Details
-
Sub-task
-
Status: Closed
-
Critical
-
Resolution: Fixed
-
None
-
None
-
None
Description
- RM should generate the master-key randomly
- The master-key should roll every so often
- NM should remember old expired keys so that already doled out container-requests can be satisfied.
Attachments
Attachments
Issue Links
- breaks
-
YARN-60 NMs rejects all container tokens after secret key rolls
- Closed
- duplicates
-
MAPREDUCE-2742 [MR-279] [Security] All tokens in YARN + MR should have an expiry interval
- Resolved
-
MAPREDUCE-3105 NM<->RM shared secrets should be rolled every so often.
- Resolved
- is blocked by
-
MAPREDUCE-3940 ContainerTokens should have an expiry interval
- Closed
-
MAPREDUCE-3942 Randomize master key generation for ApplicationTokenSecretManager and roll it every so often
- Closed
- relates to
-
YARN-35 Move to per-node RM-NM secrets
- Open