Uploaded image for project: 'Ambari'
  1. Ambari
  2. AMBARI-11001

Ambari uses users' interactive ticket cache

    XMLWordPrintableJSON

Details

    • Bug
    • Status: Resolved
    • Critical
    • Resolution: Pending Closed
    • 2.1.0
    • 2.1.0
    • ambari-server

    Description

      It appears that it is necessary to kinit prior to starting ambari-server, even after ambari-server setup-security (#3). It seems that this should be automatically handled by Ambari.

      Ambari-server should NOT use the same ticket cache as the interactive user.

      STR:
      1. kinit
      2. ambari-server start
      3. verify that ambari-server can authenticate with ticket specified in #1
      4. kdestroy
      5. try to authenticate through Ambari again (it will not work)

      Solution
      Ensure JAAS Login works properly such that the Kerberos tickets for the account that executes Ambari is not relevant.

      Attachments

        1. AMBARI-11001_01.patch
          1 kB
          Robert Levas

        Issue Links

          Activity

            People

              rlevas Robert Levas
              rlevas Robert Levas
              Votes:
              0 Vote for this issue
              Watchers:
              4 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved: