Uploaded image for project: 'Ranger'
  1. Ranger
  2. RANGER-1606

Case insensitive user/group ACL matching

    XMLWordPrintableJSON

Details

    • Improvement
    • Status: Open
    • Major
    • Resolution: Unresolved
    • 0.6.0
    • None
    • admin, Ranger, usersync
    • None
    • HDP 2.5

    Description

      Make ACL matching case insensitive for users/groups.

      Ranger imports LDAP users/groups while preserving case by default, but Active Directory environments with uppercase users/groups often import to lowercase at the OS level (eg.Centrify), causing unintuitive ACL mismatches as Ranger is doing case sensitive ACL matching. I've seen this issue at a couple of large financials now and while it's easily to workaround by configuring lowercasing on user/group imports it could be handled better automatically similar to the way Ambari changed to make user/group handling case insensitive (AMBARI-17383), rather than having to fix it on an environment by environment basis.

      This could have a config setting to disable case insensitive ACL matches to maintain backwards compatibility if needed.

      Attachments

        Activity

          People

            Unassigned Unassigned
            harisekhon Hari Sekhon
            Votes:
            0 Vote for this issue
            Watchers:
            1 Start watching this issue

            Dates

              Created:
              Updated: