Uploaded image for project: 'Hadoop Common'
  1. Hadoop Common
  2. HADOOP-8855

SSL-based image transfer does not work when Kerberos is disabled

VotersWatch issueWatchersCreate sub-taskLinkCloneUpdate Comment AuthorReplace String in CommentUpdate Comment VisibilityDelete Comments
    XMLWordPrintableJSON

    Details

    • Type: Bug
    • Status: Closed
    • Priority: Minor
    • Resolution: Fixed
    • Affects Version/s: 2.0.2-alpha, 3.0.0-alpha1
    • Fix Version/s: 2.0.3-alpha
    • Component/s: security
    • Labels:
      None
    • Hadoop Flags:
      Reviewed

      Description

      In SecurityUtil.openSecureHttpConnection, we first check UserGroupInformation.isSecurityEnabled(). However, this only checks the kerberos config, which is independent of hadoop.ssl.enabled. Instead, we should check HttpConfig.isSecure().

      Credit to Wing Yew Poon for discovering this bug

        Attachments

        1. hadoop-8855.txt
          6 kB
          Todd Lipcon
        2. hadoop-8855.txt
          6 kB
          Todd Lipcon
        3. hadoop-8855.txt
          1.0 kB
          Todd Lipcon

        Issue Links

          Activity

            People

            • Assignee:
              tlipcon Todd Lipcon
              Reporter:
              tlipcon Todd Lipcon

              Dates

              • Created:
                Updated:
                Resolved:

                Issue deployment