Hadoop Common
  1. Hadoop Common
  2. HADOOP-6634

AccessControlList uses full-principal names to verify acls causing queue-acls to fail

    Details

    • Type: Bug Bug
    • Status: Closed
    • Priority: Major Major
    • Resolution: Fixed
    • Affects Version/s: None
    • Fix Version/s: 0.21.0
    • Component/s: security
    • Labels:
      None
    • Hadoop Flags:
      Reviewed

      Description

      ACL configuration so far was using short user-names. With the changed UserGroupInformation, short names are different from the long fully-qualified names. AccessControlList continues to use UserGroupInformation.getUserName() for verifying access control. Because of this, queue acls fail for a user "user@domain.org" even though the short name "user" is part of the acl configuration.

      1. HADOOP-6634-20100317-ydist.1.txt
        4 kB
        Vinod Kumar Vavilapalli
      2. HADOOP-6634-20100428.txt
        4 kB
        Vinod Kumar Vavilapalli

        Activity

        No work has yet been logged on this issue.

          People

          • Assignee:
            Vinod Kumar Vavilapalli
            Reporter:
            Vinod Kumar Vavilapalli
          • Votes:
            0 Vote for this issue
            Watchers:
            2 Start watching this issue

            Dates

            • Created:
              Updated:
              Resolved:

              Development