Uploaded image for project: 'Ranger'
  1. Ranger
  2. RANGER-1606

Case insensitive user/group ACL matching

    XMLWordPrintableJSON

    Details

    • Type: Improvement
    • Status: Open
    • Priority: Major
    • Resolution: Unresolved
    • Affects Version/s: 0.6.0
    • Fix Version/s: None
    • Component/s: admin, Ranger, usersync
    • Labels:
      None
    • Environment:
      HDP 2.5

      Description

      Make ACL matching case insensitive for users/groups.

      Ranger imports LDAP users/groups while preserving case by default, but Active Directory environments with uppercase users/groups often import to lowercase at the OS level (eg.Centrify), causing unintuitive ACL mismatches as Ranger is doing case sensitive ACL matching. I've seen this issue at a couple of large financials now and while it's easily to workaround by configuring lowercasing on user/group imports it could be handled better automatically similar to the way Ambari changed to make user/group handling case insensitive (AMBARI-17383), rather than having to fix it on an environment by environment basis.

      This could have a config setting to disable case insensitive ACL matches to maintain backwards compatibility if needed.

        Attachments

          Activity

            People

            • Assignee:
              Unassigned
              Reporter:
              harisekhon Hari Sekhon
            • Votes:
              0 Vote for this issue
              Watchers:
              1 Start watching this issue

              Dates

              • Created:
                Updated: