Support Questions

Find answers, ask questions, and share your expertise

HDP 2.5 Ranger dont have "Deny" or "Policy Condition"

avatar
Contributor

Hi,

When I login in the Sandbox 2.5 (VMWare).

Ranger don't contain any option for "Deny" or "Policy Condition" only through "Tag based..".

In the documentation a screendump and description is showed with Hive and "Deny" condition.

Link: https://docs.hortonworks.com/HDPDocuments/HDP2/HDP-2.5.0/bk_security/content/about_ranger_policies.h...

Questions

1) Is there anything that which need to be enable to get this to work?

2) Is "Policy Condition" possible in Resource-Based Policy or only in "Tag based.."

/ Anders

8836-untitled.png

1 ACCEPTED SOLUTION

avatar
Expert Contributor

There are two types of policies in Ranger - resource based policies and tag based policies. The Policy Conditions only apply to tag based policies. If you go to the Ranger Admin UI and click on Access Manager > Tag Based Policies then click on your tag service you'll be able to add a tag based policy with the Policy Conditions you require. There's more information here: Tag Based Policies

View solution in original post

4 REPLIES 4

avatar
Expert Contributor

@Anders Boje Larsen Deny policies are only enabled for service definitions that have property enableDenyAndExceptionsInPolicies = true and are off by default for all services. You'll need to update the service definitions for the services you want deny policies for. This page has the required information: Deny-conditions and excludes in Ranger policies

avatar
Contributor

Thx @Terry Stebbens, would this also enable "Policy conditions" option?

8806-capture.png

avatar
Expert Contributor

There are two types of policies in Ranger - resource based policies and tag based policies. The Policy Conditions only apply to tag based policies. If you go to the Ranger Admin UI and click on Access Manager > Tag Based Policies then click on your tag service you'll be able to add a tag based policy with the Policy Conditions you require. There's more information here: Tag Based Policies

avatar
Contributor

Okay.. Was hoping this feature could be or will be avalible in Resource Based. One case could be data in HDFS which only should be allowed to acces data based on location or a time perioed.