Uploaded image for project: 'Kudu'
  1. Kudu
  2. KUDU-1845

Kerberos client keytab should be periodically renewed

    XMLWordPrintableJSON

Details

    • Improvement
    • Status: Resolved
    • Critical
    • Resolution: Fixed
    • None
    • 1.3.0
    • security
    • None

    Description

      Currently, security/init.cc initializes the Kerberos client keytab on startup, but never renews it. The credentials expire after some time so it's important to have some thread which renews it before expiration (hopefully in such a way that if a renewal transiently fails, we don't lose our previously good ticket)

      Attachments

        Activity

          People

            sailesh Sailesh Mukil
            tlipcon Todd Lipcon
            Votes:
            0 Vote for this issue
            Watchers:
            2 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: