RANGER-5698 : Disable Unix Authentication Service by default - #1171
RANGER-5698 : Disable Unix Authentication Service by default#1171fimugdha wants to merge 1 commit into
Conversation
| && rm -f /home/ranger/dist/ranger-${RANGER_VERSION}-admin.tar.gz \ | ||
| && rm -f /opt/ranger/admin/install.properties \ | ||
| && mkdir -p /var/run/ranger /var/log/ranger /usr/share/java/ \ | ||
| && chmod 755 ${RANGER_SCRIPTS}/setup-ranger-shadow-group.sh \ |
There was a problem hiding this comment.
Adding users/groups have moved to the base image: https://github.com/apache/ranger-tools/blob/main/docker/Dockerfile , please see this script: https://github.com/apache/ranger-tools/blob/0e27092aedb0db01be54300f2936a6244e80ec6c/docker/create_users_and_groups.sh#L1 if a user like shadow is really required to be added.
| # To enable file based sync source for usersync do: | ||
| export ENABLE_FILE_SYNC_SOURCE=true | ||
|
|
||
| # Unix authentication service is disabled by default in docker (ENABLE_UNIX_AUTH=false). |
There was a problem hiding this comment.
The comment may be removed, it's not relevant in docker deployments.
| private static final String SSL_TRUSTSTORE_FILE_TYPE_PARAM = "ranger.truststore.file.type"; | ||
| private static final String SSL_KEYSTORE_PATH_PARAM = "ranger.usersync.keystore.file"; | ||
| private static final String SSL_KEYSTORE_PATH_PASSWORD_PARAM = "ranger.usersync.keystore.password"; | ||
| private static final String SSL_KEYSTORE_PATH_PARAM = "ranger.usersync.service.https.attrib.keystore.file"; |
There was a problem hiding this comment.
it seems setup.py still using "ranger.usersync.keystore.file" and ranger-ugsync-template.xml does not have entry of ranger.usersync.service.https.attrib.keystore.file ; am i missing something here.
| </property> | ||
| <property> | ||
| <name>ranger.usersync.unix.backend</name> | ||
| <value>nss</value> |
There was a problem hiding this comment.
what was the previous default value for this property?
| static class UnixAuthenticationServiceThread extends Thread { | ||
| @Override | ||
| public void run() { | ||
| String[] params = {"-enableUnixAuth"}; |
There was a problem hiding this comment.
address this in ranger_usersync.py file as well
| # SSL Authentication | ||
| AUTH_SSL_ENABLED=false | ||
| # SSL Authentication configuration to be used when unix authentication is enabled. | ||
| AUTH_SSL_ENABLED=true |
There was a problem hiding this comment.
i think we should this also as false when ENABLE_UNIX_AUTH is false by default.
| # Also, Unix authentication is enabled in Ranger Admin. | ||
| # defaults to false | ||
| ENABLE_UNIX_AUTH = false | ||
|
|
There was a problem hiding this comment.
what will happen to upgrade case by default. probably they have to edit this line if they want to continue with unixauth.
| LOG.info("Service: {} - STOPPED", serviceName); | ||
| if (this.userSyncHAInitializerImpl != null) { | ||
| LOG.info("Stopping curator leader latch service as main thread is closing"); | ||
| this.userSyncHAInitializerImpl.stop(); |
There was a problem hiding this comment.
Can you test this once when unix auth is disabled and usersync is running in HA once.
What changes were proposed in this pull request?
The Unix Authentication service is rarely utilized for Ranger authentication, as the vast majority of deployments have migrated to modern alternatives like PAM or LDAP.
To optimize default startup behavior, we are removing the Unix Authentication service from the Ranger Usersync default startup sequence.
Moving forward, this service will run only if explicitly enabled via the
ranger.usersync.unix.auth.enabledproperty within theranger-ugsync-site.xmlconfiguration file.How was this patch tested?