Uploaded image for project: 'Hadoop Common'
  1. Hadoop Common
  2. HADOOP-12787

KMS SPNEGO sequence does not work with WEBHDFS

VotersWatch issueWatchersCreate sub-taskLinkCloneUpdate Comment AuthorReplace String in CommentUpdate Comment VisibilityDelete Comments
    XMLWordPrintableJSON

Details

    • Bug
    • Status: Resolved
    • Major
    • Resolution: Fixed
    • 2.6.3
    • 2.8.0, 3.0.0-alpha1
    • kms, security
    • None
    • Reviewed

    Description

      This was a follow up of my comments for HADOOP-10698.

      It blocks a delegation token based user (MR) using WEBHDFS to access KMS server for encrypted files. This might work in many cases before as JDK 7 has been aggressively do SPENGO implicitly. However, this is not the case in JDK 8 as we have seen many failures when using WEBHDFS with KMS and HDFS encryption zone.

      Attachments

        1. HADOOP-12878.00.patch
          5 kB
          Xiaoyu Yao
        2. HADOOP-12878.01.patch
          5 kB
          Xiaoyu Yao
        3. HADOOP-12878.02.patch
          5 kB
          Xiaoyu Yao
        4. HADOOP-12878.03.patch
          2 kB
          Xiaoyu Yao

        Issue Links

        Activity

          This comment will be Viewable by All Users Viewable by All Users
          Cancel

          People

            xyao Xiaoyu Yao
            xyao Xiaoyu Yao
            Votes:
            0 Vote for this issue
            Watchers:
            9 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved:

              Slack

                Issue deployment