<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>question User can view entire hdfs dir and navigate further via WebHDFS. hadoop-policy (Access Control Lists) does not seem to be applicable to WebHDFS. how to incorporate ACLs when accessed via WebHDFS? in Archives of Support Questions (Read Only)</title>
    <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/User-can-view-entire-hdfs-dir-and-navigate-further-via/m-p/94739#M7987</link>
    <description>&lt;P&gt;User can view entire hdfs dir and navigate more via WebHDFS. hadoop-policy (Access Control Lists) does not seem to be applicable to WebHDFS. how to incorporate ACLs when accessed via WebHDFS?&lt;/P&gt;</description>
    <pubDate>Fri, 02 Oct 2015 03:58:59 GMT</pubDate>
    <dc:creator>smayani</dc:creator>
    <dc:date>2015-10-02T03:58:59Z</dc:date>
    <item>
      <title>User can view entire hdfs dir and navigate further via WebHDFS. hadoop-policy (Access Control Lists) does not seem to be applicable to WebHDFS. how to incorporate ACLs when accessed via WebHDFS?</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/User-can-view-entire-hdfs-dir-and-navigate-further-via/m-p/94739#M7987</link>
      <description>&lt;P&gt;User can view entire hdfs dir and navigate more via WebHDFS. hadoop-policy (Access Control Lists) does not seem to be applicable to WebHDFS. how to incorporate ACLs when accessed via WebHDFS?&lt;/P&gt;</description>
      <pubDate>Fri, 02 Oct 2015 03:58:59 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/User-can-view-entire-hdfs-dir-and-navigate-further-via/m-p/94739#M7987</guid>
      <dc:creator>smayani</dc:creator>
      <dc:date>2015-10-02T03:58:59Z</dc:date>
    </item>
    <item>
      <title>Re: User can view entire hdfs dir and navigate further via WebHDFS. hadoop-policy (Access Control Lists) does not seem to be applicable to WebHDFS. how to incorporate ACLs when accessed via WebHDFS?</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/User-can-view-entire-hdfs-dir-and-navigate-further-via/m-p/94740#M7988</link>
      <description>&lt;P&gt;Are you referring to the hadoop-policy section in core-site and hdfs-site? These do not control security the way you'd expect. For proper ACLs on HDFS do either of these:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Secure (Kerberize) your cluster. Ambari automates this. Add Ranger and enable HDFS policies.&lt;/LI&gt;&lt;LI&gt;If accessing via REST API (WebHDFS) - restrict direct datanode access via a firewall and only allow access via Knox. Knox, in turn, will be able to map an incoming user into an actual role (still, full control with audit will require adding Ranger).&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;Andrew&lt;/P&gt;</description>
      <pubDate>Fri, 02 Oct 2015 06:31:56 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/User-can-view-entire-hdfs-dir-and-navigate-further-via/m-p/94740#M7988</guid>
      <dc:creator>andrewg</dc:creator>
      <dc:date>2015-10-02T06:31:56Z</dc:date>
    </item>
    <item>
      <title>Re: User can view entire hdfs dir and navigate further via WebHDFS. hadoop-policy (Access Control Lists) does not seem to be applicable to WebHDFS. how to incorporate ACLs when accessed via WebHDFS?</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/User-can-view-entire-hdfs-dir-and-navigate-further-via/m-p/94741#M7989</link>
      <description>&lt;P&gt;The ACLs specified in the hadoop-policy.xml file refer to Hadoop service-level authorization.&lt;/P&gt;&lt;P&gt;&lt;A href="http://hadoop.apache.org/docs/r2.7.1/hadoop-project-dist/hadoop-common/ServiceLevelAuth.html"&gt;http://hadoop.apache.org/docs/r2.7.1/hadoop-project-dist/hadoop-common/ServiceLevelAuth.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;These ACLs are enforced on Hadoop RPC service calls.  These ACLs are not applicable to access through WebHDFS.  In order to fully control authorization to HDFS files, use HDFS permissions and ACLs.&lt;/P&gt;&lt;P&gt;&lt;A href="http://hadoop.apache.org/docs/r2.7.1/hadoop-project-dist/hadoop-hdfs/HdfsPermissionsGuide.html"&gt;http://hadoop.apache.org/docs/r2.7.1/hadoop-project-dist/hadoop-hdfs/HdfsPermissionsGuide.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Permissions and ACLs applied to directories and files are enforced for all means of access to the file system.&lt;/P&gt;&lt;P&gt;Other potential solutions are to use Knox or Ranger.&lt;/P&gt;</description>
      <pubDate>Fri, 30 Oct 2015 04:03:12 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/User-can-view-entire-hdfs-dir-and-navigate-further-via/m-p/94741#M7989</guid>
      <dc:creator>cnauroth</dc:creator>
      <dc:date>2015-10-30T04:03:12Z</dc:date>
    </item>
    <item>
      <title>Re: User can view entire hdfs dir and navigate further via WebHDFS. hadoop-policy (Access Control Lists) does not seem to be applicable to WebHDFS. how to incorporate ACLs when accessed via WebHDFS?</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/User-can-view-entire-hdfs-dir-and-navigate-further-via/m-p/94742#M7990</link>
      <description>&lt;P&gt;&lt;A rel="user" href="https://community.cloudera.com/users/220/smayani.html" nodeid="220"&gt;@Saumil Mayani&lt;/A&gt; has this been resolved? Can you accept the best answer or provide your own solution?&lt;/P&gt;</description>
      <pubDate>Wed, 03 Feb 2016 01:24:24 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/User-can-view-entire-hdfs-dir-and-navigate-further-via/m-p/94742#M7990</guid>
      <dc:creator>aervits</dc:creator>
      <dc:date>2016-02-03T01:24:24Z</dc:date>
    </item>
  </channel>
</rss>

