Details
-
Bug
-
Status: Open
-
Major
-
Resolution: Unresolved
-
1.2.1
-
None
-
None
Description
Some online document describes how to setup WebHCat with SPNEGO support. However, there could be multiple services use SPNEGO on the same host. For example, HBase REST API can also setup to use HTTP principal for SPNEGO support. When HTTP principal is shared among other services, Hadoop proxy user settings can not identify the origin of doAs call with HTTP principal, is invoked by HBase REST API or WebHCat. Ideally, WebHCat should keep track of its own service principal independent of SPNEGO principal to ensure that SPNEGO principal is only given authentication access. SPNEGO principal should not be used in proxy user setting to grant authorization access.
Attachments
Issue Links
- blocks
-
AMBARI-21577 Hive-Service check failing in post EU validation (BI-HDP)
- Resolved