Hadoop Common
  1. Hadoop Common
  2. HADOOP-10791

AuthenticationFilter should support externalizing the secret for signing and provide rotation support

    Details

    • Type: Improvement Improvement
    • Status: Closed
    • Priority: Major Major
    • Resolution: Fixed
    • Affects Version/s: 2.4.1
    • Fix Version/s: 2.6.0
    • Component/s: security
    • Labels:
      None
    • Target Version/s:
    • Hadoop Flags:
      Reviewed

      Description

      It should be possible to externalize the secret used to sign the hadoop-auth cookies.

      In the case of WebHDFS the shared secret used by NN and DNs could be used. In the case of Oozie HA, the secret could be stored in Oozie HA control data in ZooKeeper.

      In addition, it is desirable for the secret to change periodically, this means that the AuthenticationService should remember a previous secret for the max duration of hadoop-auth cookie.

      1. HADOOP-10791.patch
        54 kB
        Robert Kanter
      2. HADOOP-10791.patch
        53 kB
        Robert Kanter
      3. HADOOP-10791.patch
        43 kB
        Robert Kanter
      4. HADOOP-10791.patch
        43 kB
        Robert Kanter

        Issue Links

          Activity

          Alejandro Abdelnur created issue -
          Robert Kanter made changes -
          Field Original Value New Value
          Assignee Robert Kanter [ rkanter ]
          Robert Kanter made changes -
          Link This issue is related to OOZIE-1917 [ OOZIE-1917 ]
          Robert Kanter made changes -
          Attachment HADOOP-10791.patch [ 12657156 ]
          Robert Kanter made changes -
          Status Open [ 1 ] Patch Available [ 10002 ]
          Robert Kanter made changes -
          Attachment HADOOP-10791.patch [ 12657210 ]
          Robert Kanter made changes -
          Attachment HADOOP-10791.patch [ 12659280 ]
          Robert Kanter made changes -
          Attachment HADOOP-10791.patch [ 12659739 ]
          Alejandro Abdelnur made changes -
          Status Patch Available [ 10002 ] Resolved [ 5 ]
          Hadoop Flags Reviewed [ 10343 ]
          Fix Version/s 2.6.0 [ 12327179 ]
          Resolution Fixed [ 1 ]
          Robert Kanter made changes -
          Link This issue is related to OOZIE-1917 [ OOZIE-1917 ]
          Robert Kanter made changes -
          Link This issue is depended upon by OOZIE-1917 [ OOZIE-1917 ]
          Zhijie Shen made changes -
          Link This issue breaks YARN-2388 [ YARN-2388 ]
          Arun C Murthy made changes -
          Status Resolved [ 5 ] Closed [ 6 ]
          Benoy Antony made changes -
          Link This issue relates to HADOOP-11567 [ HADOOP-11567 ]

            People

            • Assignee:
              Robert Kanter
              Reporter:
              Alejandro Abdelnur
            • Votes:
              0 Vote for this issue
              Watchers:
              8 Start watching this issue

              Dates

              • Created:
                Updated:
                Resolved:

                Development