Hadoop Common
  1. Hadoop Common
  2. HADOOP-7104

Remove unnecessary DNS reverse lookups from RPC layer

    Details

    • Type: Bug Bug
    • Status: Closed
    • Priority: Major Major
    • Resolution: Fixed
    • Affects Version/s: 0.22.0
    • Fix Version/s: 0.22.0
    • Component/s: ipc, security
    • Labels:
      None
    • Hadoop Flags:
      Reviewed

      Description

      RPC connection authorization needs to verify client's Kerberos principal name matches what specified for the protocol. For service clients like DN's, their Kerberos principal names can be specified in the form of "datanode/_HOST@DOMAIN.COM". To get the expected
      client principal name, the server needs to substitute "_HOST" with the client's fully qualified domain name, which requires a reverse DNS lookup from client IP address. However, for connections from clients whose principal name are either unspecified or specified not using the "_HOST" convention, the substitution is not required and the reverse DNS lookup should be avoided. Currently the reverse DNS lookup is done for all clients, which could slow services like NN down, when local named cache is not available.

      1. c7104-01.patch
        12 kB
        Kan Zhang
      2. c7104-03.patch
        13 kB
        Kan Zhang
      3. 7104-few-edits.patch
        14 kB
        Todd Lipcon

        Issue Links

          Activity

          Kan Zhang created issue -
          Kan Zhang made changes -
          Field Original Value New Value
          Attachment c7104-01.patch [ 12468304 ]
          Kan Zhang made changes -
          Status Open [ 1 ] Patch Available [ 10002 ]
          Kan Zhang made changes -
          Attachment c7104-03.patch [ 12468419 ]
          Kan Zhang made changes -
          Status Patch Available [ 10002 ] Open [ 1 ]
          Kan Zhang made changes -
          Status Open [ 1 ] Patch Available [ 10002 ]
          Todd Lipcon made changes -
          Attachment 7104-few-edits.patch [ 12468429 ]
          Todd Lipcon made changes -
          Status Patch Available [ 10002 ] Resolved [ 5 ]
          Hadoop Flags [Reviewed]
          Fix Version/s 0.23.0 [ 12315569 ]
          Resolution Fixed [ 1 ]
          Todd Lipcon made changes -
          Fix Version/s 0.22.0 [ 12314296 ]
          Fix Version/s 0.23.0 [ 12315569 ]
          Affects Version/s 0.22.0 [ 12314296 ]
          Jakob Homan made changes -
          Issue Type Improvement [ 4 ] Bug [ 1 ]
          Suresh Srinivas made changes -
          Link This issue relates to HADOOP-7215 [ HADOOP-7215 ]
          Konstantin Shvachko made changes -
          Status Resolved [ 5 ] Closed [ 6 ]

            People

            • Assignee:
              Kan Zhang
              Reporter:
              Kan Zhang
            • Votes:
              0 Vote for this issue
              Watchers:
              8 Start watching this issue

              Dates

              • Created:
                Updated:
                Resolved:

                Development