Uploaded image for project: 'Hadoop Common'
  1. Hadoop Common
  2. HADOOP-10648 Service Authorization Improvements
  3. HADOOP-10650

Add ability to specify a reverse ACL (black list) of users and groups

    XMLWordPrintableJSON

Details

    • Sub-task
    • Status: Closed
    • Major
    • Resolution: Fixed
    • None
    • 2.6.0
    • security
    • None
    • Reviewed

    Description

      Currently , it is possible to define a ACL (user and groups) for a service. To temporarily remove authorization for a set of users, administrator needs to remove the users from the specific group and this may be a lengthy process ( update ldap groups, flush caches on machines).

      If there is a facility to define a reverse ACL for services, then administrator can disable users by specifying the users in reverse ACL. In other words, one can specify a whitelist of users and groups as well as a blacklist of users and groups.

      One can also specify a default blacklist to disable the users from accessing any service.

      Attachments

        1. HADOOP-10650.patch
          12 kB
          Benoy Antony
        2. HADOOP-10650.patch
          13 kB
          Benoy Antony
        3. HADOOP-10650.patch
          13 kB
          Benoy Antony

        Issue Links

          Activity

            People

              benoyantony Benoy Antony
              benoyantony Benoy Antony
              Votes:
              0 Vote for this issue
              Watchers:
              5 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved: