
    <item>
      <title>Re: Ranger policy malfunction in kafka</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Ranger-policy-malfunction-in-kafka/m-p/102631#M65566</link>
      <description>&lt;P&gt;Hi &lt;A href="https://community.hortonworks.com/questions/9860/ranger-policy-malfunction-in-kafka.html#" rel="nofollow noopener noreferrer" target="_blank"&gt;@Neeraj Sabharwal&lt;/A&gt;,&lt;/P&gt;&lt;P&gt;I still can not deny Publish and Consume actions,my policy setting as below:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="1660-未命名.png" style="width: 1574px;"&gt;&lt;img src="https://community.cloudera.com/t5/image/serverpage/image-id/23696iEC870E1F2E34AEDB/image-size/medium?v=v2&amp;amp;px=400" role="button" title="1660-未命名.png" alt="1660-未命名.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;my environment is not a kerberized cluster and also I did not observe any records in Access of Audit,any suggestion?&lt;/P&gt;&lt;P&gt;thanks.&lt;/P&gt;</description>
      <pubDate>Mon, 19 Aug 2019 12:14:01 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Ranger-policy-malfunction-in-kafka/m-p/102631#M65566</guid>
      <dc:creator>bensonshih</dc:creator>
      <dc:date>2019-08-19T12:14:01Z</dc:date>
    </item>
    <item>
      <title>Re: Ranger policy malfunction in kafka</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Ranger-policy-malfunction-in-kafka/m-p/102632#M65567</link>
      <description>&lt;P&gt;BTW, the following steps are how I enabled ranger for kafka and executed Publish/Consume actions:&lt;/P&gt;&lt;P&gt;1. In kafka Configs &amp;gt; Advanced ranger-kafka-aduit &amp;gt; enable "Audit to DB" and changed value of "xasecure.audit.destination.hdfs.dir" to "hdfs://140.92.XX.XX:8020/ranger/audit"&lt;/P&gt;&lt;P&gt;2. Configs &amp;gt; Advanced ranger-kafka-plugin-properties &amp;gt; enable "Enable Ranger for KAFKA"&lt;/P&gt;&lt;P&gt;3. save changes and restart KAFKA&lt;/P&gt;&lt;P&gt;4. go to Ranger admin UI and I saw the repository of kafka has been created automatically&lt;/P&gt;</description>
      <pubDate>Mon, 01 Feb 2016 17:18:14 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Ranger-policy-malfunction-in-kafka/m-p/102632#M65567</guid>
      <dc:creator>bensonshih</dc:creator>
      <dc:date>2016-02-01T17:18:14Z</dc:date>
    </item>
    <item>
      <title>Re: Ranger policy malfunction in kafka</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Ranger-policy-malfunction-in-kafka/m-p/102633#M65568</link>
      <description>&lt;P&gt;Executing consume/publish steps:&lt;/P&gt;&lt;P&gt;Step1: connect to kafka-broker server&lt;/P&gt;&lt;P&gt;step2: changer user

$ su kafka&lt;/P&gt;&lt;P&gt;step3: go to bin folder

$ cd /usr/hdp/2.3.0.0-2557/kafka/bin&lt;/P&gt;&lt;P&gt;step4: create a topic

$ ./kafka-topics.sh --create --zookeeper {hostname}:2181 --replication-factor 1 --partitions 1 --topic test&lt;/P&gt;&lt;P&gt;step5: execute publish message

$ ./kafka-console-producer.sh --broker-list {hostname}:6667--topic test&lt;/P&gt;&lt;P&gt;This is a test message

//it should be denied right?&lt;/P&gt;&lt;P&gt;step6: execute consume message

$ ./kafka-console-consumer.sh --zookeeper {hostname}:2181 --topic test --from-beginning&lt;/P&gt;&lt;P&gt;//it also should be denied?&lt;/P&gt;</description>
      <pubDate>Mon, 01 Feb 2016 17:18:46 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Ranger-policy-malfunction-in-kafka/m-p/102633#M65568</guid>
      <dc:creator>bensonshih</dc:creator>
      <dc:date>2016-02-01T17:18:46Z</dc:date>
    </item>
    <item>
      <title>Re: Ranger policy malfunction in kafka</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Ranger-policy-malfunction-in-kafka/m-p/102634#M65569</link>
      <description>&lt;P&gt;&lt;A rel="user" href="https://community.cloudera.com/users/2109/bensonshih.html" nodeid="2109"&gt;@Benson Shih&lt;/A&gt; I really appreciate you sharing the details.&lt;/P&gt;&lt;P&gt;In the Ranger policy, Did you set the IP?&lt;/P&gt;&lt;H4&gt;&lt;EM&gt;Can I authorize access to Kafka over a non-secure channel via Ranger?&lt;/EM&gt;&lt;/H4&gt;&lt;P&gt;Yes. &lt;STRONG&gt;you can control access by ip-address.&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 01 Feb 2016 19:21:02 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Ranger-policy-malfunction-in-kafka/m-p/102634#M65569</guid>
      <dc:creator>nsabharwal</dc:creator>
      <dc:date>2016-02-01T19:21:02Z</dc:date>
    </item>
  </channel>
</rss>

