[
https://issues.apache.org/jira/browse/HBASE-13780?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
]
Sean Busbey updated HBASE-13780:
--------------------------------
Component/s: security
Operability
> Default to 700 for HDFS root dir permissions for secure deployments
> -------------------------------------------------------------------
>
> Key: HBASE-13780
> URL: https://issues.apache.org/jira/browse/HBASE-13780
> Project: HBase
> Issue Type: Improvement
> Components: Operability, security
> Reporter: Enis Soztutar
> Assignee: Enis Soztutar
> Fix For: 2.0.0, 0.98.13, 1.0.2, 1.2.0, 1.1.1
>
> Attachments: HBASE-13780-0.98.patch, hbase-13780_v1.patch
>
>
> Secure mode deployments should protect the files under HDFS root dir. We
> should check and set the root dirs permissions on a kerberos setup so that
> users does not have to.
> We have {{hbase.data.umask.enable}} and {{hbase.data.umask}} for data files,
> but those are not that useful since we should protect dir listing, and access
> to WAL files, snapshot files, etc.
> See HBASE-13768 which has an integration test for this.
--
This message was sent by Atlassian JIRA
(v6.3.4#6332)