hadoop-common-user mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From Benjamin Ross <br...@Lattice-Engines.com>
Subject allow all users to decrypt?
Date Tue, 08 Nov 2016 13:44:51 GMT
I'm in the process of configuring our system for hadoop encryption.  We're nearly complete
- one of the last issues is that we have a build user that needs to decrypt data to read it
from hdfs.  The issue is that the build user is an Active Directory user, so the username
is DOMAIN\build, rather than just build.  I can't add this username to ranger because the
ranger UI doesn't allow adding the \ character.

Ideally I would like all users to be able to encrypt and decrypt data from hdfs.  It just
would make our lives a lot easier - it's explicitly what we want.

Is there any way to do this?  Alternatively, is there any way to add the user DOMAIN\build
to ranger?

Worst case scenario, I can just modify the test to set HADOOP_USER_NAME to be build, but I'd
prefer not to do that.

Thanks in advance,

This message has been scanned for malware by Websense. www.websense.com

View raw message