hadoop-common-issues mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From "Yi Liu (JIRA)" <j...@apache.org>
Subject [jira] [Updated] (HADOOP-10693) Implementation of AES-CTR CryptoCodec using JNI to OpenSSL
Date Wed, 25 Jun 2014 13:14:24 GMT

     [ https://issues.apache.org/jira/browse/HADOOP-10693?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel

Yi Liu updated HADOOP-10693:

    Attachment: HADOOP-10693.2.patch

Thanks [~cmccabe] for your nice review.  The new patch includes update for your comments.
It's not really "crypto" we're locating with this, but the openssl library. So the options
should be named -Dopenssl.prefix, etc. Similar with a lot of the constants and other code
Right, I update it.

General formatting: we have an 80-column limit in Hadoop.
I update it. My bad, I thought we didn’t need this limit in JNI.

Formatting: should be char *input_bytes. Also, you need to check these against null, since
they may not succeed on some JVMs or if a non-direct buffer was passed.
I update it.

You can just write {{dlsym_EVP_CipherUpdate(...)}}. Same with all the other calls to function
I update it.

> Implementation of AES-CTR CryptoCodec using JNI to OpenSSL
> ----------------------------------------------------------
>                 Key: HADOOP-10693
>                 URL: https://issues.apache.org/jira/browse/HADOOP-10693
>             Project: Hadoop Common
>          Issue Type: Sub-task
>          Components: security
>    Affects Versions: fs-encryption (HADOOP-10150 and HDFS-6134)
>            Reporter: Yi Liu
>            Assignee: Yi Liu
>             Fix For: fs-encryption (HADOOP-10150 and HDFS-6134)
>         Attachments: HADOOP-10693.1.patch, HADOOP-10693.2.patch, HADOOP-10693.patch
> In HADOOP-10603, we have an implementation of AES-CTR CryptoCodec using Java JCE provider.

> To get high performance, the configured JCE provider should utilize native code and AES-NI,
but in JDK6,7 the Java embedded provider doesn't support it.
> Considering not all hadoop user will use the provider like Diceros or able to get signed
certificate from oracle to develop a custom provider, so this JIRA will have an implementation
of AES-CTR CryptoCodec using JNI to OpenSSL directly.

This message was sent by Atlassian JIRA

View raw message