ambari-dev mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From "Robert Levas (JIRA)" <j...@apache.org>
Subject [jira] [Commented] (AMBARI-11001) Ambari uses users' interactive ticket cache
Date Thu, 10 Dec 2015 12:00:16 GMT

    [ https://issues.apache.org/jira/browse/AMBARI-11001?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=15050649#comment-15050649
] 

Robert Levas commented on AMBARI-11001:
---------------------------------------

[~jeffreyr97]... I haven't heard of any issue related to this.  Ambari is configured to authenticate
using a keytab, rather than the user's interactive ticket cache. In order for {{renewTGT}}
to be set to {{true}, {{useTicketCache}} must be set to {{true}}. If {{useTicketCache}} is
set to {{true}}, then you cannot use a keytab to authenticate.

See https://docs.oracle.com/javase/7/docs/jre/api/security/jaas/spec/com/sun/security/auth/module/Krb5LoginModule.html.


> Ambari uses users' interactive ticket cache
> -------------------------------------------
>
>                 Key: AMBARI-11001
>                 URL: https://issues.apache.org/jira/browse/AMBARI-11001
>             Project: Ambari
>          Issue Type: Bug
>          Components: ambari-server
>    Affects Versions: 2.1.0
>            Reporter: Robert Levas
>            Assignee: Robert Levas
>            Priority: Critical
>              Labels: JAAS
>             Fix For: 2.1.0
>
>         Attachments: AMBARI-11001_01.patch
>
>
> It appears that it is necessary to kinit prior to starting ambari-server, even after
ambari-server setup-security (#3). It seems that this should be automatically handled by Ambari.

> Ambari-server should NOT use the same ticket cache as the interactive user. 
> STR:
> 1. kinit
> 2. ambari-server start
> 3. verify that ambari-server can authenticate with ticket specified in #1
> 4. kdestroy
> 5. try to authenticate through Ambari again (it will not work)
> *Solution*
> Ensure JAAS Login works properly such that the Kerberos tickets for the account that
executes Ambari is not relevant.



--
This message was sent by Atlassian JIRA
(v6.3.4#6332)

Mime
View raw message