Return-Path: X-Original-To: archive-asf-public-internal@cust-asf2.ponee.io Delivered-To: archive-asf-public-internal@cust-asf2.ponee.io Received: from cust-asf.ponee.io (cust-asf.ponee.io [163.172.22.183]) by cust-asf2.ponee.io (Postfix) with ESMTP id 012BB200CEC for ; Mon, 21 Aug 2017 23:06:29 +0200 (CEST) Received: by cust-asf.ponee.io (Postfix) id F361D165AC3; Mon, 21 Aug 2017 21:06:28 +0000 (UTC) Delivered-To: archive-asf-public@cust-asf.ponee.io Received: from mail.apache.org (hermes.apache.org [140.211.11.3]) by cust-asf.ponee.io (Postfix) with SMTP id 6A37F165AC2 for ; Mon, 21 Aug 2017 23:06:28 +0200 (CEST) Received: (qmail 20112 invoked by uid 500); 21 Aug 2017 21:06:27 -0000 Mailing-List: contact user-help@zookeeper.apache.org; run by ezmlm Precedence: bulk List-Help: List-Unsubscribe: List-Post: List-Id: Reply-To: user@zookeeper.apache.org Delivered-To: mailing list user@zookeeper.apache.org Received: (qmail 20101 invoked by uid 99); 21 Aug 2017 21:06:27 -0000 Received: from mail-relay.apache.org (HELO mail-relay.apache.org) (140.211.11.15) by apache.org (qpsmtpd/0.29) with ESMTP; Mon, 21 Aug 2017 21:06:27 +0000 Received: from auth2-smtp.messagingengine.com (auth2-smtp.messagingengine.com [66.111.4.228]) by mail-relay.apache.org (ASF Mail Server at mail-relay.apache.org) with ESMTPSA id D81F31A002B for ; Mon, 21 Aug 2017 21:06:26 +0000 (UTC) Received: from compute6.internal (compute6.nyi.internal [10.202.2.46]) by mailauth.nyi.internal (Postfix) with ESMTP id F2BA821B6B for ; Mon, 21 Aug 2017 17:06:25 -0400 (EDT) Received: from web1 ([10.202.2.211]) by compute6.internal (MEProxy); Mon, 21 Aug 2017 17:06:25 -0400 X-ME-Sender: Received: by mailuser.nyi.internal (Postfix, from userid 99) id D35B5956F6; Mon, 21 Aug 2017 17:06:25 -0400 (EDT) Message-Id: <1503349585.3811895.1080497040.222C50B9@webmail.messagingengine.com> From: Abraham Fine To: user@zookeeper.apache.org MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" X-Mailer: MessagingEngine.com Webmail Interface - ajax-21c69044 Subject: Re: How to prevent others from accessing our zookeeper service? In-Reply-To: <23F1C6CA-0DAA-48D8-BED6-D2A33AEE6399@163.com> References: <23F1C6CA-0DAA-48D8-BED6-D2A33AEE6399@163.com> Date: Mon, 21 Aug 2017 14:06:25 -0700 archived-at: Mon, 21 Aug 2017 21:06:29 -0000 My understanding is that there is no current way to keep anonymous users from connecting at all.=20 There have been numerous proposals to use SASL to solve this problem and there is an open PR by Michael Han (https://github.com/apache/zookeeper/pull/118), but nothing of the sort has been committed yet.=20 Thanks, Abe On Mon, Aug 21, 2017, at 01:34, baidu wrote: > Hi,=20 >=20 > I=E2=80=99ve read documents about zookeeper authentication and acl. To my > knowledge, this mechanism can only control the access of specified > znodes. To prevent others from accessing our zookeeper service, we need > set acl for all the znodes.=20 >=20 > Is there any other way to do this?=20 >=20 >=20 > Best wishes, > Dan