hadoop-common-issues mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From "Kan Zhang (JIRA)" <j...@apache.org>
Subject [jira] Commented: (HADOOP-6907) Rpc client doesn't use the per-connection conf to figure out server's Kerberos principal
Date Mon, 30 Aug 2010 18:50:55 GMT

    [ https://issues.apache.org/jira/browse/HADOOP-6907?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=12904283#action_12904283

Kan Zhang commented on HADOOP-6907:

The 6 javadoc warnings are from SecurityUtil.java and KerberosName.java and not related to
this patch. The number of javac warnings from compile-core-classes stayed at 15, I don't know
why test-patch reported there is an increase of javac warnings.

> Rpc client doesn't use the per-connection conf to figure out server's Kerberos principal
> ----------------------------------------------------------------------------------------
>                 Key: HADOOP-6907
>                 URL: https://issues.apache.org/jira/browse/HADOOP-6907
>             Project: Hadoop Common
>          Issue Type: Bug
>          Components: ipc, security
>            Reporter: Kan Zhang
>            Assignee: Kan Zhang
>         Attachments: c6907-12.patch, c6907-15.patch, c6907-16.patch
> Currently, RPC client caches the conf that was passed in to its constructor and uses
that same conf (or values obtained from it) for every connection it sets up. This is not sufficient
for security since each connection needs to figure out server's Kerberos principal on a per-connection
basis. It's not reasonable to expect the first conf used by a user to contain all the Kerberos
principals that her future connections will ever need. Or worse, if her first conf contains
an incorrect principal name, it will prevent the user from connecting to the server even if
she later on passes in a correct conf on retry (by calling RPC.getProxy()).

This message is automatically generated by JIRA.
You can reply to this email to add a comment to the issue online.

View raw message