Reply
Highlighted
Explorer
Posts: 6
Registered: ‎07-07-2015
Accepted Solution

Hbase ACLs will apply for the subgroup members?

Hi,

 

We are running with acl error in HBase. One of our user named "x" is part of the group called "A". And "A" is part of another group "B".

Now Group "B" have access to a table "p" in Hbase.

 

When user "x" is trying to access table "p", he is getting error as access denied.

 

I want to know whether hbase acls supports subgroup members or only direct group members only will have access?

 

 

Thanks

Srini

Posts: 1,896
Kudos: 433
Solutions: 303
Registered: ‎07-31-2013

Re: Hbase ACLs will apply for the subgroup members

Unless "hdfs groups x" returns both "A" and "B" in its results,
HDFS/HBase/etc. would not be aware of such a relationship.

If you use SSSD+LDAP to resolve groups for your OS, you can request it to
query a certain level of nesting. See ldap_group_nesting_level under
http://linux.die.net/man/5/sssd-ldap.
Explorer
Posts: 6
Registered: ‎07-07-2015

Re: Hbase ACLs will apply for the subgroup members

Hi,

 

This was our mistake, we missed to add the @ before the group name while giving access to the tables.

 

Thanks

Srini

Posts: 1,896
Kudos: 433
Solutions: 303
Registered: ‎07-31-2013

Re: Hbase ACLs will apply for the subgroup members

Thank you for following up as always, Srini!
Announcements