[
https://issues.apache.org/jira/browse/RANGER-5703?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
]
Ramachandran Krishnan updated RANGER-5703:
------------------------------------------
Summary: Removing the unixauthservice Module from Apache Ranger & keep
UserGroupSync and Admin local PAM (was: Removing the unixauthservice Module
from Apache Ranger)
> Removing the unixauthservice Module from Apache Ranger & keep UserGroupSync
> and Admin local PAM
> -----------------------------------------------------------------------------------------------
>
> Key: RANGER-5703
> URL: https://issues.apache.org/jira/browse/RANGER-5703
> Project: Ranger
> Issue Type: Task
> Components: Ranger
> Reporter: Ramachandran Krishnan
> Assignee: Ramachandran Krishnan
> Priority: Major
> Fix For: 3.0.0, 2.9.0
>
> Time Spent: 20m
> Remaining Estimate: 0h
>
> Remove the legacy _remote_ Unix authentication stack from Ranger.
> UserGroupSync and Admin _local_ PAM stay as-is.
> Ranger today mixes three separate concerns under “Unix”:
> * UserGroupSync (LDAP/file/passwd → Admin)
> * Admin local PAM login ({{{}PamLoginModule{}}} on the Admin host)
> * Remote Unix login (Admin → UserSync TCP 5151 → native validators)
> The last path adds operational complexity and security surface with little
> benefit for most deployments.
> *Scope*
> _Delete modules:_ {{{}unixauthservice{}}}, {{{}unixauthclient{}}},
> {{{}unixauthnative{}}}, {{unixauthpam}}
> *_Add / relocate:_*
> * {{UserSyncService}} — new usersync JVM entry point (HA,
> {{{}UserGroupSync{}}}, metrics)
> * Usersync install scripts/config: {{unixauthservice/}} → {{ugsync/}}
> * Local PAM JAAS classes ({{{}PamLoginModule{}}}, etc.): {{unixauthclient/}}
> → {{security-admin/}}
> *_Remove behavior:_*
> * TCP listener on port 5151
> * {{RemoteUnixLoginModule}}
> * Native validators ({{{}credValidator.uexe{}}},
> {{{}pamCredValidator.uexe{}}})
> *Unchanged*
> * UserGroupSync (LDAP, file, Unix passwd/group sources)
> * Admin local PAM ({{{}ranger.pam.service{}}}, libpam4j)
> * LDAP / AD / Kerberos / JDBC Admin authentication
> *Upgrade impact*
> ||Flow||Port 5151?||After change||
> |UserGroupSync|No|Unchanged|
> |Admin local PAM|No|Unchanged|
> |Remote Unix login|Yes|Removed|
> _Affected before upgrade:_ Admin login with {{authentication_method=UNIX}}
> and {{ranger.pam.authentication.enabled=false}} (password check on UserSync
> via port 5151).
> _{*}Migration{*}:_ Configure local PAM on Admin ({{{}ranger.pam.service{}}})
> or switch to LDAP/AD before upgrade.
> After this change, {{UNIX}} and {{PAM}} both use local {{PamLoginModule}} on
> the Admin host.
--
This message was sent by Atlassian Jira
(v8.20.10#820010)