Details
-
Improvement
-
Status: Resolved
-
Major
-
Resolution: Fixed
-
None
-
None
Description
We have seen in the past, that Hadoop's delegation tokens are subject to a number of subtle token renewal bugs. In addition, they have a maximum life time that can be worked around but is very inconvenient for the user.
As per mailing list discussion, a way to work around the maximum life time of DelegationTokens would be to pass the Kerberos principal and key tab upon job submission. A daemon could then periodically renew the ticket.
Attachments
Issue Links
- is blocked by
-
HDFS-9276 Failed to Update HDFS Delegation Token for long running application in HA mode
- Resolved
- is part of
-
FLINK-3929 Support for Kerberos Authentication with Keytab Credential
- Resolved
- is related to
-
FLINK-3239 Support for Kerberos enabled Kafka 0.9.0.0
- Resolved
- requires
-
FLINK-3929 Support for Kerberos Authentication with Keytab Credential
- Resolved