Hello Zoltan Chovan, Alexey Serbin,

I'd like you to do a code review. Please visit

    http://gerrit.cloudera.org:8080/24833

to review the following change.


Change subject: [docs] Document proxy user configuration
......................................................................

[docs] Document proxy user configuration

Document the proxy user feature in the security guide: the flag-based
rule format, the requirement that both a target rule and a host rule
match, the Kerberos-only restriction, and the fact that authorization
uses the effective user while logs retain both identities.

Note that the effective (proxied) users must also be listed in
--user-acl on every master and tablet server, since servers authorize
RPCs against the effective user and an empty --user-acl rejects every
user.

Change-Id: I33c23ca76df8c3b9018213c01eb00bfd0726bc15
---
M docs/security.adoc
1 file changed, 34 insertions(+), 0 deletions(-)



  git pull ssh://gerrit.cloudera.org:29418/kudu refs/changes/33/24833/1
--
To view, visit http://gerrit.cloudera.org:8080/24833
To unsubscribe, visit http://gerrit.cloudera.org:8080/settings

Gerrit-Project: kudu
Gerrit-Branch: master
Gerrit-MessageType: newchange
Gerrit-Change-Id: I33c23ca76df8c3b9018213c01eb00bfd0726bc15
Gerrit-Change-Number: 24833
Gerrit-PatchSet: 1
Gerrit-Owner: mintao <[email protected]>
Gerrit-Reviewer: Alexey Serbin <[email protected]>
Gerrit-Reviewer: Zoltan Chovan <[email protected]>

Reply via email to