Hi Amithsha, In addition, as he is the superadmin, hdfs can access any data and is not submitted to Ranger security. Therefore Kerberos authentication is a very important step if you want to protect the data in HDFS.
Regards, Loïc Loïc CHANEL System & virtualization engineer TO - XaaS Ind - Worldline (Villeurbanne, France) 2016-03-29 13:56 GMT+02:00 Sachin Janani <sachin_jan...@persistent.com>: > Hi Amith, > > If you do “export HADOOP_USER_NAME=hdfs” then hdfs user will be used. This > is because you don’t have any mechanism to authenticate the user. To > authenticate you need to kerberized the cluster. > Hope it answers your question. > > Regards, > Sachin Janani > > > > > > *From:* Amith sha [mailto:amithsh...@gmail.com] > *Sent:* Tuesday, March 29, 2016 4:33 PM > *To:* user@ranger.incubator.apache.org > *Subject:* Exporting Hadoop User Name > > > > Hi All, > > Need to Clarify regarding Authorization > > > > In Ranger Authorization > > > > My current User (i.e) user who is accessing the Object > > For Example:- > > username:- USERA is trying to cat the file in HDFS > > So will be exported and checked in Ranger Console about his privileges. > > If He has right permission > > Then using HDFS USERNAME and HDFS PASSWORD the file in HDFS is accessed. > > > > Here if in my Terminal as USERA i did this > > *export HADOOP_USER_NAME=hdfs* > > What will happen > > *So After Exporting if i connect Ranger it will pick me as *HDFS* user OR > *USREA > *user? > > If so Then how can i protect the HDFS Data > > > > Thanks & Regards > > Amithsha > > DISCLAIMER ========== This e-mail may contain privileged and confidential > information which is the property of Persistent Systems Ltd. It is intended > only for the use of the individual or entity to which it is addressed. If > you are not the intended recipient, you are not authorized to read, retain, > copy, print, distribute or use this message. If you have received this > communication in error, please notify the sender and delete all copies of > this message. Persistent Systems Ltd. does not accept any liability for > virus infected mails. >