Details
-
Improvement
-
Status: Resolved
-
Major
-
Resolution: Fixed
-
Slider 0.90.2
-
None
-
Kerberos
Description
Proposed enhancements
- make easier to run server-side. the sysprops to enable com.sun debugging should be cached and then restored —and only set if a -verbose flag is set.
- check for Java Crypto Extensions having full key length; fail fast if not
- list tokens
- add option to check networking (hostname resolves)
- look up KDCs and fail if none are reachable
- maybe each title() call should force flush stderr, to try and keep JDK output in sync with stdout.
- am to have option to display this and also fail fast
- implement `--services` probes for : yarn, hdfs, registry, timeline. This can't go into any hadoop-common lib, a list of probes classes can be provided to execute as the provided UGI.
Attachments
Issue Links
- breaks
-
SLIDER-1065 kdiag test failing on host without default realm
- Resolved
- is related to
-
HADOOP-12649 Improve Kerberos diagnostics and failure handling
- Open
- relates to
-
SLIDER-1059 Kdiag: validate and dump user credential cache file
- Open
-
SLIDER-1057 Kdiag: dump and tell if AES 256 is enabled or not
- Resolved
-
SLIDER-1058 Kdiag: dump keytab file out so user may aware its content
- Resolved