Details
-
Improvement
-
Status: Resolved
-
Minor
-
Resolution: Fixed
-
2.0.0
Description
The Kerberos service components should indicate security state when queried by Ambari Agent via STATUS_COMMAND. Each component should determine it's state as follows:
KERBEROS_CLIENT
Indicators
- Command JSON
- config['configurations']['cluster-env']['security_enabled']
- = “true”
- config['configurations']['cluster-env']['smokeuser_keytab']
- not empty
- path exists and is readable
- required
- config['configurations']['cluster-env']['smokeuser']
- not empty
- required
- config['configurations']['cluster-env']['security_enabled']
Pseudocode
if indicators imply security is on and validate if kinit(smoketest user) succeeds state = SECURED_KERBEROS else state = ERROR else state = UNSECURED
Attachments
Attachments
Issue Links
- requires
-
AMBARI-8343 Components should indicate Security State (via ambari-agent)
- Resolved
- links to