Details
-
Bug
-
Status: Resolved
-
Critical
-
Resolution: Fixed
-
3.3.0
-
None
-
Kerberos and ZKDelgationTokenSecretManager enabled in HttpFS
-
Reviewed
-
httpfs.authentication.* configs become deprecated and hadoop.http.authentication.* configs are honored in HttpFS. If the both configs are set, httpfs.authentication.* configs are effective for compatibility.
Description
We are facing "Request is a replay (34)" error when accessing to HDFS via httpfs on trunk.
% curl -i --negotiate -u : "https://<host>:4443/webhdfs/v1/?op=liststatus" HTTP/1.1 401 Authentication required Date: Mon, 09 Sep 2019 06:00:04 GMT Date: Mon, 09 Sep 2019 06:00:04 GMT Pragma: no-cache X-Content-Type-Options: nosniff X-XSS-Protection: 1; mode=block WWW-Authenticate: Negotiate Set-Cookie: hadoop.auth=; Path=/; Secure; HttpOnly Cache-Control: must-revalidate,no-cache,no-store Content-Type: text/html;charset=iso-8859-1 Content-Length: 271 HTTP/1.1 403 GSSException: Failure unspecified at GSS-API level (Mechanism level: Request is a replay (34)) Date: Mon, 09 Sep 2019 06:00:04 GMT Date: Mon, 09 Sep 2019 06:00:04 GMT Pragma: no-cache X-Content-Type-Options: nosniff X-XSS-Protection: 1; mode=block (snip) Set-Cookie: hadoop.auth=; Path=/; Secure; HttpOnly Cache-Control: must-revalidate,no-cache,no-store Content-Type: text/html;charset=iso-8859-1 Content-Length: 413 <html> <head> <meta http-equiv="Content-Type" content="text/html;charset=utf-8"/> <title>Error 403 GSSException: Failure unspecified at GSS-API level (Mechanism level: Request is a replay (34))</title> </head> <body><h2>HTTP ERROR 403</h2> <p>Problem accessing /webhdfs/v1/. Reason: <pre> GSSException: Failure unspecified at GSS-API level (Mechanism level: Request is a replay (34))</pre></p> </body> </html>
Attachments
Attachments
Issue Links
- is broken by
-
HADOOP-16314 Make sure all end point URL is covered by the same AuthenticationFilter
- Resolved