Hi All, Just a gentle reminder on the earlier note about removing remote Unix authentication (unixauthservice, port 5151).
We have not heard back from anyone yet, so we wanted to reach out once more and hear from you before we move forward. In brief: - Going away: remote login path Admin → UserSync (5151) / RemoteUnixLoginModule - Staying as-is: UserGroupSync, local PAM on Admin, LDAP/Kerberos/JDBC If this affects your setup (authentication_method=UNIX with remote auth, or ranger.unixauth.*), a quick reply on this thread would be very helpful. More detail: RANGER-5703 <https://issues.apache.org/jira/browse/RANGER-5703> · PR #1105 <https://github.com/apache/ranger/pull/1105> Thanks, Ram On Wed, Jul 29, 2026 at 10:18 AM Ramachandran Krishnan <[email protected]> wrote: > Hi All, > > Follow-up to my Jul 23 announcement about removing the remote Unix > authentication stack (unixauthservice / port 5151). > > We have not received any replies indicating active use of remote Unix > login. Before we proceed with the merge, this is a last call for > community input. > Quick recap > > Removed: Admin → UserSync TCP/TLS (port 5151) → native password validator > (RemoteUnixLoginModule, unixauthservice, unixauthclient, unixauthnative, > unixauthpam). > > Not affected: UserGroupSync (LDAP/file/unix sources), Admin local PAM ( > PamLoginModule, ranger.pam.service), LDAP/AD/Kerberos/JDBC auth. > > Migration: If you use authentication_method=UNIX with > ranger.pam.authentication.enabled=false, switch to local PAM on Admin or > LDAP/Kerberos before upgrading. > > Full details: RANGER-5703 > <https://issues.apache.org/jira/browse/RANGER-5703> | PR #1105 > <https://github.com/apache/ranger/pull/1105> > Current status > > - PR #1105 <https://github.com/apache/ranger/pull/1105> is open for > review, synced with master (includes #1106 short-term rate limiting on > the listener — that code is removed entirely by #1105). > - UserSync gets a new launcher (UserSyncService); local PAM JAAS > classes move into security-admin. > - Testing so far: build, unit tests, Docker usersync startup, Admin > PAM smoke. > > Please reply if any of this applies to you > > 1. You rely on remote Unix login (Admin → UserSync:5151 / > ranger.unixauth.*). > 2. You use ranger.usersync.passwordvalidator.path on the UserSync host > for Admin authentication. > 3. You have concerns about the UserSync launcher change or local PAM > behavior after removal. > > If we hear nothing by Aug 5, 2026, we will treat that as no community > objection and proceed with merge. > > Thanks, > Ram > > On Thu, Jul 23, 2026 at 10:07 PM Ramachandran Krishnan <[email protected]> > wrote: > >> We are proposing to remove the remote Unix authentication stack from >> Apache Ranger. This is tracked in RANGER-5703 >> <https://issues.apache.org/jira/browse/RANGER-5703> and implemented in PR >> #1105 <https://github.com/apache/ranger/pull/1105>. >> >> We are sending this to the dev and user lists to explain what would >> change, what would not, and to ask whether anyone still relies on the >> removed functionality. >> Background >> >> The unixauthservice module was added long before Ranger existed. It >> provides a TCP/TLS listener (default port 5151) on the UserSync host >> that validates OS credentials when Ranger Admin is configured for remote >> Unix login (authentication_method=UNIX with >> ranger.pam.authentication.enabled=false). Ranger Admin connects via >> RemoteUnixLoginModule in unixauthclient. >> >> This remote path has also been the subject of recent security review >> (OWASP account-lockout / brute-force concerns on the listener). Rather than >> maintain and harden rarely used code, we believe removal is the better >> long-term fix, with a clear migration path for the few deployments that >> may still use it. >> What would be removed >> Module Role >> >> unixauthservice >> TCP listener on UserSync (port 5151) >> unixauthclient >> Admin-side JAAS client (RemoteUnixLoginModule) >> unixauthnative / unixauthpam >> Native password validators (credValidator.uexe, pamCredValidator.uexe) >> on the UserSync host >> >> Related Admin config (ranger.unixauth.*) and UserSync auth-listener >> config (ranger.usersync.port, .ssl, .passwordvalidator.path, etc.) would >> also be removed. >> >> There would be no disable toggle — the code is deleted, not >> feature-flagged off. >> What would not change >> >> Ranger has two separate “Unix/PAM” concepts. This proposal removes only >> remote credential checking over port 5151. >> Functionality Affected? >> >> UserGroupSync (LDAP, file, /etc/passwd as sync sources) >> No — continues unchanged >> Admin local PAM (PamLoginModule, ranger.pam.service, libpam4j on the Admin >> host) >> No — unchanged; JAAS classes move into security-admin >> LDAP, AD, Kerberos, JDBC Admin authentication >> No >> Remote Unix login (Admin → UserSync:5151 → native validator) >> Yes — removed >> >> Important clarification: Admin-side PAM (authentication_method=PAM, or >> UNIX with local PAM enabled) does not call UnixAuthenticationService. It >> authenticates in-process on the Admin node via /etc/pam.d. >> >> The property ranger.usersync.passwordvalidator.path applies only to the >> remote >> listener on the UserSync host, not to Admin PamLoginModule. >> UserSync entry point >> >> UnixAuthenticationService.main() is today’s UserSync JVM entry point (HA >> latch, UserGroupSync, optional metrics, and optionally the auth >> listener). Removing the module without a replacement would break UserSync >> startup. >> >> PR #1105 adds org.apache.ranger.usergroupsync.UserSyncService in ugsync/ as >> the new launcher and relocates usersync install scripts/config out of >> unixauthservice/. UserGroupSync itself is not removed. >> Migration (if you use remote Unix login today) >> >> If Admin login currently depends on remote Unix auth: >> >> - authentication_method=UNIX >> >> >> - ranger.pam.authentication.enabled=false (historical default for UNIX >> ) >> >> …then credentials are validated on the UserSync host over port 5151. >> After this change, that path is gone. >> >> Before upgrading, switch Admin authentication to one of: >> >> 1. Local PAM on the Admin host — configure ranger.pam.service (and >> /etc/pam.d/... on Admin), or >> 2. LDAP / AD / Kerberos >> >> After the change, authentication_method=UNIX and PAM would both use local >> PamLoginModule on Admin only. >> >> More detail: PR #1105 comment >> <https://github.com/apache/ranger/pull/1105#issuecomment-5057842997>. >> Call for community input >> >> We are not aware of active community use of remote Unix login, but we >> want to hear from anyone who still depends on it. >> >> Please reply on this thread or comment on RANGER-5703 >> <https://issues.apache.org/jira/browse/RANGER-5703> if: >> >> - You use authentication_method=UNIX with remote auth (port 5151 / >> ranger.unixauth.*), or >> - You point ranger.usersync.passwordvalidator.path at a PAM-aware >> validator on the UserSync host for Admin login, or >> - You have concerns about the UserSync launcher relocation or local >> PAM behavior. >> >> If no objections or usage reports surface during review, we plan to >> proceed with merge after adequate testing (build, UserSync HA/metrics >> startup, Admin PAM login, docker CI). >> Links >> >> - JIRA: https://issues.apache.org/jira/browse/RANGER-5703 >> - PR: #1105 <https://github.com/apache/ranger/pull/1105> >> - Removal design notes: #1105 >> <https://github.com/apache/ranger/pull/1105#issuecomment-5057842997> >> >> Thanks, >> Ram >> >>
