<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>question Re: What Ranger based authorization do I need to be able to grant privileges to others through grant command? in Support Questions</title>
    <link>https://community.cloudera.com/t5/Support-Questions/What-Ranger-based-authorization-do-I-need-to-be-able-to/m-p/132878#M95548</link>
    <description>&lt;P&gt;I've just tried the scenario you described on HDP-2.5.3 (Ranger-0.6) and it works, my user1 has only "Select" privilege but could grant all privileges to user2, and he can even grant "all" to himself. I think the idea with "Delegate Admin" is that you can set certain user to be a Ranger admin on given resources. Though, I've never seen this well documented. And actually the &lt;A href="https://cwiki.apache.org/confluence/display/RANGER/Apache+Ranger+0.5+-+User+Guide"&gt;User guide for Ranger-0.5&lt;/A&gt; says that &lt;EM&gt;The delegated admin can update, delete 
the policies. It can also create child policies based on the original 
policy (base policy). &lt;/EM&gt;So, if you want to avoid unexpected surprises you can disable "Delegate Admin" in all policies, and control everything by the central admin.&lt;/P&gt;</description>
    <pubDate>Fri, 03 Mar 2017 09:50:51 GMT</pubDate>
    <dc:creator>pminovic</dc:creator>
    <dc:date>2017-03-03T09:50:51Z</dc:date>
    <item>
      <title>What Ranger based authorization do I need to be able to grant privileges to others through grant command?</title>
      <link>https://community.cloudera.com/t5/Support-Questions/What-Ranger-based-authorization-do-I-need-to-be-able-to/m-p/132876#M95546</link>
      <description>&lt;P&gt;As an example: I have a Hive policy granting 'user1' 'select' privilege on 'default,*,*' with delegate admin set to true. Can 'user1' now issue a grant command to give 'user2',  'create', 'update' and 'select' privileges on 'default,*,*' ? user1 itself does not have the privileges its granting to user2 on the resources. &lt;A rel="user" href="https://community.cloudera.com/users/47/vperiasamy.html" nodeid="47"&gt;@vperiasamy&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 02 Mar 2017 06:40:04 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/What-Ranger-based-authorization-do-I-need-to-be-able-to/m-p/132876#M95546</guid>
      <dc:creator>aleekha</dc:creator>
      <dc:date>2017-03-02T06:40:04Z</dc:date>
    </item>
    <item>
      <title>Re: What Ranger based authorization do I need to be able to grant privileges to others through grant command?</title>
      <link>https://community.cloudera.com/t5/Support-Questions/What-Ranger-based-authorization-do-I-need-to-be-able-to/m-p/132877#M95547</link>
      <description>&lt;P&gt;In the above situation, I believe 'user1' will be able to grant to 'user2' any permissions, because delegate admin access is for the resources specified, not for the specific permissions. &lt;/P&gt;&lt;P&gt;&lt;A rel="user" href="https://community.cloudera.com/users/304/sneethiraj.html" nodeid="304"&gt;@sneethiraj&lt;/A&gt; can offer more insights. &lt;/P&gt;</description>
      <pubDate>Thu, 02 Mar 2017 23:40:09 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/What-Ranger-based-authorization-do-I-need-to-be-able-to/m-p/132877#M95547</guid>
      <dc:creator>vperiasamy</dc:creator>
      <dc:date>2017-03-02T23:40:09Z</dc:date>
    </item>
    <item>
      <title>Re: What Ranger based authorization do I need to be able to grant privileges to others through grant command?</title>
      <link>https://community.cloudera.com/t5/Support-Questions/What-Ranger-based-authorization-do-I-need-to-be-able-to/m-p/132878#M95548</link>
      <description>&lt;P&gt;I've just tried the scenario you described on HDP-2.5.3 (Ranger-0.6) and it works, my user1 has only "Select" privilege but could grant all privileges to user2, and he can even grant "all" to himself. I think the idea with "Delegate Admin" is that you can set certain user to be a Ranger admin on given resources. Though, I've never seen this well documented. And actually the &lt;A href="https://cwiki.apache.org/confluence/display/RANGER/Apache+Ranger+0.5+-+User+Guide"&gt;User guide for Ranger-0.5&lt;/A&gt; says that &lt;EM&gt;The delegated admin can update, delete 
the policies. It can also create child policies based on the original 
policy (base policy). &lt;/EM&gt;So, if you want to avoid unexpected surprises you can disable "Delegate Admin" in all policies, and control everything by the central admin.&lt;/P&gt;</description>
      <pubDate>Fri, 03 Mar 2017 09:50:51 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/What-Ranger-based-authorization-do-I-need-to-be-able-to/m-p/132878#M95548</guid>
      <dc:creator>pminovic</dc:creator>
      <dc:date>2017-03-03T09:50:51Z</dc:date>
    </item>
  </channel>
</rss>

