Details
-
Bug
-
Status: Open
-
Major
-
Resolution: Unresolved
-
2.5.0, 2.6.0
-
None
Description
"Admin -> Kerberos -> Additonal Realms"
- Currently requires keytab re-generation which in turn requires restarting the cluster. But it is completely unrelated to keytabs.
Fix:
- Move "Additional Realms" to the "Kerberos" service configs where it belongs, along with the "auth_to_local" setting which is what it is used for.
- When it is changed:
- No keytab re-generation is then required.
- Instead of silently altering "auth_to_local" rules, they should come up as "Recommendations".
Attachments
Issue Links
- is caused by
-
AMBARI-13060 Kerberos: Allow user to specify additional realms for auth-to-local rules
- Resolved