Re: Hadoop Common: Why not re-use the Security model offered by SELINUX?

2015-03-30 Thread Colin P. McCabe
As ATM and Steve have already commented, selinux isn't really comparable to the existing Hadoop security framework. These are just two things that have different functions. The Hadoop security framework needs to deal with authenticating users over the network, managing Kerberos and active directo

Re: Hadoop Common: Why not re-use the Security model offered by SELINUX?

2015-03-28 Thread Steve Loughran
SELinux does nothing for Hadoop cluster security at the data-layer, which is why there tools on top, not only to lock down systems, but to provide better data governance: where did things come from, has it been tainted by merging with sensitive data, etc, etc. Where it could be good is 1. All

Re: Hadoop Common: Why not re-use the Security model offered by SELINUX?

2015-03-27 Thread jay vyas
a Consultancy Services Limited > > > 415/21-24, Kumaran Nagar, > > > Sholinganallur, > > > Old Mahabalipuram, > > > Chennai - 600 119,Tamil Nadu > > > India > > > Cell:- +91-9840141129 > > > Mailto: madhan.sundarara...@tcs.com > > > Website: http://www.tcs.com > &

Re: Hadoop Common: Why not re-use the Security model offered by SELINUX?

2015-03-26 Thread Aaron T. Myers
tainty. IT Services > > Business Solutions > >Consulting > > > > > > > > > > From: Allen Wittenauer > > To: common-dev@hadoop.apache.org > > Date

Re: Hadoop Common: Why not re-use the Security model offered by SELINUX?

2015-03-26 Thread Allen Wittenauer
xperience certainty. IT Services >Business Solutions >Consulting > > > > > From: Allen Wittenauer > To: common-dev@hadoop.apache.org > Date: 03/26/2015 06:51 PM > Subject:Re: Hadoop Common: Why not re-use the Securit

Re: Hadoop Common: Why not re-use the Security model offered by SELINUX?

2015-03-26 Thread Madhan Sundararajan
ience certainty. IT Services Business Solutions Consulting From: Allen Wittenauer To: common-dev@hadoop.apache.org Date: 03/26/2015 06:51 PM Subject: Re: Hadoop Common: Why not re-use the

Re: Hadoop Common: Why not re-use the Security model offered by SELINUX?

2015-03-26 Thread Allen Wittenauer
How would you propose we use SELinux features to support security, especially in a distributed manner where clients might be under different administrative controls? What about the non-Linux platforms that Hadoop runs on? On Mar 26, 2015, at 3:46 AM, Madhan Sundararajan wrote: >

Hadoop Common: Why not re-use the Security model offered by SELINUX?

2015-03-26 Thread Madhan Sundararajan
Team, SELINUX was introduced to bring in a robust security management in Linux OS. In all distributions of Hadoop (Cloudera/Hortonworks/...) one of the pre-installation checklist items is to disable SELINUX in all the nodes of the cluster. Why not re-use the security model offered by SELIN