[ 
https://issues.apache.org/jira/browse/RANGER-980?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=15439441#comment-15439441
 ] 

Yan commented on RANGER-980:
----------------------------

I can see pros and cons on both options. For the existing approach of retaining 
the deleted users/groups, as pointed out by Don, it can avoid human errors. On 
the other hand, it could bloat the Ranger db if the user is deleted indeed. 
Plus if later on another namesake is added in the provider, he might be given 
the same privileges as his former namesake automatically. 

I am wondering whether we can introduce a provider-specific boolean to 
determine whether to sync the deletion from the provider. And/or
automatically disable the Ranger user if (s)he is absent from the provider.

> User sync does not delete users if they do not exist anymore
> ------------------------------------------------------------
>
>                 Key: RANGER-980
>                 URL: https://issues.apache.org/jira/browse/RANGER-980
>             Project: Ranger
>          Issue Type: Bug
>          Components: usersync
>    Affects Versions: 0.6.0, 0.5.3
>            Reporter: Bolke de Bruin
>            Priority: Critical
>              Labels: security
>         Attachments: 
> 0001-RANGER-980-User-sync-does-not-delete-users-if-they-d.patch, 
> RANGER-980.patch
>
>
> usersync for all sources creates users and groups, but does not delete them 
> from Ranger's database if these users and groups do not exists anymore in the 
> original source.
> So if you have for example a user called "bob" and bob leaves the company his 
> access rights will continue to exist in Ranger. If a new employee comes in 
> that is also "bob" he is immediately granted the same access as the previous 
> employee. This creates security incidents.
> In a reasonable complex company it cannot be expected that another user 
> administration is being taken care of, while deletion could and should happen 
> automatically.



--
This message was sent by Atlassian JIRA
(v6.3.4#6332)

Reply via email to