Uploaded image for project: 'Apache Storm'
  1. Apache Storm
  2. STORM-3044

AutoTGT should ideally check if a TGT is specific to IP addresses and reject

    XMLWordPrintableJSON

Details

    • Improvement
    • Status: Resolved
    • Major
    • Resolution: Fixed
    • None
    • 2.0.0
    • None

    Description

      There are several options that a TGT can have, one of them is being forwardable, another is having one or more IP addresses in it that make it so it cannot be used anywhere else. If the ticket is forwardable, but is tied to IP addresses it will not likely work for storm so we should reject it.

      It looks like we can call getClientAddresses() on the ticket and if it returns something then we should reject it. We should also include instructions about how to get a proper ticekt in the error message.

      `kinit -A -f`

      Attachments

        Issue Links

          Activity

            People

              ethanli Ethan Li
              ethanli Ethan Li
              Votes:
              0 Vote for this issue
              Watchers:
              1 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved:

                Time Tracking

                  Estimated:
                  Original Estimate - Not Specified
                  Not Specified
                  Remaining:
                  Remaining Estimate - 0h
                  0h
                  Logged:
                  Time Spent - 40m
                  40m