<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>question Re: what are security implications of whitelisting yarn user with yarn.nodemanager.linux-container-executor.nonsecure-mode.local-user=yarn? in Archives of Support Questions (Read Only)</title>
    <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/what-are-security-implications-of-whitelisting-yarn-user/m-p/131571#M27228</link>
    <description>&lt;A rel="user" href="https://community.cloudera.com/users/381/cnauroth.html" nodeid="381"&gt;@Chris Nauroth&lt;/A&gt;&lt;P&gt;thank you very much, looking forward to your Hadoop Summit sessions.&lt;/P&gt;</description>
    <pubDate>Thu, 16 Jun 2016 09:37:21 GMT</pubDate>
    <dc:creator>aervits</dc:creator>
    <dc:date>2016-06-16T09:37:21Z</dc:date>
    <item>
      <title>what are security implications of whitelisting yarn user with yarn.nodemanager.linux-container-executor.nonsecure-mode.local-user=yarn?</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/what-are-security-implications-of-whitelisting-yarn-user/m-p/131569#M27226</link>
      <description>&lt;P&gt;In absence of a secured cluster, I enabled Linux Secured Containers and white-listed yarn user. In a production environment, what are the security risks with whitelisting yarn user and having regular users execute Oozie workflows on behalf of hbase user. &lt;/P&gt;</description>
      <pubDate>Thu, 05 May 2016 00:57:18 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/what-are-security-implications-of-whitelisting-yarn-user/m-p/131569#M27226</guid>
      <dc:creator>aervits</dc:creator>
      <dc:date>2016-05-05T00:57:18Z</dc:date>
    </item>
    <item>
      <title>Re: what are security implications of whitelisting yarn user with yarn.nodemanager.linux-container-executor.nonsecure-mode.local-user=yarn?</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/what-are-security-implications-of-whitelisting-yarn-user/m-p/131570#M27227</link>
      <description>&lt;A rel="user" href="https://community.cloudera.com/users/393/aervits.html" nodeid="393"&gt;@Artem Ervits&lt;/A&gt;, the risk of executing as the yarn user relates to several statements from the Apache Hadoop documentation on &lt;A href="http://hadoop.apache.org/docs/r2.7.2/hadoop-project-dist/hadoop-common/SecureMode.html"&gt;Secure Mode&lt;/A&gt;.  Specifically, the section on the &lt;A href="http://hadoop.apache.org/docs/r2.7.2/hadoop-project-dist/hadoop-common/SecureMode.html#NodeManager"&gt;NodeManager&lt;/A&gt; states the following:&lt;P&gt;
&lt;/P&gt;&lt;P&gt;&lt;EM&gt;For maximum security, this executor sets up restricted permissions and user/group ownership of local files and directories used by the containers such as the shared objects, jars, intermediate files, log files etc. Particularly note that, because of this, except the application owner and NodeManager, no other user can access any of the local files/directories including those localized as part of the distributed cache.
&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;Therefore, by executing YARN containers as user "yarn", which is the same as the user running the NodeManager, the container process can get full access to localized file content.  This would open a risk of users writing arbitrary application code that scans the local disk looking for localized files that potentially contain sensitive data, or even changing the contents of user-submitted executables to mount a code injection attack.  It would also be possible to access files owned by the yarn user on HDFS.&lt;/P&gt;</description>
      <pubDate>Mon, 13 Jun 2016 13:28:18 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/what-are-security-implications-of-whitelisting-yarn-user/m-p/131570#M27227</guid>
      <dc:creator>cnauroth</dc:creator>
      <dc:date>2016-06-13T13:28:18Z</dc:date>
    </item>
    <item>
      <title>Re: what are security implications of whitelisting yarn user with yarn.nodemanager.linux-container-executor.nonsecure-mode.local-user=yarn?</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/what-are-security-implications-of-whitelisting-yarn-user/m-p/131571#M27228</link>
      <description>&lt;A rel="user" href="https://community.cloudera.com/users/381/cnauroth.html" nodeid="381"&gt;@Chris Nauroth&lt;/A&gt;&lt;P&gt;thank you very much, looking forward to your Hadoop Summit sessions.&lt;/P&gt;</description>
      <pubDate>Thu, 16 Jun 2016 09:37:21 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/what-are-security-implications-of-whitelisting-yarn-user/m-p/131571#M27228</guid>
      <dc:creator>aervits</dc:creator>
      <dc:date>2016-06-16T09:37:21Z</dc:date>
    </item>
  </channel>
</rss>

