[ 
https://issues.apache.org/jira/browse/RANGER-606?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=14969803#comment-14969803
 ] 

Madhan Neethiraj edited comment on RANGER-606 at 10/22/15 8:16 PM:
-------------------------------------------------------------------

Details of the current implementation along with few usecases is available in 
the documentation here - 
https://cwiki.apache.org/confluence/display/RANGER/Deny-conditions+and+excludes+in+Ranger+policies.

Also, a lot of discussions on this was made in mailing list 
'[email protected]'; archive of this thread is available at 
http://mail-archives.apache.org/mod_mbox/ranger-user/201510.mbox/%[email protected]%3e

Can you please review the details and vote as below?
 +1: current implementation is good
 -1: current implementation is not good. Please add alternate design proposal 
for each usecase covered in the documentation.
  0: no comments


was (Author: madhan.neethiraj):
Details of the current implementation along with few usecases is available in 
the documentation here - 
https://cwiki.apache.org/confluence/display/RANGER/Deny-conditions+and+excludes+in+Ranger+policies.

Can you please review the details and vote as below?
 +1: current implementation is good
 -1: current implementation is not good. Please add alternate design proposal 
for each usecase covered in the documentation.
  0: no comments

> Add support for deny policies 
> ------------------------------
>
>                 Key: RANGER-606
>                 URL: https://issues.apache.org/jira/browse/RANGER-606
>             Project: Ranger
>          Issue Type: Bug
>          Components: admin, plugins
>    Affects Versions: 0.5.0
>            Reporter: Madhan Neethiraj
>            Assignee: Madhan Neethiraj
>             Fix For: 0.5.0
>
>
> Currently Ranger supports creation of policies that can allow access when 
> specific conditions are met (for example, resources, user, groups, 
> access-type, custom-conditions..). In addition to this, having the ability to 
> create policies that deny access for specific conditions will help address 
> many usecases, like:
> - deny access for specific users/groups/ip-addresses/time-of-day
> - deny access when specific conditions are met - like 
> resources/users/groups/access-types/custom-conditions



--
This message was sent by Atlassian JIRA
(v6.3.4#6332)

Reply via email to