Support Questions
Find answers, ask questions, and share your expertise
Announcements
Alert: Welcome to the Unified Cloudera Community. Former HCC members be sure to read and learn how to activate your account here.

Ranger Plugins with Kerberos: Users for lookup?

Solved Go to solution
Highlighted

Ranger Plugins with Kerberos: Users for lookup?

Expert Contributor

Hi community,

working through the documentation, I stumbled about some pages regarding Ranger Plugins when enabling Kerberos (Link).

The documentation states the requirement to create some extra users for lookup purposes (such as rangerhdfslookup) for HDFS, HBase, Hive and Knox. The HDP documentation is the only place I found this information.

Is this a mandatory requirement? Why is this user needed?

Hope you can clear this up for me.

Best regards, Benjamin

1 ACCEPTED SOLUTION

Accepted Solutions

Re: Ranger Plugins with Kerberos: Users for lookup?

Expert Contributor

Oh well, I think I found the answer in the community:

"If your cluster is kerberized you'll need one more account usually called "rangerlookup" to facilitate autocompletion of databases, tables etc, with a headless principal and a password (keytab unsupported). The docs talk about a rangerlookup account per service (hdfs, hbase, etc.) but I use only one." (Source: https://community.hortonworks.com/questions/21818/can-proxyuser-group-be-redefined-as-something-else...

Other helpful entries:

https://community.hortonworks.com/questions/12039/ranger-ui-for-hive-plug-in-auto-complete-of-tables...

https://community.hortonworks.com/questions/21145/autocompletion-of-names-not-working-in-ranger.html

https://community.hortonworks.com/questions/432/permissions-necessary-for-the-user-required-to-con.h...

1 REPLY 1

Re: Ranger Plugins with Kerberos: Users for lookup?

Expert Contributor

Oh well, I think I found the answer in the community:

"If your cluster is kerberized you'll need one more account usually called "rangerlookup" to facilitate autocompletion of databases, tables etc, with a headless principal and a password (keytab unsupported). The docs talk about a rangerlookup account per service (hdfs, hbase, etc.) but I use only one." (Source: https://community.hortonworks.com/questions/21818/can-proxyuser-group-be-redefined-as-something-else...

Other helpful entries:

https://community.hortonworks.com/questions/12039/ranger-ui-for-hive-plug-in-auto-complete-of-tables...

https://community.hortonworks.com/questions/21145/autocompletion-of-names-not-working-in-ranger.html

https://community.hortonworks.com/questions/432/permissions-necessary-for-the-user-required-to-con.h...

Don't have an account?
Coming from Hortonworks? Activate your account here