<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>question Restrict/Protect free access to users through web in Archives of Support Questions (Read Only)</title>
    <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Restrict-Protect-free-access-to-users-through-web/m-p/128682#M34683</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Is there a way to restrict/protect the access to the following service URLs through browser. As of now all these URLs are accessible without authentication and our Security Assessment team list these as part of the vulnerabilities.&lt;/P&gt;&lt;P&gt;&lt;A href="http://domainame:50070/logs/" target="_blank"&gt;http://domainame:50070/logs/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://domainame:50070/explorer.html#/" target="_blank"&gt;http://domainame:50070/explorer.html#/&lt;/A&gt; &lt;/P&gt;&lt;P&gt;
&lt;A href="http://domainame:50070/dfshealth.html#tab-datanode" target="_blank"&gt;http://domainame:50070/dfshealth.html#tab-datanode&lt;/A&gt; &lt;/P&gt;&lt;P&gt;
&lt;A href="http://domainame:16030/rs-status" target="_blank"&gt;http://domainame:16030/rs-status&lt;/A&gt; &lt;/P&gt;&lt;P&gt;
&lt;A href="http://domainame:8088/cluster/cluster" target="_blank"&gt;http://domainame:8088/cluster/cluster&lt;/A&gt; &lt;/P&gt;&lt;P&gt;
&lt;A href="http://domainame:8188/applicationhistory" target="_blank"&gt;http://domainame:8188/applicationhistory&lt;/A&gt; &lt;/P&gt;&lt;P&gt;
&lt;A href="http://domainame:8042/node" target="_blank"&gt;http://domainame:8042/node&lt;/A&gt; &lt;/P&gt;&lt;P&gt;&lt;A href="http://secondarynamenode:16010/logs/" target="_blank"&gt;http://secondarynamenode:16010/logs/&lt;/A&gt; &lt;/P&gt;&lt;P&gt;&lt;A href="http://datanode:61310/logs/" target="_blank"&gt;http://datanode:61310/logs/&lt;/A&gt; &lt;/P&gt;&lt;P&gt;Your speedy response is highly appreciated.&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
    <pubDate>Fri, 16 Sep 2022 10:29:53 GMT</pubDate>
    <dc:creator>testsaran09</dc:creator>
    <dc:date>2022-09-16T10:29:53Z</dc:date>
    <item>
      <title>Restrict/Protect free access to users through web</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Restrict-Protect-free-access-to-users-through-web/m-p/128682#M34683</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Is there a way to restrict/protect the access to the following service URLs through browser. As of now all these URLs are accessible without authentication and our Security Assessment team list these as part of the vulnerabilities.&lt;/P&gt;&lt;P&gt;&lt;A href="http://domainame:50070/logs/" target="_blank"&gt;http://domainame:50070/logs/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://domainame:50070/explorer.html#/" target="_blank"&gt;http://domainame:50070/explorer.html#/&lt;/A&gt; &lt;/P&gt;&lt;P&gt;
&lt;A href="http://domainame:50070/dfshealth.html#tab-datanode" target="_blank"&gt;http://domainame:50070/dfshealth.html#tab-datanode&lt;/A&gt; &lt;/P&gt;&lt;P&gt;
&lt;A href="http://domainame:16030/rs-status" target="_blank"&gt;http://domainame:16030/rs-status&lt;/A&gt; &lt;/P&gt;&lt;P&gt;
&lt;A href="http://domainame:8088/cluster/cluster" target="_blank"&gt;http://domainame:8088/cluster/cluster&lt;/A&gt; &lt;/P&gt;&lt;P&gt;
&lt;A href="http://domainame:8188/applicationhistory" target="_blank"&gt;http://domainame:8188/applicationhistory&lt;/A&gt; &lt;/P&gt;&lt;P&gt;
&lt;A href="http://domainame:8042/node" target="_blank"&gt;http://domainame:8042/node&lt;/A&gt; &lt;/P&gt;&lt;P&gt;&lt;A href="http://secondarynamenode:16010/logs/" target="_blank"&gt;http://secondarynamenode:16010/logs/&lt;/A&gt; &lt;/P&gt;&lt;P&gt;&lt;A href="http://datanode:61310/logs/" target="_blank"&gt;http://datanode:61310/logs/&lt;/A&gt; &lt;/P&gt;&lt;P&gt;Your speedy response is highly appreciated.&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Fri, 16 Sep 2022 10:29:53 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Restrict-Protect-free-access-to-users-through-web/m-p/128682#M34683</guid>
      <dc:creator>testsaran09</dc:creator>
      <dc:date>2022-09-16T10:29:53Z</dc:date>
    </item>
    <item>
      <title>Re: Restrict/Protect free access to users through web</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Restrict-Protect-free-access-to-users-through-web/m-p/128683#M34684</link>
      <description>&lt;P style="margin-left: 40px;"&gt; &lt;A rel="user" href="https://community.cloudera.com/users/11121/testsaran09.html" nodeid="11121"&gt;@Saravanan Ramaraj&lt;/A&gt; have you looked into apache knox? &lt;/P&gt;&lt;P&gt;The Knox API Gateway is designed as a reverse proxy with consideration for pluggability in the areas of
policy enforcement, through providers and the backend services for which it proxies requests.  The Apache Knox Gateway is a REST API Gateway for interacting with Apache Hadoop clusters.  The Knox Gateway provides a single access point for all REST interactions with Apache Hadoop clusters.&lt;/P&gt;&lt;P&gt;In this capacity, the Knox Gateway is able to provide valuable functionality to aid in the control,
integration, monitoring and automation of critical administrative and analytical needs of the enterprise.&lt;/P&gt;&lt;UL&gt;
&lt;LI&gt;Authentication (LDAP and Active Directory Authentication Provider)&lt;/LI&gt;&lt;LI&gt;Federation/SSO (HTTP Header Based Identity Federation)&lt;/LI&gt;&lt;LI&gt;Authorization (Service Level Authorization)&lt;/LI&gt;&lt;LI&gt;Auditing&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;And then for authorization you can use Apache Ranger which offers a centralized security framework to manage fine-grained access control over Hadoop data access components&lt;/P&gt;&lt;P&gt;coupled with kerberos you cluster will be secured and the links shall be authenticed using kerberos and ranger will provide authorization on what services the user has access to.  Finally knox will be your perimeter security.&lt;/P&gt;</description>
      <pubDate>Thu, 14 Jul 2016 10:12:37 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Restrict-Protect-free-access-to-users-through-web/m-p/128683#M34684</guid>
      <dc:creator>sunile_manjee</dc:creator>
      <dc:date>2016-07-14T10:12:37Z</dc:date>
    </item>
  </channel>
</rss>

