Uploaded image for project: 'Ranger'
  1. Ranger
  2. RANGER-977

Ranger KMS default policies should include hdfs & hive

    XMLWordPrintableJSON

Details

    • Bug
    • Status: Resolved
    • Major
    • Resolution: Fixed
    • 0.5.0
    • 0.6.0
    • Ranger
    • None

    Description

      Currently when Ranger KMS is installed, only keyadmin user has the permissions.
      Users have to manually create user nn and assign policies for this user for the encryption zone creation to work. This should be added by default. Also nn is a kerberos principal which should be mapped to hdfs user, for which default policy should be added after KMS is installed. (with generate_eek and get_matadata operations). Investigate why KMS is not performing this mapping and resolve it. In addition address this use-case for making hive encryption zones work as well.

      Attachments

        Issue Links

          Activity

            People

              spolavarapu Sailaja Polavarapu
              spolavarapu Sailaja Polavarapu
              Votes:
              0 Vote for this issue
              Watchers:
              2 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved: