Return-Path: X-Original-To: archive-asf-public-internal@cust-asf2.ponee.io Delivered-To: archive-asf-public-internal@cust-asf2.ponee.io Received: from cust-asf.ponee.io (cust-asf.ponee.io [163.172.22.183]) by cust-asf2.ponee.io (Postfix) with ESMTP id 45BDA200CD1 for ; Tue, 11 Jul 2017 20:54:08 +0200 (CEST) Received: by cust-asf.ponee.io (Postfix) id 44D19166F5E; Tue, 11 Jul 2017 18:54:08 +0000 (UTC) Delivered-To: archive-asf-public@cust-asf.ponee.io Received: from mail.apache.org (hermes.apache.org [140.211.11.3]) by cust-asf.ponee.io (Postfix) with SMTP id 99DD5166F5B for ; Tue, 11 Jul 2017 20:54:07 +0200 (CEST) Received: (qmail 80414 invoked by uid 500); 11 Jul 2017 18:54:06 -0000 Mailing-List: contact hdfs-issues-help@hadoop.apache.org; run by ezmlm Precedence: bulk List-Help: List-Unsubscribe: List-Post: List-Id: Delivered-To: mailing list hdfs-issues@hadoop.apache.org Received: (qmail 80357 invoked by uid 99); 11 Jul 2017 18:54:06 -0000 Received: from pnap-us-west-generic-nat.apache.org (HELO spamd3-us-west.apache.org) (209.188.14.142) by apache.org (qpsmtpd/0.29) with ESMTP; Tue, 11 Jul 2017 18:54:06 +0000 Received: from localhost (localhost [127.0.0.1]) by spamd3-us-west.apache.org (ASF Mail Server at spamd3-us-west.apache.org) with ESMTP id 301621960F2 for ; Tue, 11 Jul 2017 18:54:06 +0000 (UTC) X-Virus-Scanned: Debian amavisd-new at spamd3-us-west.apache.org X-Spam-Flag: NO X-Spam-Score: -99.202 X-Spam-Level: X-Spam-Status: No, score=-99.202 tagged_above=-999 required=6.31 tests=[KAM_ASCII_DIVIDERS=0.8, RP_MATCHES_RCVD=-0.001, SPF_PASS=-0.001, USER_IN_WHITELIST=-100] autolearn=disabled Received: from mx1-lw-us.apache.org ([10.40.0.8]) by localhost (spamd3-us-west.apache.org [10.40.0.10]) (amavisd-new, port 10024) with ESMTP id fBiZ-LbCc1Yy for ; Tue, 11 Jul 2017 18:54:05 +0000 (UTC) Received: from mailrelay1-us-west.apache.org (mailrelay1-us-west.apache.org [209.188.14.139]) by mx1-lw-us.apache.org (ASF Mail Server at mx1-lw-us.apache.org) with ESMTP id BB00A624D7 for ; Tue, 11 Jul 2017 18:54:03 +0000 (UTC) Received: from jira-lw-us.apache.org (unknown [207.244.88.139]) by mailrelay1-us-west.apache.org (ASF Mail Server at mailrelay1-us-west.apache.org) with ESMTP id 9CE32E0E02 for ; Tue, 11 Jul 2017 18:54:02 +0000 (UTC) Received: from jira-lw-us.apache.org (localhost [127.0.0.1]) by jira-lw-us.apache.org (ASF Mail Server at jira-lw-us.apache.org) with ESMTP id 8D090246E1 for ; Tue, 11 Jul 2017 18:54:01 +0000 (UTC) Date: Tue, 11 Jul 2017 18:54:01 +0000 (UTC) From: "Hudson (JIRA)" To: hdfs-issues@hadoop.apache.org Message-ID: In-Reply-To: References: Subject: [jira] [Commented] (HDFS-12052) Set SWEBHDFS delegation token kind when ssl is enabled in HttpFS MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: 7bit X-JIRA-FingerPrint: 30527f35849b9dde25b450d4833f0394 archived-at: Tue, 11 Jul 2017 18:54:08 -0000 [ https://issues.apache.org/jira/browse/HDFS-12052?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=16082754#comment-16082754 ] Hudson commented on HDFS-12052: ------------------------------- SUCCESS: Integrated in Jenkins build Hadoop-trunk-Commit #11988 (See [https://builds.apache.org/job/Hadoop-trunk-Commit/11988/]) HDFS-12052. Set SWEBHDFS delegation token kind when ssl is enabled in (jzhuge: rev 12c8fdceaf263425661169cba25402df89d444c1) * (edit) hadoop-hdfs-project/hadoop-hdfs-httpfs/src/main/java/org/apache/hadoop/fs/http/server/HttpFSAuthenticationFilter.java * (edit) hadoop-hdfs-project/hadoop-hdfs-httpfs/src/main/java/org/apache/hadoop/fs/http/server/HttpFSServerWebServer.java * (edit) hadoop-hdfs-project/hadoop-hdfs-httpfs/src/test/java/org/apache/hadoop/fs/http/server/TestHttpFSServer.java * (edit) hadoop-hdfs-project/hadoop-hdfs-httpfs/src/test/java/org/apache/hadoop/fs/http/server/HttpFSKerberosAuthenticationHandlerForTesting.java > Set SWEBHDFS delegation token kind when ssl is enabled in HttpFS > ---------------------------------------------------------------- > > Key: HDFS-12052 > URL: https://issues.apache.org/jira/browse/HDFS-12052 > Project: Hadoop HDFS > Issue Type: Bug > Components: httpfs, webhdfs > Affects Versions: 2.7.3, 3.0.0-alpha3 > Reporter: Zoran Dimitrijevic > Assignee: Zoran Dimitrijevic > Fix For: 3.0.0-beta1 > > Attachments: HDFS-12052.00.patch, HDFS-12052.01.patch, HDFS-12052.02.patch, HDFS-12052.03.patch, HDFS-12052.04.patch, HDFS-12052.05.patch, HDFS-12052.06.patch, HDFS-12052.07.patch > > > When httpfs runs with httpfs.ssl.enabled it should return SWEBHDFS delegation tokens. > Currently, httpfs returns WEBHDFS delegation "kind" for tokens regardless of whether ssl is enabled or not. If clients directly connect to renew tokens (for example, hdfs dfs) all works because httpfs doesn't check whether token kind is for swebhdfs or webhdfs. However, this breaks when yarn rm needs to renew the token for the job (for example, when running hadoop distcp). Since DT kind is WEBHDFS, rm tries to establish non-ssl connection to httpfs and fails. > I've tested a simple patch which I'll upload to this jira, and it fixes this issue (hadoop distcp works). -- This message was sent by Atlassian JIRA (v6.4.14#64029) --------------------------------------------------------------------- To unsubscribe, e-mail: hdfs-issues-unsubscribe@hadoop.apache.org For additional commands, e-mail: hdfs-issues-help@hadoop.apache.org