ambari-issues mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From "Hadoop QA (JIRA)" <j...@apache.org>
Subject [jira] [Commented] (AMBARI-18836) Remove group readable from hdfs headless keytab
Date Fri, 11 Nov 2016 15:18:58 GMT

    [ https://issues.apache.org/jira/browse/AMBARI-18836?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=15657308#comment-15657308
] 

Hadoop QA commented on AMBARI-18836:
------------------------------------

{color:red}-1 overall{color}.  Here are the results of testing the latest attachment 
  http://issues.apache.org/jira/secure/attachment/12838432/0001-AMBARI-18836-Remove-group-readable-from-hdfs-headles.patch
  against trunk revision .

    {color:green}+1 @author{color}.  The patch does not contain any @author tags.

    {color:red}-1 tests included{color}.  The patch doesn't appear to include any new or modified
tests.
                        Please justify why no new tests are needed for this patch.
                        Also please list what manual steps were performed to verify this patch.

    {color:green}+1 javac{color}.  The applied patch does not increase the total number of
javac compiler warnings.

    {color:green}+1 release audit{color}.  The applied patch does not increase the total number
of release audit warnings.

    {color:red}-1 core tests{color}.  The test build failed in ambari-server 

Test results: https://builds.apache.org/job/Ambari-trunk-test-patch/9233//testReport/
Console output: https://builds.apache.org/job/Ambari-trunk-test-patch/9233//console

This message is automatically generated.

> Remove group readable from hdfs headless keytab
> -----------------------------------------------
>
>                 Key: AMBARI-18836
>                 URL: https://issues.apache.org/jira/browse/AMBARI-18836
>             Project: Ambari
>          Issue Type: Bug
>    Affects Versions: trunk
>            Reporter: Shi Wang
>            Assignee: Shi Wang
>             Fix For: trunk
>
>         Attachments: 0001-AMBARI-18836-Remove-group-readable-from-hdfs-headles.patch
>
>
> The Smoke and “Headless” Service users are used by Ambari to perform service “smoke”
checks and run alert health checks. 
> The permission for hdfs.headless.keytab is 440. But it will cause security concern to
allow other service user in hadoop group to kinit hdfs headless principal using hdfs.headless.keytab.
In this way, other service user could "pretend" to be hdfs user and be granted hdfs user's
authorities.



--
This message was sent by Atlassian JIRA
(v6.3.4#6332)

Mime
View raw message