<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>question Re: Ranger stacked policy evaluation with EXCLUDE switch in Archives of Support Questions (Read Only)</title>
    <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Ranger-stacked-policy-evaluation-with-EXCLUDE-switch/m-p/135745#M43786</link>
    <description>&lt;P&gt;For the moment I will not use this &lt;STRONG&gt;&lt;EM&gt;exclude&lt;/EM&gt;&lt;/STRONG&gt; switch because it behaves not as I (and my client) would expect. I will go for the Deny Conditions extension for the Hive service.&lt;/P&gt;&lt;P&gt;The exclude switch is confusing in that it seems to swap an allow into a deny, but it doesn't. It only excludes the resources from the policy&lt;/P&gt;</description>
    <pubDate>Tue, 18 Oct 2016 17:37:05 GMT</pubDate>
    <dc:creator>jknulst</dc:creator>
    <dc:date>2016-10-18T17:37:05Z</dc:date>
    <item>
      <title>Ranger stacked policy evaluation with EXCLUDE switch</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Ranger-stacked-policy-evaluation-with-EXCLUDE-switch/m-p/135739#M43780</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I have read the &lt;A href="https://cwiki.apache.org/confluence/display/RANGER/Deny-conditions+and+excludes+in+Ranger+policies" rel="nofollow noopener noreferrer" target="_blank"&gt;manual&lt;/A&gt; but I don't understand the behaviour of 2 policies I have regarding the same Hive table.&lt;/P&gt;&lt;P&gt;Policy 15 is a global allow policy on all Hive tables, all columns:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="8639-screen-shot-2016-10-18-at-82358-am.png" style="width: 2512px;"&gt;&lt;img src="https://community.cloudera.com/t5/image/serverpage/image-id/22049i3596CEFC9FCB1AF9/image-size/medium?v=v2&amp;amp;px=400" role="button" title="8639-screen-shot-2016-10-18-at-82358-am.png" alt="8639-screen-shot-2016-10-18-at-82358-am.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;then I have policy 31 like this:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="8634-screen-shot-2016-10-18-at-121942-am.png" style="width: 2504px;"&gt;&lt;img src="https://community.cloudera.com/t5/image/serverpage/image-id/22050i98943E9B8E10E0B4/image-size/medium?v=v2&amp;amp;px=400" role="button" title="8634-screen-shot-2016-10-18-at-121942-am.png" alt="8634-screen-shot-2016-10-18-at-121942-am.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;But whatever I try, user raj_ops still can run 'select * from employee' and get results. &lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="8635-screen-shot-2016-10-18-at-122631-am.png" style="width: 2758px;"&gt;&lt;img src="https://community.cloudera.com/t5/image/serverpage/image-id/22051i83AE90A0975B4244/image-size/medium?v=v2&amp;amp;px=400" role="button" title="8635-screen-shot-2016-10-18-at-122631-am.png" alt="8635-screen-shot-2016-10-18-at-122631-am.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Policy 31 is not evaluated as a 'deny' on the resource. I know you can add explicit Deny Conditons to the hive service, and I will try that. But the question is what the EXCLUDE switch (after the Hive column* box ) is good for when it is not picked up.  &lt;/P&gt;</description>
      <pubDate>Mon, 19 Aug 2019 08:54:06 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Ranger-stacked-policy-evaluation-with-EXCLUDE-switch/m-p/135739#M43780</guid>
      <dc:creator>jknulst</dc:creator>
      <dc:date>2019-08-19T08:54:06Z</dc:date>
    </item>
    <item>
      <title>Re: Ranger stacked policy evaluation with EXCLUDE switch</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Ranger-stacked-policy-evaluation-with-EXCLUDE-switch/m-p/135740#M43781</link>
      <description>&lt;P&gt;you mentioned there is a global allow policy , can you please attach screenshot of that too&lt;/P&gt;</description>
      <pubDate>Tue, 18 Oct 2016 12:56:41 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Ranger-stacked-policy-evaluation-with-EXCLUDE-switch/m-p/135740#M43781</guid>
      <dc:creator>dsharma</dc:creator>
      <dc:date>2016-10-18T12:56:41Z</dc:date>
    </item>
    <item>
      <title>Re: Ranger stacked policy evaluation with EXCLUDE switch</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Ranger-stacked-policy-evaluation-with-EXCLUDE-switch/m-p/135741#M43782</link>
      <description>&lt;P&gt;&lt;A href="https://community.hortonworks.com/questions/62016/edit.html#"&gt;@Deepak Sharma&lt;/A&gt; added in main question&lt;/P&gt;</description>
      <pubDate>Tue, 18 Oct 2016 13:28:14 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Ranger-stacked-policy-evaluation-with-EXCLUDE-switch/m-p/135741#M43782</guid>
      <dc:creator>jknulst</dc:creator>
      <dc:date>2016-10-18T13:28:14Z</dc:date>
    </item>
    <item>
      <title>Re: Ranger stacked policy evaluation with EXCLUDE switch</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Ranger-stacked-policy-evaluation-with-EXCLUDE-switch/m-p/135742#M43783</link>
      <description>&lt;P&gt;&lt;A rel="user" href="https://community.cloudera.com/users/12513/jknulst.html" nodeid="12513"&gt;@Jasper&lt;/A&gt; in policy 15 i can see you have added * resources for all and raj_ops is part of the user , so he is able to access all &lt;/P&gt;</description>
      <pubDate>Tue, 18 Oct 2016 13:48:43 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Ranger-stacked-policy-evaluation-with-EXCLUDE-switch/m-p/135742#M43783</guid>
      <dc:creator>dsharma</dc:creator>
      <dc:date>2016-10-18T13:48:43Z</dc:date>
    </item>
    <item>
      <title>Re: Ranger stacked policy evaluation with EXCLUDE switch</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Ranger-stacked-policy-evaluation-with-EXCLUDE-switch/m-p/135743#M43784</link>
      <description>&lt;P&gt;&lt;A rel="user" href="https://community.cloudera.com/users/505/dsharma.html" nodeid="505"&gt;@Deepak Sharma&lt;/A&gt; Yes, but I would expect that if 1 policy (15) says 'yes' and the other (31) says 'no', then it should be 'no' . As is stated in the schema in the &lt;A href="https://cwiki.apache.org/confluence/display/RANGER/Deny-conditions+and+excludes+in+Ranger+policies"&gt;manual&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 18 Oct 2016 13:57:26 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Ranger-stacked-policy-evaluation-with-EXCLUDE-switch/m-p/135743#M43784</guid>
      <dc:creator>jknulst</dc:creator>
      <dc:date>2016-10-18T13:57:26Z</dc:date>
    </item>
    <item>
      <title>Re: Ranger stacked policy evaluation with EXCLUDE switch</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Ranger-stacked-policy-evaluation-with-EXCLUDE-switch/m-p/135744#M43785</link>
      <description>&lt;P&gt;No &lt;A rel="user" href="https://community.cloudera.com/users/12513/jknulst.html" nodeid="12513"&gt;@Jasper&lt;/A&gt; this will be the case when there is deny condition for raj_ops , then raj_ops will be denied from performing operation, but in current scenario you can see both are allow condition , in such case if any of the condtion match then it will be allowed , and even manual also says same !&lt;/P&gt;</description>
      <pubDate>Tue, 18 Oct 2016 15:11:42 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Ranger-stacked-policy-evaluation-with-EXCLUDE-switch/m-p/135744#M43785</guid>
      <dc:creator>dsharma</dc:creator>
      <dc:date>2016-10-18T15:11:42Z</dc:date>
    </item>
    <item>
      <title>Re: Ranger stacked policy evaluation with EXCLUDE switch</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Ranger-stacked-policy-evaluation-with-EXCLUDE-switch/m-p/135745#M43786</link>
      <description>&lt;P&gt;For the moment I will not use this &lt;STRONG&gt;&lt;EM&gt;exclude&lt;/EM&gt;&lt;/STRONG&gt; switch because it behaves not as I (and my client) would expect. I will go for the Deny Conditions extension for the Hive service.&lt;/P&gt;&lt;P&gt;The exclude switch is confusing in that it seems to swap an allow into a deny, but it doesn't. It only excludes the resources from the policy&lt;/P&gt;</description>
      <pubDate>Tue, 18 Oct 2016 17:37:05 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Ranger-stacked-policy-evaluation-with-EXCLUDE-switch/m-p/135745#M43786</guid>
      <dc:creator>jknulst</dc:creator>
      <dc:date>2016-10-18T17:37:05Z</dc:date>
    </item>
    <item>
      <title>Re: Ranger stacked policy evaluation with EXCLUDE switch</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Ranger-stacked-policy-evaluation-with-EXCLUDE-switch/m-p/135746#M43787</link>
      <description>&lt;P&gt;For the moment I will not use this &lt;STRONG&gt;&lt;EM&gt;exclude&lt;/EM&gt;&lt;/STRONG&gt; switch because it behaves not as I (and my client) would expect. I will go for the Deny Conditions extension for the Hive service.&lt;/P&gt;&lt;P&gt;The exclude switch is confusing in that it seems to swap an allow into a deny, but it doesn't. It only excludes the resources from the policy&lt;/P&gt;</description>
      <pubDate>Tue, 18 Oct 2016 17:37:08 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Ranger-stacked-policy-evaluation-with-EXCLUDE-switch/m-p/135746#M43787</guid>
      <dc:creator>jknulst</dc:creator>
      <dc:date>2016-10-18T17:37:08Z</dc:date>
    </item>
  </channel>
</rss>

