- Subscribe to RSS Feed
- Mark Question as New
- Mark Question as Read
- Float this Question for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Additional ranger Keyadmins
- Labels:
-
Apache Ranger
Created ‎12-10-2018 07:40 AM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
We are managing the Ranger KMS using kayadmin user.
I can add users and assign admin role from ranger admin console. But could not find user management option after login to keyadmin user profile.
How can I create new users and add them as keyadmin for managing keys ?
Thanks,
Sajesh
Created ‎12-10-2018 05:16 PM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi @Sajesh PP,
To create KMS admins, do the following: 1. Since only admin role can create users, first login to Ranger UI as an admin. 2. Create multiple new users from Ranger webUI and keep these users as ADMIN role 3. Go to Settings -> Permissions -> Edit 'Key Manager' permission & add newly created user to 'Key Manager' module -> Save & Logout 4. Login as new user and you can use 'Encryption' tab for creating and managing the keys.
Hope this helps!
Please login and accept the answer if you find this answer helpful. Thanks
Created ‎12-10-2018 05:16 PM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi @Sajesh PP,
To create KMS admins, do the following: 1. Since only admin role can create users, first login to Ranger UI as an admin. 2. Create multiple new users from Ranger webUI and keep these users as ADMIN role 3. Go to Settings -> Permissions -> Edit 'Key Manager' permission & add newly created user to 'Key Manager' module -> Save & Logout 4. Login as new user and you can use 'Encryption' tab for creating and managing the keys.
Hope this helps!
Please login and accept the answer if you find this answer helpful. Thanks
Created ‎12-11-2018 06:26 AM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I had followed the above steps.
After login to new user account i can go to Encryption tab.But when I select my Service name from "Select service" option it says "User:<user> not allowed to do 'GET_KEYS" and i cannot see any of my keys listed
Created on ‎12-11-2018 10:58 AM - edited ‎08-17-2019 04:00 PM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi @Sajesh PP,
Could you please try to add new user to KMS policy and grant the permissions.
Login as keyadmin -> Access Manager -> Click the KMS service -> Edit "all-keyname" policy -> add newly created user in select user section.
Hope this helps!!
Please login and accept the answer if you find this answer helpful. Thanks
Created ‎12-13-2018 10:29 AM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
@Sajesh PP Are you able to list the keys using above method?If so, please login and accept the answer.
