Details
-
Bug
-
Status: Patch Available
-
Major
-
Resolution: Unresolved
-
2.6.0
-
None
-
None
Description
HADOOP-11934 discovered an infinite loop of dependencies in the use of credential provider in LdapGroupsMapping. It added a new localjceks:// URI to workaround the problem. The assumption is that the groups mapping is used only in NameNode and that using a local credential file is not a problem.
However, there are cases where Hadoop clients, such as Sqoop, may use hdfs:// based credential provider and use LdapGroupsMapping at the same time. We should use HADOOP-12846 to exclude hdfs:// URI credential providers.
Attachments
Attachments
Issue Links
- relates to
-
HADOOP-10905 LdapGroupsMapping Should use configuration.getPassword for SSL and LDAP Passwords
- Closed
-
HADOOP-12846 Credential Provider Recursive Dependencies
- Resolved
-
HADOOP-12851 S3AFileSystem Uptake of ProviderUtils.excludeIncompatibleCredentialProviders
- Resolved
-
HADOOP-13353 LdapGroupsMapping getPassward shouldn't return null when IOException throws
- Resolved
-
HADOOP-11934 Use of JavaKeyStoreProvider in LdapGroupsMapping causes infinite loop
- Closed