hadoop-hdfs-issues mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From "Aaron T. Myers (JIRA)" <j...@apache.org>
Subject [jira] [Commented] (HDFS-3460) HttpFS proxyuser validation with Kerberos ON uses full principal name
Date Thu, 24 May 2012 00:27:40 GMT

    [ https://issues.apache.org/jira/browse/HDFS-3460?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=13282071#comment-13282071

Aaron T. Myers commented on HDFS-3460:

The patch looks good to me. +1 pending Jenkins.

Please unset the fix version until it's committed, and set the "target version" appropriately.
> HttpFS proxyuser validation with Kerberos ON uses full principal name
> ---------------------------------------------------------------------
>                 Key: HDFS-3460
>                 URL: https://issues.apache.org/jira/browse/HDFS-3460
>             Project: Hadoop HDFS
>          Issue Type: Bug
>    Affects Versions: 2.0.0-alpha
>            Reporter: Alejandro Abdelnur
>            Assignee: Alejandro Abdelnur
>            Priority: Critical
>             Fix For: 2.0.1-alpha
>         Attachments: HDFS-3460.patch
> The HttpFSServer.getEffectiveUser() method uses the principal name for proxy user verification.
If the Kerberos is ON and the proxy user is a service principal (NAME/HOST) then the verification
fails, instead the short name (just NAME) should be used.

This message is automatically generated by JIRA.
If you think it was sent incorrectly, please contact your JIRA administrators: https://issues.apache.org/jira/secure/ContactAdministrators!default.jspa
For more information on JIRA, see: http://www.atlassian.com/software/jira


View raw message