<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>question Re: Ranger for YARN RM: Not using group membership in Archives of Support Questions (Read Only)</title>
    <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Ranger-for-YARN-RM-Not-using-group-membership/m-p/171563#M45805</link>
    <description>&lt;P&gt;It was a problem with case conversion. Hadoop seems to require all lowercase principals, whereas the used principals were all uppercase.&lt;/P&gt;&lt;P&gt;Adding /L to the Auth_to_local mapping solved the problem.&lt;/P&gt;</description>
    <pubDate>Thu, 10 Nov 2016 17:21:05 GMT</pubDate>
    <dc:creator>benhadoop</dc:creator>
    <dc:date>2016-11-10T17:21:05Z</dc:date>
    <item>
      <title>Ranger for YARN RM: Not using group membership</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Ranger-for-YARN-RM-Not-using-group-membership/m-p/171562#M45804</link>
      <description>&lt;P&gt;Hi community,&lt;/P&gt;&lt;P&gt;I am running a kerberized HDP 2.5 cluster with Ranger policies activated for everything. I have synced Ranger with LDAP and Linux with AD to have consistent group memberships.&lt;/P&gt;&lt;P&gt;With SPNEGO, the access to the ResourceManager ist also a matter of authorization. Only users with administer_queue rights on a queue can view details of applications in that queue.&lt;/P&gt;&lt;P&gt;My problem is: When creating Ranger policies for YARN queues, rights based on groups are not respected in the RM WebUI. Only user-based rights are accepted. The group membership is, however, shown correctly in Ranger.&lt;/P&gt;&lt;P&gt;Do you have any idea, how to ensure that YARN uses the correct groups for granting rights?&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Thu, 10 Nov 2016 16:09:09 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Ranger-for-YARN-RM-Not-using-group-membership/m-p/171562#M45804</guid>
      <dc:creator>benhadoop</dc:creator>
      <dc:date>2016-11-10T16:09:09Z</dc:date>
    </item>
    <item>
      <title>Re: Ranger for YARN RM: Not using group membership</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Ranger-for-YARN-RM-Not-using-group-membership/m-p/171563#M45805</link>
      <description>&lt;P&gt;It was a problem with case conversion. Hadoop seems to require all lowercase principals, whereas the used principals were all uppercase.&lt;/P&gt;&lt;P&gt;Adding /L to the Auth_to_local mapping solved the problem.&lt;/P&gt;</description>
      <pubDate>Thu, 10 Nov 2016 17:21:05 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Ranger-for-YARN-RM-Not-using-group-membership/m-p/171563#M45805</guid>
      <dc:creator>benhadoop</dc:creator>
      <dc:date>2016-11-10T17:21:05Z</dc:date>
    </item>
  </channel>
</rss>

