Our Community is getting an upgrade! To get everything ready for the relaunch, we’ll be placing the site in read-only mode starting September 21st.
We really appreciate your understanding while we get things set up behind the scenes. Catch up on all the exciting details about the move here.
Need help or have questions? Drop us a line at [email protected]

Support Questions

Find answers, ask questions, and share your expertise
Announcements
Share your experience with Cloudera on G2 and get a $25 Amazon Gift card.
Hi, I'm CLEO! Something exciting is coming to the Community. Stay Tuned!

Ranger policy - logical AND between domain groups

avatar
New Contributor

Hello.

Is there a way in ranger policies to  add permissions for users that are only in both of domain group1 and domain group2 (logical AND between groups). Because there is always a logical OR between users and groups in ranger policies??

1 ACCEPTED SOLUTION

avatar
Master Mentor

@arturbrandys2 

Policies are defined by the end services utilizing Ranger.  Ranger also does not make authorization decisions.  Each service runs a client that downloads the latest policy definitions json from Ranger for its specific service.  The end service then uses those policy definitions to handle authorizations for the service.  

Ranger does not offer a method to define an "and" relationship between multiple groups.  Even if this was possible, the end services would need to also be modified to handle that association when making access decisions based on the downloaded json.


If you found any of the suggestions/solutions provided helped you with your issue, please take a moment to login and click "Accept as Solution" on one or more of them that helped.

Thank you,
Matt

View solution in original post

1 REPLY 1

avatar
Master Mentor

@arturbrandys2 

Policies are defined by the end services utilizing Ranger.  Ranger also does not make authorization decisions.  Each service runs a client that downloads the latest policy definitions json from Ranger for its specific service.  The end service then uses those policy definitions to handle authorizations for the service.  

Ranger does not offer a method to define an "and" relationship between multiple groups.  Even if this was possible, the end services would need to also be modified to handle that association when making access decisions based on the downloaded json.


If you found any of the suggestions/solutions provided helped you with your issue, please take a moment to login and click "Accept as Solution" on one or more of them that helped.

Thank you,
Matt