Details
-
Bug
-
Status: Resolved
-
Major
-
Resolution: Fixed
-
1.1.0, 1.2.0, 1.3.0
-
None
-
None
Description
HadoopAuthCookieStore checks to see if the cookie corresponds to Knox after KNOX-1341 and further improved in KNOX-2026.
The HS2 cookie format doesn't match what Knox expects though. Knox expects the cookie to have the entire principal (knox/hostname@REALM.COM). HS2 generates the authentication cookie based on the short name just "knox".
This causes a mismatch and Knox never stores the HS2 cookie. This results in repeated Knox Kerberos auth to HS2 which is a performance penalty.