[ 
https://issues.apache.org/jira/browse/HIVE-78?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=12652091#action_12652091
 ] 

Ashish Thusoo commented on HIVE-78:
-----------------------------------

On the first looks Realms seems to be a nice fit for this problem.

One capability that is missing there and which may become an issue later is the 
ability to compose roles into higher level roles. To me it seems that roles are 
strictly flat and are not hierarchical, so I cannot create an admin role that 
has the basic roles within it . Can this be achieved with Realms? I have not 
used it before so I am not sure that if it is achievable?

The other issue that I can think of is whether Realms is generic enough to 
protect any kind of a resource and not just limited to web resourrces. We have 
tables and partitions, servers etc. Could you elaborate on how this would work 
for the capabilities that I listed in my previous comments.



> Authentication infrastructure for Hive
> --------------------------------------
>
>                 Key: HIVE-78
>                 URL: https://issues.apache.org/jira/browse/HIVE-78
>             Project: Hadoop Hive
>          Issue Type: New Feature
>          Components: Server Infrastructure
>            Reporter: Ashish Thusoo
>            Assignee: Edward Capriolo
>
> Allow hive to integrate with existing user repositories for authentication 
> and authorization infromation.

-- 
This message is automatically generated by JIRA.
-
You can reply to this email to add a comment to the issue online.

Reply via email to