Uploaded image for project: 'Ambari'
  1. Ambari
  2. AMBARI-22981

Update Hadoop RPC Encryption Properties During Upgrade

    XMLWordPrintableJSON

Details

    Description

      When HDP 3.0.0 is installed, clients should have the ability to choose encrypted communication over RPC when talking to core hadoop components. Today, the properties that control this are:

      • core-site.xml : hadoop.rpc.protection = authentication
      • hdfs-site.xml : dfs.data.transfer.protection = authentication

      The new value of privacy enables clients to choose an encrypted means of communication. By keeping authentication first, it will be taken as the default mechanism so that wire encryption is not automatically enabled by accident.

      The following properties should be changed to add privacy:

      • core-site.xml : hadoop.rpc.protection = authentication,privacy
      • hdfs-site.xml : dfs.data.transfer.protection = authentication,privacy

      The following are cases when this needs to be performed:

      • During Kerberization (this case is covered by AMBARI-22803)
      • During a stack upgrade to any version of HDP 3.0.0, they should be automatically merged

      Blueprint deployment is not a scenario being covered here.

      Attachments

        Issue Links

          Activity

            People

              smolnar Sandor Molnar
              smolnar Sandor Molnar
              Votes:
              0 Vote for this issue
              Watchers:
              2 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved:

                Time Tracking

                  Estimated:
                  Original Estimate - Not Specified
                  Not Specified
                  Remaining:
                  Remaining Estimate - 0h
                  0h
                  Logged:
                  Time Spent - 1h 50m
                  1h 50m