You are viewing a plain text version of this content. The canonical link for it is here.
Posted to hdfs-user@hadoop.apache.org by fred th <me...@gmail.com> on 2013/09/03 22:09:27 UTC

forbid use of hadoop.job.ugi to impersonate user without Kerberos

Hello,
I'm considering using hadoop for a share cluster. As start to setup quickly
the system I'm was planning to differ Kerberos use.
Is there other way than using Kerberos to forbid a user to use
hadoop.job.ugi parameter to impersonate another user?

thanks
Mt

Re: forbid use of hadoop.job.ugi to impersonate user without Kerberos

Posted by Harsh J <ha...@cloudera.com>.
No.

There are several ways a user can impersonate another user if you do
not use strong authentication (i.e. kerberos). Some ways are
implemented with that intention, for users who don't want any
authentication.

On Wed, Sep 4, 2013 at 1:39 AM, fred th <me...@gmail.com> wrote:
> Hello,
> I'm considering using hadoop for a share cluster. As start to setup quickly
> the system I'm was planning to differ Kerberos use.
> Is there other way than using Kerberos to forbid a user to use
> hadoop.job.ugi parameter to impersonate another user?
>
> thanks
> Mt



-- 
Harsh J

Re: forbid use of hadoop.job.ugi to impersonate user without Kerberos

Posted by Harsh J <ha...@cloudera.com>.
No.

There are several ways a user can impersonate another user if you do
not use strong authentication (i.e. kerberos). Some ways are
implemented with that intention, for users who don't want any
authentication.

On Wed, Sep 4, 2013 at 1:39 AM, fred th <me...@gmail.com> wrote:
> Hello,
> I'm considering using hadoop for a share cluster. As start to setup quickly
> the system I'm was planning to differ Kerberos use.
> Is there other way than using Kerberos to forbid a user to use
> hadoop.job.ugi parameter to impersonate another user?
>
> thanks
> Mt



-- 
Harsh J

Re: forbid use of hadoop.job.ugi to impersonate user without Kerberos

Posted by Harsh J <ha...@cloudera.com>.
No.

There are several ways a user can impersonate another user if you do
not use strong authentication (i.e. kerberos). Some ways are
implemented with that intention, for users who don't want any
authentication.

On Wed, Sep 4, 2013 at 1:39 AM, fred th <me...@gmail.com> wrote:
> Hello,
> I'm considering using hadoop for a share cluster. As start to setup quickly
> the system I'm was planning to differ Kerberos use.
> Is there other way than using Kerberos to forbid a user to use
> hadoop.job.ugi parameter to impersonate another user?
>
> thanks
> Mt



-- 
Harsh J

Re: forbid use of hadoop.job.ugi to impersonate user without Kerberos

Posted by Harsh J <ha...@cloudera.com>.
No.

There are several ways a user can impersonate another user if you do
not use strong authentication (i.e. kerberos). Some ways are
implemented with that intention, for users who don't want any
authentication.

On Wed, Sep 4, 2013 at 1:39 AM, fred th <me...@gmail.com> wrote:
> Hello,
> I'm considering using hadoop for a share cluster. As start to setup quickly
> the system I'm was planning to differ Kerberos use.
> Is there other way than using Kerberos to forbid a user to use
> hadoop.job.ugi parameter to impersonate another user?
>
> thanks
> Mt



-- 
Harsh J