[ 
https://issues.apache.org/jira/browse/AMBARI-15040?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=15382059#comment-15382059
 ] 

Henning Kropp commented on AMBARI-15040:
----------------------------------------

Why only with PAM? For an enterprise environment it is not acceptable to have 
to manage (admin) privileges with a separate tool. You typically aim for a 
centralized approach with AD or LDAP integration. So this should likely also be 
applied to LDAP authentication as well.

> In PAM mode, support only group base authorization in Ambari
> ------------------------------------------------------------
>
>                 Key: AMBARI-15040
>                 URL: https://issues.apache.org/jira/browse/AMBARI-15040
>             Project: Ambari
>          Issue Type: Story
>          Components: ambari-server
>    Affects Versions: 2.1.0, 2.2.0
>            Reporter: Tuong Truong
>              Labels: authorization, security-groups
>
> Once PAM mode is enable for Ambari, user authorization should not be 
> supported in order to avoid security hold or ambiguity.



--
This message was sent by Atlassian JIRA
(v6.3.4#6332)

Reply via email to