hive-dev mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From "Mubashir Kazia (JIRA)" <j...@apache.org>
Subject [jira] [Created] (HIVE-10115) HS2 running on a Kerberized cluster should offer Kerberos(GSSAPI) and Delegation token(DIGEST) when alternate authentication is enabled
Date Fri, 27 Mar 2015 04:30:53 GMT
Mubashir Kazia created HIVE-10115:
-------------------------------------

             Summary: HS2 running on a Kerberized cluster should offer Kerberos(GSSAPI) and
Delegation token(DIGEST) when alternate authentication is enabled
                 Key: HIVE-10115
                 URL: https://issues.apache.org/jira/browse/HIVE-10115
             Project: Hive
          Issue Type: Improvement
          Components: Authentication
    Affects Versions: 1.0.0
            Reporter: Mubashir Kazia
             Fix For: 1.1.0


In a Kerberized cluster when alternate authentication is enabled on HS2, it should also accept
Kerberos Authentication. The reason this is important is because when we enable LDAP authentication
HS2 stops accepting delegation token authentication. So we are forced to enter username passwords
in the oozie configuration.
The whole idea of SASL is that multiple authentication mechanism can be offered. If we disable
Kerberos(GSSAPI) and delegation token (DIGEST) authentication when we enable LDAP authentication,
this defeats SASL purpose.



--
This message was sent by Atlassian JIRA
(v6.3.4#6332)

Mime
View raw message