Support Questions
Find answers, ask questions, and share your expertise
Announcements
Alert: Welcome to the Unified Cloudera Community. Former HCC members be sure to read and learn how to activate your account here.

Ranger KMS Tutorial

Solved Go to solution
Highlighted

Ranger KMS Tutorial

Expert Contributor

Hi,

Is there a Ranger KMS tutorial that we can try?

Thanks,

Avijeet

1 ACCEPTED SOLUTION

Accepted Solutions
Highlighted

Re: Ranger KMS Tutorial

5 REPLIES 5
Highlighted

Re: Ranger KMS Tutorial

Highlighted

Re: Ranger KMS Tutorial

Explorer

@Avijeet Dash I have installed ranger and ranger kms and setup all the configurations and everything is working fine.

I have created encryption zone in hdfs and in the policy i have mentioned two users(user 1 and user 2) to access this encryption zone, they are able to access this encryption zone . I want to set permissions to encryption zone in such a way that user1 should have read and write access and user 2 should have only read access?how can we define this ?

Highlighted

Re: Ranger KMS Tutorial

Expert Contributor

@khadeer mhmd

I believe the DECRYPT_EEK permission decides the read/write access, I don't think there are 2 different permissions. you migth try only read kind of permission using HDFS plugin.

Re: Ranger KMS Tutorial

Hi @khadeer mhmd, Have you installed Ranger KMS in HDP2.5 sandbox?

I am getting below error while adding Ranger KMS service in Ambari (HDP 2.5 sandbox).

Caught an exception while executing custom service command: <class 'ambari_agent.AgentException.AgentException'>: 'Script /var/lib/ambari-agent/cache/common-services/RANGER_KMS/0.5.0.2.3/package/scripts/kms_server.py does not exist'; 'Script /var/lib/ambari-agent/cache/common-services/RANGER_KMS/0.5.0.2.3/package/scripts/kms_server.py does not exist'

Could anyone please help me on this issue.

Highlighted

Re: Ranger KMS Tutorial

New Contributor

@khadeer mhmd

The owner of the file has both the read and write access and the others will have only the read access.

Don't have an account?
Coming from Hortonworks? Activate your account here