hadoop-common-issues mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From "Mingliang Liu (JIRA)" <j...@apache.org>
Subject [jira] [Commented] (HADOOP-13945) Azure: Add Kerberos and Delegation token support to WASB client.
Date Wed, 15 Feb 2017 22:43:41 GMT

    [ https://issues.apache.org/jira/browse/HADOOP-13945?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=15868742#comment-15868742
] 

Mingliang Liu commented on HADOOP-13945:
----------------------------------------

Thanks for updating the patch. I'll review the v4 patch this week.

Early comments:
{code}
35	   * @return True - If initialization successful
36	   *         False - Otherwise
37	   */
38	  public void init(Configuration conf)
39	      throws WasbAuthorizationException, IOException;
{code}
The @return is wrongly annotated as the {{init()}} is void return type.

Failing unit test is not related.
We can checkstyle warning before commit, e,g, to make {{DEFAULT_AZURE_AUTHORIZATION}} final.
Specially file length warning can be ignored as it's mostly existing and can be fixed separately.



> Azure: Add Kerberos and Delegation token support to WASB client.
> ----------------------------------------------------------------
>
>                 Key: HADOOP-13945
>                 URL: https://issues.apache.org/jira/browse/HADOOP-13945
>             Project: Hadoop Common
>          Issue Type: Improvement
>          Components: fs/azure
>    Affects Versions: 2.8.0
>            Reporter: Santhosh G Nayak
>            Assignee: Santhosh G Nayak
>         Attachments: HADOOP-13945.1.patch, HADOOP-13945.2.patch, HADOOP-13945.3.patch,
HADOOP-13945.4.patch
>
>
> Current implementation of Azure storage client for Hadoop ({{WASB}}) does not support
Kerberos Authentication and FileSystem authorization, which makes it unusable in secure environments
with multi user setup. 
> To make {{WASB}} client more suitable to run in Secure environments, there are 2 initiatives
under way for providing the authorization (HADOOP-13930) and fine grained access control (HADOOP-13863)
support.
> This JIRA is created to add Kerberos and delegation token support to {{WASB}} client
to fetch Azure Storage SAS keys (from Remote service as discussed in HADOOP-13863), which
provides fine grained timed access to containers and blobs. 
> For delegation token management, the proposal is it use the same REST service which being
used to generate the SAS Keys.



--
This message was sent by Atlassian JIRA
(v6.3.15#6346)

---------------------------------------------------------------------
To unsubscribe, e-mail: common-issues-unsubscribe@hadoop.apache.org
For additional commands, e-mail: common-issues-help@hadoop.apache.org


Mime
View raw message