Uploaded image for project: 'Apache Drill'
  1. Apache Drill
  2. DRILL-4627

Drill should protect data placed into Zookeeper/ZK

    XMLWordPrintableJSON

Details

    • Bug
    • Status: Open
    • Minor
    • Resolution: Unresolved
    • None
    • None
    • None

    Description

      Drill is striving to improve it's security posture and is improving rapidly.

      One key item in a secure system is protection of all relevant data that an attacker could use to cause harm. Today Drill does not protect the data in ZK. This means that an attacker could alter it.

      I recommend that Drill create appropriate ZK ACLs on the data in ZK and establish an appropriate authentication mechanism to ZK - that's likely Kerberos for most Hadoop clusters but MapR Native Security for MapR.

      Attachments

        Activity

          People

            Unassigned Unassigned
            kbotzum Keys Botzum
            Votes:
            0 Vote for this issue
            Watchers:
            1 Start watching this issue

            Dates

              Created:
              Updated: