Return-Path: X-Original-To: apmail-ambari-dev-archive@www.apache.org Delivered-To: apmail-ambari-dev-archive@www.apache.org Received: from mail.apache.org (hermes.apache.org [140.211.11.3]) by minotaur.apache.org (Postfix) with SMTP id 770BD110F3 for ; Tue, 16 Sep 2014 20:56:35 +0000 (UTC) Received: (qmail 23249 invoked by uid 500); 16 Sep 2014 20:56:35 -0000 Delivered-To: apmail-ambari-dev-archive@ambari.apache.org Received: (qmail 23176 invoked by uid 500); 16 Sep 2014 20:56:35 -0000 Mailing-List: contact dev-help@ambari.apache.org; run by ezmlm Precedence: bulk List-Help: List-Unsubscribe: List-Post: List-Id: Reply-To: dev@ambari.apache.org Delivered-To: mailing list dev@ambari.apache.org Received: (qmail 23040 invoked by uid 99); 16 Sep 2014 20:56:35 -0000 Received: from arcas.apache.org (HELO arcas.apache.org) (140.211.11.28) by apache.org (qpsmtpd/0.29) with ESMTP; Tue, 16 Sep 2014 20:56:35 +0000 Date: Tue, 16 Sep 2014 20:56:35 +0000 (UTC) From: "Yusaku Sako (JIRA)" To: dev@ambari.apache.org Message-ID: In-Reply-To: References: Subject: [jira] [Updated] (AMBARI-7204) Ambari Automated Kerberization MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: 7bit X-JIRA-FingerPrint: 30527f35849b9dde25b450d4833f0394 [ https://issues.apache.org/jira/browse/AMBARI-7204?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Yusaku Sako updated AMBARI-7204: -------------------------------- Fix Version/s: 2.0.0 > Ambari Automated Kerberization > ------------------------------ > > Key: AMBARI-7204 > URL: https://issues.apache.org/jira/browse/AMBARI-7204 > Project: Ambari > Issue Type: Epic > Components: ambari-server, security, stacks > Affects Versions: 2.0.0 > Environment: Kerberos > Reporter: Robert Levas > Assignee: Robert Levas > Labels: active-directory, authentication, kerberos, mit-kerberos, security, stack > Fix For: 2.0.0 > > Attachments: AmbariClusterKerberization.pdf > > Original Estimate: 2,016h > Remaining Estimate: 2,016h > > *Problem* > Manually installing and setting up Kerberos for a secure Hadoop cluster is error prone, largely manual and a potential source of configuration problems. It requires many steps where configuration files and credentials may need to be distributed across many nodes. Because of this the process is time consuming and lead to a high probability of user error. > The problem is exacerbated when the cluster is modified by adding or removing nodes and services. > *Solution* > Use Ambari to secure the cluster using Kerberos. By automating the process of setting up Kerberos, the repetitive tasks of distributing configuration details and credentials can be done in parallel to the nodes within the cluster. This also negates most user-related errors due to the lack of interaction a user has with the process. > See [^AmbariClusterKerberization.pdf] for more details. -- This message was sent by Atlassian JIRA (v6.3.4#6332)