Our Community is getting an upgrade! To get everything ready for the relaunch, we’ll be placing the site in read-only mode starting September 21st.
We really appreciate your understanding while we get things set up behind the scenes. Catch up on all the exciting details about the move here.
Need help or have questions? Drop us a line at [email protected]

Support Questions

Find answers, ask questions, and share your expertise
Announcements
Share your experience with Cloudera on G2 and get a $25 Amazon Gift card.
Hi, I'm CLEO! Something exciting is coming to the Community. Stay Tuned!

Knox not downloading Ranger polices

avatar
Contributor

I'm able to list Knox topologies in Ranger and created Ranger policy for webhdfs. Ran the script ranger-knox-plugin.sh and created ranger-security, audits and policymgr-ssl xmls.
Configured one topology for webhdfs in knox and added below
<provider>
<role>authorization</role>
<name>XASecurePDPKnox</name>
<enabled>true</enabled>
</provider>

When I run curl to webhdfs I'm getting 403 error and I could see in Ranger audits access is denied by ranger-acl.

I could nail it down to policy not getting downloaded from Ranger but don't see any error in Knox gateway.log even after setting the logging to debug.

Knox is enabled with self-signed and ranger with no ssl. I imported knox cert to Ranger cacert.

Am I missing any steps in Knox configuration that could be preventing the policy download?

Any help is appreciated!

1 REPLY 1

avatar
Master Collaborator

Hello @Hadoop16  Can you try adding public group to the ranger knox policy and then run webhdfs curl command