| RANGER-2940 |
Added code to update user roles when group memberships are changed with AD/LDAP incremental sync |
| RANGER-2981 |
Unwanted popup display on Security Zone Tab |
| RANGER-2985 |
User with all permission in ranger is not able to update volume |
| RANGER-2987 |
Remove unused ratis jars in ranger admin packaging for ozone plugin |
| RANGER-2988 |
Role Name Search filter is not available on policy listing page |
| RANGER-2991 |
Ranger should close solrclient connection |
| RANGER-2997 |
Ranger usersync role assignment issues |
| RANGER-3002 |
Query info popup stuck in Ranger access audits view |
| RANGER-3007 |
Ozone & Ranger Upgrade: Not able to access volume after Upgrade |
| RANGER-3014 |
Revert RANGER-2789 GET API service/xusers/users turns very slow when there are more than 1000 users |
| RANGER-3021 |
RangerRole Version update is not in correct format in an upgraded cluster |
| RANGER-3034 |
Remove cached policies in plugin if the service is deleted in Ranger admin |
| RANGER-3037 |
Import policy API is not returning proper response in case pre authorization fails |
| RANGER-3038 |
Group memberships not getting updated to ranger |
| RANGER-3058 |
create table fails when ViewDFS(client side HDFS mounting fs) mount points are targeting to Ozone/S3 FS |
| RANGER-3060 |
Maven build failing due to PMD violations |
| RANGER-3061 |
Default configuration error when enable ssl for ranger admin |
| RANGER-3062 |
Even after removing ‘Security Zone’ permission for an user, UI still shows ‘Security Zone’ tab |
| RANGER-3064 |
Make policy API consistent with the UI behavior for keyadmin role |
| RANGER-3068 |
Ranger Usersync is not handling error during initialization process |
| RANGER-3070 |
Add Support for using {OWNER} placeholder in Ozone Ranger Plugin |
| RANGER-3071 |
Supporting character set which is not included in latin1 |
| RANGER-3073 |
Incorrect UI hint message for password validation in FIPS environment |
| RANGER-3074 |
Fix build issues |
| RANGER-3079 |
Fix build failures for ranger-2.2 branch |
| RANGER-3083 |
denyAllElse policy does not handle access request with access-type of '_any' |
| RANGER-3084 |
Ranger database connection fails when postgres is SSL enabled & postgresql-42.2.14 driver jar is used |
| RANGER-3088 |
Build tagged-resource-cache using memory optimization flags identical to policy-cache |
| RANGER-3090 |
KMS setup.sh fails due to blank property value of ranger.ks.db.ssl.certificateFile |
| RANGER-3093 |
Add required libraries to ranger-tools to ensure that perftester scripts run correctly |
| RANGER-3094 |
Ranger HDFS audit not capturing the correct path for write rename operations |
| RANGER-3095 |
not able to list the keys with a user whose id contains non latin character |
| RANGER-3098 |
Updates to validity period of tag are not reflected in Ranger database |
| RANGER-3101 |
Ranger usersync not recovering from initial errors in subsequent syncs |
| RANGER-3104 |
Ranger Hive policy with nested Roles failed to authorize request |
| RANGER-3107 |
Optimize memory requirements for storing Tag/Policy/Zone trie - Trade-off processing time for memory |
| RANGER-3112 |
Ranger usersync unit test cases are failing on mac |
| RANGER-3117 |
Need feature to capture URL of a particular instance of audit event |
| RANGER-3121 |
HBase list command authorization issue in Ranger |
| RANGER-3124 |
Search filter with user name having non latin character is not working on Audit>>Access tab |
| RANGER-3129 |
Python client uses incorrect default value assignment for method parameters |
| RANGER-3134 |
Remove global JAAS Configuration for Ranger auditing to SOLR |
| RANGER-3140 |
Ranger ShutdownHook hook to be called in RangerHBaseCoprocessor preShutdown apis for a clean shutdown of HBase |
| RANGER-3143 |
Ranger usersync, user group mapping for user deletion is not syncing up, if only one user is present in the group |
| RANGER-3149 |
Adding exisitng policy check for PatchForKafkaServiceDefUpdate_J10033 |
| RANGER-3156 |
RangerResouceTrie.add() and RangerResourceTrie.delete() do not work correctly for the resources containing wildcards |
| RANGER-3159 |
Having any permission on hbase tables should allow listing of tables |
| RANGER-3163 |
Ranger Database deadlock when Service creation and user sync are running parallel |
| RANGER-3169 |
Ranger Usersync config for keystore type and truststore type for LDAPS are not effective |
| RANGER-3171 |
Ranger ui became broken after logout in Firefox |
| RANGER-3172 |
Patch to migrate old policy to use new Policy Ref table |
| RANGER-3175 |
Add back the support to provide option to retrieve users from group member attribute |
| RANGER-3178 |
Fix spurious full policy/tag downloads when incremental policy/tag updates are enabled |
| RANGER-3187 |
Roles download failed in Ranger after upgrade |
| RANGER-3190 |
Skip python unit tests if requests library not present |
| RANGER-3194 |
Ranger Access Audits page not loading |
| RANGER-3199 |
illegal reflective access operation warning in KMS catalina.out logs |
| RANGER-3203 |
Add back the support to provide option to retrieve groups from user memberof attribute |
| RANGER-3205 |
Policy Item not render in report page |
| RANGER-3207 |
Graceful handling of invalid usernames for usersync |
| RANGER-3208 |
NPE in Ranger policy engine when processing SELF_OR_CHILD scoped search |
| RANGER-3218 |
User getting denied even after having tag based policy |
| RANGER-3220 |
Zone name is not getting populated for tag based policy. |
| RANGER-3224 |
Not able to delete security-zone |
| RANGER-3229 |
Correct Kafka default policy item for all-delegation token and rangerlookup user |
| RANGER-3233 |
Ranger Kafka Plugin changes to get the UGI from Kafka client JAAS config instead of Subject from Kafka LoginManager |
| RANGER-3234 |
Ranger db patch no 045 is failing for oracle db. |
| RANGER-3235 |
Remove hive-exec dependency from Ranger audit frame work |
| RANGER-3238 |
Incorrect response for 'ranger_metric denyconditions' in Collect Diagnostic Data |
| RANGER-3252 |
Inconsistent behavior in Ranger Role authorization with in same hive beeline session |
| RANGER-3259 |
[Ranger Audit Filter] Ranger role is allowed to delete, even if its used in audit filters |
| RANGER-3260 |
Update default hdfs audit filters to filter out unwanted audits |
| RANGER-3261 |
Remove unused .htaccess file from component |
| RANGER-3262 |
Ranger group memberships are not working for LDAP sync |
| RANGER-3263 |
libthrift 0.14.x exclude tomcat-embed-core from dependency |
| RANGER-3264 |
[Solr Ranger Plugin] Add support/Fix Test connection with Solr service |
| RANGER-3266 |
Solr inter-node communication not working after enabling Ranger |
| RANGER-3268 |
Ranger Audit filter should filter audits that are created by Hive Role command operations |
| RANGER-3272 |
Zone tag policies are getting deleted when zone is updated |
| RANGER-3275 |
Need to update solr-config.xml in the ranger-audits collection config-set |
| RANGER-3277 |
Number of users/groups marked for delete are not shown in logs |
| RANGER-3280 |
Ensure that the policy/tag versions gets correctly updated for every change to service/policy/tag |
| RANGER-3286 |
Oracle upgrade fails with oracle: SQLSyntaxErrorException in 052-add-unique-constraint-on-change-logs |
| RANGER-3288 |
Ranger Audit Filters doesn't filter hdfs read operation when filter is set to not audit read |
| RANGER-3291 |
NPE in BasePlugin if the first policy download contains no policies and no policy-deltas |
| RANGER-3292 |
Fix ConcurrentModificationException from RangerTransactionSynchronizationAdapter |
| RANGER-3294 |
AccessResult attribute with isAudited as false not filtered in Ranger Audit Filter |
| RANGER-3297 |
Internal user is not marked as external after the user sync source details are changed |
| RANGER-3301 |
[UI] in admin audit log tables not formatted correctly for long string value for resources. |
| RANGER-3304 |
Create solr audit conf zip archive |
| RANGER-3311 |
Ranger Usersync not retrying failed updates for unix or file sync source |
| RANGER-3312 |
Role is getting removed from policy when user present in that policy is deleted |
| RANGER-3320 |
ranger tags are not added for when tagging identically named database/tables in two different Ranger services |
| RANGER-3322 |
remove grant of public synonym privileges for oracle db |
| RANGER-3323 |
Ranger Hive Table lookup is not working |
| RANGER-3325 |
Roles information not present in the Excel and CSV files which are downloaded from Reports page |
| RANGER-3333 |
Ozone Ranger Audits are not showing up in Ranger Admin UI for "om" service user |
| RANGER-3336 |
All policies are exported, when searching reports using roles |
| RANGER-3337 |
Ranger policy not taking effect with HDFS Snapshots |
| RANGER-3338 |
Masking and Row filter policy are getting exported from report page when Policy type=Access |
| RANGER-3341 |
External user's role creation may fail in certain version of MariaDB |
| RANGER-3343 |
Ranger policy cache is incorrect in some scenario |
| RANGER-3344 |
Ranger Admin fails to start with java.lang.NoClassDefFoundError: org/apache/htrace/core/Tracer$Builder |
| RANGER-3345 |
Default Ranger policy for KMS should include "om" user for Ozone bucket level encryption to work |
| RANGER-3350 |
Ranger HivePluginAuthorizer SHOW CURRENT ROLES not fetching the role set in current hive beeline session |
| RANGER-3351 |
Incorrect hive query displayed for grant and revoke role command |
| RANGER-3353 |
Show roles is not listing all roles |
| RANGER-3355 |
Ranger Admin : Update the current logging mechanism to use custom log4j conf |
| RANGER-3366 |
Cluster type is missed in copy constructor of RangerAccessRequestImpl |
| RANGER-3367 |
[Intermittent] Ranger Admin perf logs are not getting logged after Spring Security upgrade |
| RANGER-3372 |
Issue in policies search on report page with user having more than one unix group |
| RANGER-3385 |
Duplicate SQL prefix should not be allowed |
| RANGER-3387 |
Ranger Admin Header Validation |
| RANGER-3398 |
Duplicate JAVA patch suffix should not be allowed |
| RANGER-3404 |
user with no permissions can access and edit delegate admin only policies |
| RANGER-3419 |
compressDeltas method returns two ranger policy entries for policy create+update case when provided lastKnownVersion is previous to create call |
| RANGER-3441 |
PropertiesUtil (Admin) logging potentially sensitive data |
| RANGER-3446 |
log4j initialization failure in docker setup |
| RANGER-3455 |
[Logout-Ranger] Should either be disabled/ should redirect to knox logout page |
| RANGER-3462 |
User with delegated admin permission on a resource cannot fetch policy for the resource |
| RANGER-3480 |
Policy version in access audit is not matching with the policy version seen in policy view |
| RANGER-3481 |
Incremental policy updates do not work correctly for multiple security zones |
| RANGER-3489 |
Add htrace-core.jar as dependency for various Ranger Plugins |