Support Questions
Find answers, ask questions, and share your expertise
Announcements
Alert: Welcome to the Unified Cloudera Community. Former HCC members be sure to read and learn how to activate your account here.

How can I verify to which user my kerberos principal is resolving to in kafka when ranger is enabled

Highlighted

How can I verify to which user my kerberos principal is resolving to in kafka when ranger is enabled

Contributor

I have added sasl.kerberos.principal.to.local.rules = RULE:[1:$1@$0](test1@OPENSTACKLOCAL)s/@.*/test/,DEFAULT

in custom kafka broker in ambari. Now I want to confirm to which user my kerberos principal is resolving to when I try to produce to a topic ?

I tried enabling debug in log4j for ranger authorization in kafka but cannot see any of logs in ranger-kafka.log.

I cannot enable ranger audit logs.

Can some one please help ?

1 REPLY 1

Re: How can I verify to which user my kerberos principal is resolving to in kafka when ranger is enabled

You can look at ranger log/access log to see how kafka policies are downloaded by kafka plugin (which should be running in the context of kafka identify)

Don't have an account?
Coming from Hortonworks? Activate your account here