Member since
09-18-2015
3274
Posts
1159
Kudos Received
426
Solutions
My Accepted Solutions
| Title | Views | Posted |
|---|---|---|
| 2568 | 11-01-2016 05:43 PM | |
| 8500 | 11-01-2016 05:36 PM | |
| 4860 | 07-01-2016 03:20 PM | |
| 8181 | 05-25-2016 11:36 AM | |
| 4335 | 05-24-2016 05:27 PM |
11-06-2015
09:17 PM
1 Kudo
@bganesan@hortonworks.com @bdurai@hortonworks.com Balaji and Bosco, Do we need to worry about HADOOP_USER_NAME if we enable LDAP mapping for HDFS by following this blog? BLOG No kerberos in place.
... View more
11-06-2015
09:09 PM
Do you have LDAP enabled for HDFS? http://hortonworks.com/blog/hadoop-groupmapping-ldap-integration/ @Ali Bajwa
... View more
11-06-2015
08:05 PM
@Ali Bajwa Thanks for sharing this. Is it valid for AD logins? User A logs into the system with his AD credentials, HDFS or Hive ACL's kicks in for authorization. Is it possible for user A to export HADOOP_USER_NAME=hdfs and take over permissions?
... View more
11-06-2015
08:02 PM
@Andrew Grande Could you elaborate more on "fraction of components" ? User A logs into the system with his AD credentials, HDFS or Hive ACL's kicks in for authorization. I agree with you that Kerberos add more security because all the benefits/features it comes with.
... View more
11-06-2015
07:52 PM
@Ali Bajwa @rgarcia@hortonworks.com This is great discussions. Could you share an example of HADOOP_USER_NAME?
... View more
11-06-2015
07:04 PM
3 Kudos
Bringing up couple of FAQ 1) Do we have to use Kerberos? We are ok with AD/LDAP authentication 2) Will Ranger work without Kerberos? Do we need Kerberos for Ranger to secure Ranger?
... View more
Labels:
- Labels:
-
Apache Ranger
11-06-2015
06:37 PM
As of HDP 2.3.2 ..above components are supported by Ranger For Storm @hfaouaz@hortonworks.com Yes, Storm and Kafka needs to be kerberized
... View more
11-06-2015
02:34 PM
1 Kudo
@hrongali@hortonworks.com This document will save you lot of headache. Link Page 12 is the most important. Please feel free to reach out to me anytime. Adding important information regarding service account link Use the Skip Group Modifications option to not modify the Linux groups in the cluster. Choosing this option is typically required if your environment manages groups using LDAP and not on the local Linux machines.
... View more
11-06-2015
12:01 PM
@Artem Ervits I have accepted Deepesh response as Best Answer. Please let me know your feedback
... View more