Uploaded image for project: 'Apache Ozone'
  1. Apache Ozone
  2. HDDS-7529

Secure SCM bootstrap fails if clusterID validation is disabled

    XMLWordPrintableJSON

Details

    • Bug
    • Status: Resolved
    • Major
    • Resolution: Not A Bug
    • 1.3.0
    • None
    • SCM HA
    • None

    Description

      Secure SCM bootstrap fails if ozone.scm.skip.bootstrap.validation=true.

      org.apache.hadoop.security.AccessControlException: Client cannot authenticate via:[KERBEROS]
        ...
        at org.apache.hadoop.hdds.protocolPB.SCMSecurityProtocolClientSideTranslatorPB.getSCMCertChain(SCMSecurityProtocolClientSideTranslatorPB.java:222)
        at org.apache.hadoop.hdds.scm.ha.HASecurityUtils.getRootCASignedSCMCert(HASecurityUtils.java:150)
        at org.apache.hadoop.hdds.scm.ha.HASecurityUtils.initializeSecurity(HASecurityUtils.java:103)
        at org.apache.hadoop.hdds.scm.server.StorageContainerManager.initializeSecurityIfNeeded(StorageContainerManager.java:1157)
        at org.apache.hadoop.hdds.scm.server.StorageContainerManager.scmBootstrap(StorageContainerManager.java:1084)
        at org.apache.hadoop.hdds.scm.server.StorageContainerManagerStarter$SCMStarterHelper.bootStrap(StorageContainerManagerStarter.java:192)
        at org.apache.hadoop.hdds.scm.server.StorageContainerManagerStarter.bootStrapScm(StorageContainerManagerStarter.java:135)
      

      Attachments

        Activity

          People

            aryangupta1998 Aryan Gupta
            adoroszlai Attila Doroszlai
            Votes:
            0 Vote for this issue
            Watchers:
            2 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: