Uploaded image for project: 'Ambari'
  1. Ambari
  2. AMBARI-12501

Kerberos: Allow setting/clearing attributes for MIT KDC identities

    XMLWordPrintableJSON

Details

    • Bug
    • Status: Resolved
    • Critical
    • Resolution: Fixed
    • 2.0.0, 2.0.1, 2.1.0
    • 2.1.1
    • ambari-server

    Description

      Allow for attributes to be set (or unset) for identities created in an MIT (or similar) KDC.

      A user should be able to specify a list of attributes to be set or unset while creating identities using the MIT kadmin utility. For example:

      -requires_preauth max_renew_life=7d
      

      Solution
      Add a property in kerberos-env or reuse kerberos-env/create_attributes_template to store the user-specified attributes.

      Attachments

        1. AMBARI-12501_trunk_02.patch
          55 kB
          Robert Levas
        2. AMBARI-12501_trunk_01.patch
          55 kB
          Robert Levas
        3. AMBARI-12501_branch-2.1_02.patch
          55 kB
          Robert Levas
        4. AMBARI-12501_branch-2.1_01.patch
          55 kB
          Robert Levas

        Issue Links

          Activity

            People

              rlevas Robert Levas
              rlevas Robert Levas
              Votes:
              0 Vote for this issue
              Watchers:
              3 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved: