Member since
06-13-2016
10
Posts
30
Kudos Received
5
Solutions
My Accepted Solutions
Title | Views | Posted |
---|---|---|
932 | 04-02-2018 05:44 AM | |
2179 | 12-25-2017 06:50 AM | |
772 | 09-29-2017 04:44 AM | |
2261 | 06-28-2017 06:38 PM | |
745 | 03-29-2017 09:22 AM |
04-02-2018
05:44 AM
1 Kudo
Express or rolling upgrade stops all the services including Knox, but it does not impact upgrade process since client would have got cookie and it will be able to access ambari until the current session is alive or cookie is not lost/expired. Resoultion if cookie is lost/session is expired: client should use local login to access the Ambari and proceed further. eg: <ambari_host:ambari_port>/#/login/local
... View more
12-25-2017
06:50 AM
1 Kudo
Please, refer to the steps in https://community.hortonworks.com/articles/15159/securing-solr-collections-with-ranger-kerberos.html
... View more
09-29-2017
04:44 AM
3 Kudos
Try this REST call- http://<ranger_admin_url>/service/assets/accessAudit?repoType=3&resourceTable=db_1/test_table&resourceType=@table
... View more
06-28-2017
06:38 PM
5 Kudos
In case of spark-hive client, if no database is specified in the connection url, it uses default db and tries to use that, since there is no policy configured for default db it fails. So, create a Ranger policy for default db granting access, whereas in case of HSI client the connection doesn't use any database.
... View more
03-30-2017
04:21 PM
1 Kudo
@Deepak Sharma , when you say it worked, I am expecting, that you didn't do 2-way ssl and it's only one way by storing HS2 certificate in Knox host. Please confirm.
... View more
03-29-2017
11:41 PM
3 Kudos
@li zhen Few questions 1- Is this a HA cluster? If so, is Ranger configured to talk to LoadBalancer. If Loadbalancer is configured then there is an additional step that should be done as defined in this docs. https://docs.hortonworks.com/HDPDocuments/Ambari-2.4.1.0/bk_ambari-upgrade/content/upgrading_HDP_post_upgrade_tasks_ranger_kerberos.html 2- is this cluster initially simple and later kerberos is enabled? 3- Also for any download request, you will notice 401 followed by 200(if there are changes to policies in repo) or 401 followed by 304(when there is no change in policies for this repo)
... View more
03-29-2017
09:22 AM
5 Kudos
As Knox interacts with Ranger, please make sure that Ranger Admin cert is in Knox truststore(which is cacerts) on Knox host.
... View more
03-27-2017
09:01 PM
2 Kudos
1- check if hive.server2.use.SSL property is set to true on Hive front , 2- make sure the HS2 host certificate(that exists in /etc/security/serverKeys) is copied to cacerts on knox host 3- make sure the knox topology is referring to https://<hiveserver2_host>:<port>;
... View more
06-13-2016
09:05 AM
3 Kudos
What version of Ambari are you relying on?
... View more