Uploaded image for project: 'CDH (READ-ONLY)'
  1. CDH (READ-ONLY)
  2. DISTRO-439

Any user can kill the oozie job of other user

    Details

    • Type: Bug
    • Status: Resolved
    • Priority: Major
    • Resolution: Not A Bug
    • Affects Version/s: CDH4.0.1
    • Fix Version/s: None
    • Component/s: Oozie
    • Labels:
      None
    • Environment:
      Centos-5.8,Hadoop 2.0.0-cdh4.0.1,Oozie-3.1.3-cdh4.0.1

      Description

      As per the release build version: 3.1.3-cdh4.0.1, any user can kill the job run by a different user.
      Consider two users, abc and xyz. One user, say abc belongs to a group mentioned as hadoop.proxyuser.oozie.groups.
      While other user xyz do not belong to hadoop.proxyuser.oozie.groups.

      If user xyz trys to run a job, hadoop throws error as "Error: E0501 : E0501: Could not perform authorization operation, User: oozie is not allowed to impersonate root". But the same user (xyz) is allowed to kill a job initiated by any authorised (abc) user.

        Attachments

          Activity

            People

            • Assignee:
              Unassigned
              Reporter:
              priyasundararajan PriyaSundararajan
            • Votes:
              0 Vote for this issue
              Watchers:
              3 Start watching this issue

              Dates

              • Created:
                Updated:
                Resolved: