Uploaded image for project: 'Hive'
  1. Hive
  2. HIVE-6799

HiveServer2 needs to map kerberos name to local name before proxy check

    XMLWordPrintableJSON

Details

    • Improvement
    • Status: Closed
    • Critical
    • Resolution: Fixed
    • 0.13.1
    • 0.14.0
    • HiveServer2
    • None

    Description

      HiveServer2 does not map kerberos name of authenticated principal to local name.

      Due to this, I get error like the following in HiveServer log:
      Failed to validate proxy privilage of knox/hdps.example.com for sam

      I have KINITED as knox/hdps.example.com@EXAMPLE.COM

      I do have the following in core-site.xml

      <property>
      <name>hadoop.proxyuser.knox.groups</name>
      <value>users</value>
      </property>
      <property>
      <name>hadoop.proxyuser.knox.hosts</name>
      <value>*</value>
      </property>

      Attachments

        1. HIVE-6799-3.patch
          2 kB
          Dilli Arumugam
        2. HIVE-6799.patch
          2 kB
          Dilli Arumugam
        3. HIVE-6799.3.patch
          2 kB
          Vaibhav Gumashta
        4. HIVE-6799.2.patch
          2 kB
          Dilli Arumugam
        5. HIVE-6799.1.patch
          2 kB
          Dilli Arumugam

        Issue Links

          Activity

            People

              darumugam Dilli Arumugam
              darumugam Dilli Arumugam
              Votes:
              0 Vote for this issue
              Watchers:
              4 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved: