Return-Path: X-Original-To: apmail-ambari-dev-archive@www.apache.org Delivered-To: apmail-ambari-dev-archive@www.apache.org Received: from mail.apache.org (hermes.apache.org [140.211.11.3]) by minotaur.apache.org (Postfix) with SMTP id DCD0B17C41 for ; Wed, 15 Apr 2015 23:54:59 +0000 (UTC) Received: (qmail 15580 invoked by uid 500); 15 Apr 2015 23:54:59 -0000 Delivered-To: apmail-ambari-dev-archive@ambari.apache.org Received: (qmail 15548 invoked by uid 500); 15 Apr 2015 23:54:59 -0000 Mailing-List: contact dev-help@ambari.apache.org; run by ezmlm Precedence: bulk List-Help: List-Unsubscribe: List-Post: List-Id: Reply-To: dev@ambari.apache.org Delivered-To: mailing list dev@ambari.apache.org Received: (qmail 15534 invoked by uid 99); 15 Apr 2015 23:54:59 -0000 Received: from arcas.apache.org (HELO arcas.apache.org) (140.211.11.28) by apache.org (qpsmtpd/0.29) with ESMTP; Wed, 15 Apr 2015 23:54:59 +0000 Date: Wed, 15 Apr 2015 23:54:59 +0000 (UTC) From: "Yusaku Sako (JIRA)" To: dev@ambari.apache.org Message-ID: In-Reply-To: References: Subject: [jira] [Commented] (AMBARI-10507) Local root user's group being assigned to hadoop MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: 7bit X-JIRA-FingerPrint: 30527f35849b9dde25b450d4833f0394 [ https://issues.apache.org/jira/browse/AMBARI-10507?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=14497332#comment-14497332 ] Yusaku Sako commented on AMBARI-10507: -------------------------------------- Committed to branch-2.0.maint. > Local root user's group being assigned to hadoop > ------------------------------------------------ > > Key: AMBARI-10507 > URL: https://issues.apache.org/jira/browse/AMBARI-10507 > Project: Ambari > Issue Type: Bug > Components: ambari-server, security > Affects Versions: 2.0.0 > Reporter: Adam Westerman > Assignee: Adam Westerman > Priority: Critical > Labels: patch, security > Fix For: 2.1.0, 2.0.1 > > Attachments: AMBARI-10507.patch > > Original Estimate: 1h > Remaining Estimate: 1h > > When installing Ranger through Ambari, you have the option to specify DB user names. If you leave the Ranger DB root user configuration db_root_user as the default (which is 'root'), Ambari will erroneously attempt to create a local user named root, and assign it to the group 'hadoop'. This results in local root users being reassigned to the group 'hadoop'. In addition, both the db_user param and audit_db_name param are erroneously being used to create local users (granted, with less severe consequences). -- This message was sent by Atlassian JIRA (v6.3.4#6332)