<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>question Re: Atlas : how to secure Kafka ? in Archives of Support Questions (Read Only)</title>
    <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Atlas-how-to-secure-Kafka/m-p/198516#M65850</link>
    <description>&lt;P&gt;&lt;A rel="user" href="https://community.cloudera.com/users/11698/gmartin.html" nodeid="11698"&gt;@Graham Martin&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Thks for your expanation. I am going to install &amp;amp; to use Kerberos.&lt;/P&gt;&lt;P&gt;
&lt;A rel="user" href="https://community.cloudera.com/users/11698/gmartin.html" nodeid="11698"&gt;&lt;/A&gt; &lt;/P&gt;</description>
    <pubDate>Tue, 01 Aug 2017 16:42:08 GMT</pubDate>
    <dc:creator>smartdatabundle</dc:creator>
    <dc:date>2017-08-01T16:42:08Z</dc:date>
    <item>
      <title>Atlas : how to secure Kafka ?</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Atlas-how-to-secure-Kafka/m-p/198512#M65846</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I could access all topics on kafka without authentification. &lt;/P&gt;&lt;P&gt;My question : how I could secure access on kafka topics ?&lt;/P&gt;&lt;P&gt;Thks.&lt;/P&gt;</description>
      <pubDate>Tue, 01 Aug 2017 14:08:24 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Atlas-how-to-secure-Kafka/m-p/198512#M65846</guid>
      <dc:creator>smartdatabundle</dc:creator>
      <dc:date>2017-08-01T14:08:24Z</dc:date>
    </item>
    <item>
      <title>Re: Atlas : how to secure Kafka ?</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Atlas-how-to-secure-Kafka/m-p/198513#M65847</link>
      <description>&lt;P&gt;&lt;A rel="user" href="https://community.cloudera.com/users/17573/smartdatabundle.html" nodeid="17573"&gt;@Smart Data&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Atlas is more Governance related, security to a less extent.&lt;/P&gt;&lt;P&gt;You secure Kafka via Kerberos for authentication, and Ranger for authorization:&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.hortonworks.com/HDPDocuments/HDP2/HDP-2.6.1/index.html#bk_security" target="_blank"&gt;https://docs.hortonworks.com/HDPDocuments/HDP2/HDP-2.6.1/index.html#bk_security&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 01 Aug 2017 14:57:15 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Atlas-how-to-secure-Kafka/m-p/198513#M65847</guid>
      <dc:creator>gmartin</dc:creator>
      <dc:date>2017-08-01T14:57:15Z</dc:date>
    </item>
    <item>
      <title>Re: Atlas : how to secure Kafka ?</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Atlas-how-to-secure-Kafka/m-p/198514#M65848</link>
      <description>&lt;P&gt;&lt;A rel="user" href="https://community.cloudera.com/users/11698/gmartin.html" nodeid="11698"&gt;@Graham Martin&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Thks for your quick reply. Is there an alternative to Kerberos ? May be Apache Knox + LDAP ?&lt;/P&gt;&lt;P&gt;I went to the link: indeed, it explains only the use of Kerberos.&lt;/P&gt;&lt;P&gt; 
&lt;A rel="user" href="https://community.cloudera.com/users/11698/gmartin.html" nodeid="11698"&gt;&lt;/A&gt; &lt;/P&gt;</description>
      <pubDate>Tue, 01 Aug 2017 15:09:26 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Atlas-how-to-secure-Kafka/m-p/198514#M65848</guid>
      <dc:creator>smartdatabundle</dc:creator>
      <dc:date>2017-08-01T15:09:26Z</dc:date>
    </item>
    <item>
      <title>Re: Atlas : how to secure Kafka ?</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Atlas-how-to-secure-Kafka/m-p/198515#M65849</link>
      <description>&lt;P&gt;&lt;A rel="user" href="https://community.cloudera.com/users/17573/smartdatabundle.html" nodeid="17573"&gt;@Smart Data&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Ranger can be used to sync users with LDAP/AD. Credentials are stored in LDAP/AD, and Ranger configured to access.&lt;/P&gt;&lt;P&gt;Knox is used as a proxy, but more for REST API service calls, and some UIs. It is not meant to proxy high volume traffic like Kafka messages.&lt;/P&gt;</description>
      <pubDate>Tue, 01 Aug 2017 15:28:38 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Atlas-how-to-secure-Kafka/m-p/198515#M65849</guid>
      <dc:creator>gmartin</dc:creator>
      <dc:date>2017-08-01T15:28:38Z</dc:date>
    </item>
    <item>
      <title>Re: Atlas : how to secure Kafka ?</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Atlas-how-to-secure-Kafka/m-p/198516#M65850</link>
      <description>&lt;P&gt;&lt;A rel="user" href="https://community.cloudera.com/users/11698/gmartin.html" nodeid="11698"&gt;@Graham Martin&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Thks for your expanation. I am going to install &amp;amp; to use Kerberos.&lt;/P&gt;&lt;P&gt;
&lt;A rel="user" href="https://community.cloudera.com/users/11698/gmartin.html" nodeid="11698"&gt;&lt;/A&gt; &lt;/P&gt;</description>
      <pubDate>Tue, 01 Aug 2017 16:42:08 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Atlas-how-to-secure-Kafka/m-p/198516#M65850</guid>
      <dc:creator>smartdatabundle</dc:creator>
      <dc:date>2017-08-01T16:42:08Z</dc:date>
    </item>
    <item>
      <title>Re: Atlas : how to secure Kafka ?</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Atlas-how-to-secure-Kafka/m-p/198517#M65851</link>
      <description>&lt;P&gt;@&lt;A href="https://community.hortonworks.com/users/17573/smartdatabundle.html"&gt;@Smart Data&lt;/A&gt;&lt;/P&gt;&lt;P&gt;If you intend to run a secure Hadop cluster then there is no way you can avoid Kerberos. Below are the difference between knox and kerberos.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The &lt;A href="https://hortonworks.com/hadoop/knox"&gt;Apache Knox Gateway&lt;/A&gt; is a system that provides a single point of authentication and access. It provides the following features:&lt;/P&gt;&lt;UL&gt;
&lt;LI&gt;Single REST API Access Point&lt;/LI&gt;&lt;LI&gt;Centralized authentication, authorization and auditing for Hadoop REST/HTTP services&lt;/LI&gt;&lt;LI&gt;LDAP/AD Authentication, Service Authorization and Audit&lt;/LI&gt;&lt;LI&gt;Eliminates SSH edge node risks&lt;/LI&gt;&lt;LI&gt;Hides Network Topology&lt;/LI&gt;&lt;/UL&gt;&lt;H3&gt;LAYERS OF DEFENSE FOR A HADOOP CLUSTER&lt;/H3&gt;&lt;UL&gt;
&lt;LI&gt;Perimeter Level Security – Network Security, Apache Knox (gateway)&lt;/LI&gt;&lt;LI&gt;Authentication : Kerberos&lt;/LI&gt;&lt;LI&gt;Authorization&lt;/LI&gt;&lt;LI&gt;OS Security : encryption of data in network and HDFS&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Apache Knox can also access a Hadoop cluster over HTTP or HTTPS&lt;/P&gt;&lt;H3&gt;CURRENT FEATURES OF APACHE KNOX&lt;/H3&gt;&lt;UL&gt;
&lt;LI&gt;Authenticate : by LDAP or Cloud SSO Provider&lt;/LI&gt;&lt;LI&gt;Provides services for HDFS, HCat, HBase, Oozie, Hive, YARN, and Storm&lt;/LI&gt;&lt;LI&gt;HTTP access for Hive over JDBC support is available (ODBC driver Support- In Future)&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Hope that helps to explain.&lt;/P&gt;</description>
      <pubDate>Tue, 01 Aug 2017 17:24:32 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Atlas-how-to-secure-Kafka/m-p/198517#M65851</guid>
      <dc:creator>Shelton</dc:creator>
      <dc:date>2017-08-01T17:24:32Z</dc:date>
    </item>
    <item>
      <title>Re: Atlas : how to secure Kafka ?</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Atlas-how-to-secure-Kafka/m-p/198518#M65852</link>
      <description>&lt;P&gt;@&lt;A href="https://community.hortonworks.com/users/17573/smartdatabundle.html"&gt;@Smart Data&lt;/A&gt;&lt;/P&gt;&lt;P&gt;If you intend to run a secure Hadop cluster then there is no way you can avoid Kerberos. Below are the difference between knox and kerberos.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The &lt;A href="https://hortonworks.com/hadoop/knox"&gt;Apache Knox Gateway&lt;/A&gt; is a system that provides a single point of authentication and access. It provides the following features:&lt;/P&gt;&lt;UL&gt;
&lt;LI&gt;Single REST API Access Point&lt;/LI&gt;&lt;LI&gt;Centralized authentication, authorization and auditing for Hadoop REST/HTTP services&lt;/LI&gt;&lt;LI&gt;LDAP/AD Authentication, Service Authorization and Audit&lt;/LI&gt;&lt;LI&gt;Eliminates SSH edge node risks&lt;/LI&gt;&lt;LI&gt;Hides Network Topology&lt;/LI&gt;&lt;/UL&gt;&lt;H3&gt;LAYERS OF DEFENSE FOR A HADOOP CLUSTER&lt;/H3&gt;&lt;UL&gt;
&lt;LI&gt;Perimeter Level Security – Network Security, Apache Knox (gateway)&lt;/LI&gt;&lt;LI&gt;Authentication : Kerberos&lt;/LI&gt;&lt;LI&gt;Authorization&lt;/LI&gt;&lt;LI&gt;OS Security : encryption of data in network and HDFS&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Apache Knox can also access a Hadoop cluster over HTTP or HTTPS&lt;/P&gt;&lt;H3&gt;CURRENT FEATURES OF APACHE KNOX&lt;/H3&gt;&lt;UL&gt;
&lt;LI&gt;Authenticate : by LDAP or Cloud SSO Provider&lt;/LI&gt;&lt;LI&gt;Provides services for HDFS, HCat, HBase, Oozie, Hive, YARN, and Storm&lt;/LI&gt;&lt;LI&gt;HTTP access for Hive over JDBC support is available (ODBC driver Support- In Future)&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Hope that helps to explain.&lt;/P&gt;</description>
      <pubDate>Tue, 01 Aug 2017 17:25:01 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Atlas-how-to-secure-Kafka/m-p/198518#M65852</guid>
      <dc:creator>Shelton</dc:creator>
      <dc:date>2017-08-01T17:25:01Z</dc:date>
    </item>
    <item>
      <title>Re: Atlas : how to secure Kafka ?</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Atlas-how-to-secure-Kafka/m-p/198519#M65853</link>
      <description>&lt;P&gt;&lt;A rel="user" href="https://community.cloudera.com/users/1271/sheltong.html" nodeid="1271"&gt;@Geoffrey Shelton Okot&lt;/A&gt; thks for this explanation.&lt;/P&gt;</description>
      <pubDate>Tue, 01 Aug 2017 19:22:18 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Atlas-how-to-secure-Kafka/m-p/198519#M65853</guid>
      <dc:creator>smartdatabundle</dc:creator>
      <dc:date>2017-08-01T19:22:18Z</dc:date>
    </item>
  </channel>
</rss>

