<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>question Re: Ranger Admin stops applying policy updates. in Archives of Support Questions (Read Only)</title>
    <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Ranger-Admin-stops-applying-policy-updates/m-p/162941#M29307</link>
    <description>&lt;P&gt;&lt;A rel="user" href="https://community.cloudera.com/users/2398/hyadav.html" nodeid="2398"&gt;@Harini Yadav&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Please check this -&lt;/P&gt;&lt;P&gt;Ranger will always takes 1st precedence and then POSX permissions/HDFS acl's.&lt;/P&gt;&lt;P&gt;Also setting "xasecure.add-hadoop-authorization" = false in ranger-hdfs-security.xml in /etc/hadoop/conf will stop the fall back to HDFS ACL.&lt;/P&gt;&lt;P&gt;Please check below url's for more details -&lt;/P&gt;&lt;P&gt;&lt;A href="http://hortonworks.com/blog/best-practices-in-hdfs-authorization-with-apache-ranger/" target="_blank"&gt;http://hortonworks.com/blog/best-practices-in-hdfs-authorization-with-apache-ranger/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.hortonworks.com/questions/22054/should-we-disable-hdfs-default-acl-to-enable-range.html" target="_blank"&gt;https://community.hortonworks.com/questions/22054/should-we-disable-hdfs-default-acl-to-enable-range.html&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 23 May 2016 18:33:17 GMT</pubDate>
    <dc:creator>sshimpi</dc:creator>
    <dc:date>2016-05-23T18:33:17Z</dc:date>
    <item>
      <title>Ranger Admin stops applying policy updates.</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Ranger-Admin-stops-applying-policy-updates/m-p/162940#M29306</link>
      <description>&lt;P&gt;1) Using HDFS DFS -ls command I see /apps/hive with permissions 777 &lt;/P&gt;&lt;P&gt;2) Modifying permissions on /apps/hive to 700 by using HDFS DFS -chmod command 
3) Now going back to Ranger and modifying permissions to HDFS policy to add users to have access to path /apps/hive/warehouse. Ranger will no longer sync with HDFS&lt;/P&gt;</description>
      <pubDate>Mon, 23 May 2016 18:29:04 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Ranger-Admin-stops-applying-policy-updates/m-p/162940#M29306</guid>
      <dc:creator>hyadav</dc:creator>
      <dc:date>2016-05-23T18:29:04Z</dc:date>
    </item>
    <item>
      <title>Re: Ranger Admin stops applying policy updates.</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Ranger-Admin-stops-applying-policy-updates/m-p/162941#M29307</link>
      <description>&lt;P&gt;&lt;A rel="user" href="https://community.cloudera.com/users/2398/hyadav.html" nodeid="2398"&gt;@Harini Yadav&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Please check this -&lt;/P&gt;&lt;P&gt;Ranger will always takes 1st precedence and then POSX permissions/HDFS acl's.&lt;/P&gt;&lt;P&gt;Also setting "xasecure.add-hadoop-authorization" = false in ranger-hdfs-security.xml in /etc/hadoop/conf will stop the fall back to HDFS ACL.&lt;/P&gt;&lt;P&gt;Please check below url's for more details -&lt;/P&gt;&lt;P&gt;&lt;A href="http://hortonworks.com/blog/best-practices-in-hdfs-authorization-with-apache-ranger/" target="_blank"&gt;http://hortonworks.com/blog/best-practices-in-hdfs-authorization-with-apache-ranger/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.hortonworks.com/questions/22054/should-we-disable-hdfs-default-acl-to-enable-range.html" target="_blank"&gt;https://community.hortonworks.com/questions/22054/should-we-disable-hdfs-default-acl-to-enable-range.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 23 May 2016 18:33:17 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Ranger-Admin-stops-applying-policy-updates/m-p/162941#M29307</guid>
      <dc:creator>sshimpi</dc:creator>
      <dc:date>2016-05-23T18:33:17Z</dc:date>
    </item>
  </channel>
</rss>

