Behavioral Changes in Apache Ranger
Behavioral changes denote a marked change in behavior from the previously released version to this version of Apache Ranger.
Cloudera Runtime 7.3.2.10000 SP1
- READ permission now required for Ozone key create/delete operations
- Summary:
READ permission is now required for Ozone key create/delete operations
- Ranger denies ALTER TABLE operations on tables with active row filter or column masking policies
- Summary:
Ranger denies ALTER TABLE operations on tables with active row filter or column masking policies.
- GraalJS engine hardening for _expression policy conditions
- Summary:
The GraalJS engine used to evaluate
_expressionpolicy conditions in Apache Ranger has been hardened for security. - Enforcement of unauthenticated access properties
- Summary:
The
ranger.admin.allow.unauthenticated.accessandranger.admin.allow.unauthenticated.download.accessproperties are now enforced regardless of whether Kerberos authentication is configured on Ranger Admin. The default values remain unchanged. - Updated permission error response for unauthorized Ozone key deletion
- Previous behavior:
Previously, attempting to delete an Ozone key without sufficient privileges returned a
DELETEpermission denied error.
Cloudera Runtime 7.3.2.100 CHF 1
There are no behavioral changes in this release.
Cloudera Runtime 7.3.2.0
The behavioral changes for Apache Ranger in Cloudera Runtime 7.3.2.0 include all cumulative updates from previous releases (such as 7.3.1.x). This version specifically incorporates changes introduced in Cloudera Runtime 7.3.1.100 through 7.3.1.706 alongside the following functional adjustments. For a complete list, see Behavioral Changes.
- Summary:The new column authorization optimization property in the Ranger-HBase plugin changes Ranger audit behavior, when enabled. There is no behavioral change if the property is disabled.
- Summary:The following service configurations have been added to a new place in the Ranger Admin Web UI:
- Policy Download Users (policy.download.auth.users)
- Tag Download Users (tag.download.auth.users)
- Service Admin Users (service.admin.users)
- Service Admin Groups (service.admin.groups)
- Superusers (ranger.plugin.super.users)
- Superuser Groups (ranger.plugin.super.groups)
- Userstore Download Users (userstore.download.auth.users)
- Summary:
Policy resources in the Ranger Admin UI are being added using React JS instead of Backbone JS
- Summary:
Hive authorization from Ranger for Alter Table Rename command does not require CREATE database permission on the database where the renamed table will be created.
- Summary:
Added support for multiple columns policy creation in Ranger for Grant/Revoke request.
