Uploaded image for project: 'Hive'
  1. Hive
  2. HIVE-10115

HS2 running on a Kerberized cluster should offer Kerberos(GSSAPI) and Delegation token(DIGEST) when alternate authentication is enabled

    XMLWordPrintableJSON

    Details

    • Type: Improvement
    • Status: Closed
    • Priority: Major
    • Resolution: Fixed
    • Affects Version/s: 1.1.0
    • Fix Version/s: 1.3.0, 2.0.1, 2.1.0
    • Component/s: Authentication
    • Labels:

      Description

      In a Kerberized cluster when alternate authentication is enabled on HS2, it should also accept Kerberos Authentication. The reason this is important is because when we enable LDAP authentication HS2 stops accepting delegation token authentication. So we are forced to enter username passwords in the oozie configuration.
      The whole idea of SASL is that multiple authentication mechanism can be offered. If we disable Kerberos(GSSAPI) and delegation token (DIGEST) authentication when we enable LDAP authentication, this defeats SASL purpose.

        Attachments

        1. HIVE-10115.0.patch
          8 kB
          Mubashir Kazia
        2. HIVE-10115.2.patch
          9 kB
          Sergio Peña

          Issue Links

            Activity

              People

              • Assignee:
                mkazia Mubashir Kazia
                Reporter:
                mkazia Mubashir Kazia
              • Votes:
                1 Vote for this issue
                Watchers:
                11 Start watching this issue

                Dates

                • Created:
                  Updated:
                  Resolved: