Member since
09-18-2015
3274
Posts
1159
Kudos Received
426
Solutions
My Accepted Solutions
| Title | Views | Posted |
|---|---|---|
| 2744 | 11-01-2016 05:43 PM | |
| 9407 | 11-01-2016 05:36 PM | |
| 5113 | 07-01-2016 03:20 PM | |
| 8572 | 05-25-2016 11:36 AM | |
| 4723 | 05-24-2016 05:27 PM |
01-31-2016
04:35 PM
@Anna Shaverdian see this https://community.hortonworks.com/articles/12699/ranger-and-kafka-integration-faq.html
... View more
01-31-2016
04:31 PM
@Benson Shih Just created an article based on this https://community.hortonworks.com/articles/12699/ranger-and-kafka-integration-faq.html Very useful to resolve this issue.
... View more
01-31-2016
04:30 PM
2 Kudos
Original Article Can I authorize access to Kafka over a non-secure channel via Ranger? Yes. you can control access by ip-address. Can I authorize access to Kafka over non-secure channel by user/user-groups? No, one can’t use user/group based access to authorize Kafka access over a non-secure channel. This is because it isn't possible to assert client’s identity over the non-secure channel. Why do we have to specify public user group on all policies items created for authorizing Kafka access over non-secure channel?
Kafka can’t assert the identity of client user over a non-secure channel. Thus, Kafka treats all users for such access as an anonymous user (a special user literally named ANONYMOUS ). Ranger's public user group is a means to model all users which, of course, includes this anonymous user ( ANONYMOUS ). What are the specific things to watch out for when setting up authorization for accessing Kafka over non-secure channel?
Make sure that all broker-ips have Kafka admin access to all topics, i.e. *.
Make sure no publishers or consumers are running on broker nodes that need access control. Since broker ips have open access it isn’t possible to control access on those nodes. Please take time to read the original article.
... View more
01-31-2016
04:22 PM
@Benson Shih See this https://cwiki.apache.org/confluence/display/RANGER/Kafka+Plugin#KafkaPlugin-CanIauthorizeraccesstoKafkaoveranon-securechannelviaRanger?
... View more
01-31-2016
03:41 PM
Thanks @Paul Codding for taking care of this...very helpful to have in official docs.
... View more
01-31-2016
03:40 PM
@William Gonzalez Thanks for raising this!!
... View more
01-31-2016
03:36 PM
@luc tiber I agree with your last comments and glad that you are trying latest version. Please submit your feedback once you fix the issue.
... View more
01-31-2016
02:12 PM
1 Kudo
Tools in use: HBase shell and Zeppelin
User demouser needs access to HBase table called PRICES.
User zeppelin needs the same access to run few queries.
You can run this demo by using Hortonworks Sandbox
... View more
01-31-2016
02:10 PM
@subhash parise Take a look on this demo If you are using Ranger then you don't have to setup anything except user authorization.
... View more