Support Questions
Find answers, ask questions, and share your expertise
Announcements
Alert: Welcome to the Unified Cloudera Community. Former HCC members be sure to read and learn how to activate your account here.

if i am changing permissions on hdfs files from CLI and i am applying policies for the same file from Ranger Ui then which will take predence?hadoop ACL or Ranger Policies

Re: if i am changing permissions on hdfs files from CLI and i am applying policies for the same file from Ranger Ui then which will take predence?hadoop ACL or Ranger Policies

xasecure.add-hadoop-authorization= ? what should i do withis configuration then it should be true or false and what about dfs.namenode.acl.permissions ?

Highlighted

Re: if i am changing permissions on hdfs files from CLI and i am applying policies for the same file from Ranger Ui then which will take predence?hadoop ACL or Ranger Policies

but if xasecure.add-hadoop-authorization should be at true. then ranger policies are not effective hadoop acl takes precedence

Highlighted

Re: if i am changing permissions on hdfs files from CLI and i am applying policies for the same file from Ranger Ui then which will take predence?hadoop ACL or Ranger Policies

@khushi kalra xasecure.add-hadoop-authorization should be at true. This enables default HDFS policy if ranger fails (no policy in ranger)

Highlighted

Re: if i am changing permissions on hdfs files from CLI and i am applying policies for the same file from Ranger Ui then which will take predence?hadoop ACL or Ranger Policies

but if xasecure.add-hadoop-authorization should be at true. then ranger policies are not effective hadoop acl takes precedence @ Abdelkrim Hadjidj

Highlighted

Re: if i am changing permissions on hdfs files from CLI and i am applying policies for the same file from Ranger Ui then which will take predence?hadoop ACL or Ranger Policies

I have created a file and blocked a user from acl permissions and created a policy on ranger where he can access it but If user goes through ambari then he cannot go in but if we go through command line then we can create a file in their

Highlighted

Re: if i am changing permissions on hdfs files from CLI and i am applying policies for the same file from Ranger Ui then which will take predence?hadoop ACL or Ranger Policies

I have created a file and blocked a user from acl permissions and created a policy on ranger where he can access it but If user goes through ambari then he cannot go in but if we go through command line then we can create a file in their @ Abdelkrim Hadjidj

Highlighted

Re: if i am changing permissions on hdfs files from CLI and i am applying policies for the same file from Ranger Ui then which will take predence?hadoop ACL or Ranger Policies

I have created a file and blocked a user from acl permissions and created a policy on ranger where he can access it but If user goes through ambari then he cannot go in but if we go through command line then we can create a file in their @ Abdelkrim Hadjidj

Highlighted

Re: if i am changing permissions on hdfs files from CLI and i am applying policies for the same file from Ranger Ui then which will take predence?hadoop ACL or Ranger Policies

@khushi kalra No, Ranger policies will always take precedence if HDFS plugin is installed and if a policy for the target exists in Ranger.

When you look to the description of xasecure.add-hadoop-authorization you can read that its working is conditioned by Ranger authorization failure:

<property>		
	<name>xasecure.add-hadoop-authorization</name>		
	<value>true</value>		
	<description>			
		Enable/Disable the default hadoop authorization (based on			rwxrwxrwx permission on the resource) if Ranger Authorization fails.		
	</description>	
</property> 

This means that the Hadoop authorization works if and only if Ranger has no authorization for the folder.

You can check this, create a folder in HDFS a delete the read/write permission for a other users (rwx------). Create a Ranger policy to give a user (different from the owner) the right to read and write and test if you can access the folder

Highlighted

Re: if i am changing permissions on hdfs files from CLI and i am applying policies for the same file from Ranger Ui then which will take predence?hadoop ACL or Ranger Policies

then if hadoop acls have all the effects then what is the use of ranger? and in real cluster we cannot turn the acl permissions to false.

Highlighted

Re: if i am changing permissions on hdfs files from CLI and i am applying policies for the same file from Ranger Ui then which will take predence?hadoop ACL or Ranger Policies

then if hadoop acls have all the effects then what is the use of ranger? and in real cluster we cannot turn the acl permissions to false @ Abdelkrim Hadjidj , Ramesh Mani

Don't have an account?
Coming from Hortonworks? Activate your account here