Return-Path: X-Original-To: archive-asf-public-internal@cust-asf2.ponee.io Delivered-To: archive-asf-public-internal@cust-asf2.ponee.io Received: from cust-asf.ponee.io (cust-asf.ponee.io [163.172.22.183]) by cust-asf2.ponee.io (Postfix) with ESMTP id 34629200BB6 for ; Thu, 20 Oct 2016 22:58:00 +0200 (CEST) Received: by cust-asf.ponee.io (Postfix) id 330BA160ACC; Thu, 20 Oct 2016 20:58:00 +0000 (UTC) Delivered-To: archive-asf-public@cust-asf.ponee.io Received: from mail.apache.org (hermes.apache.org [140.211.11.3]) by cust-asf.ponee.io (Postfix) with SMTP id 78255160AE0 for ; Thu, 20 Oct 2016 22:57:59 +0200 (CEST) Received: (qmail 77017 invoked by uid 500); 20 Oct 2016 20:57:58 -0000 Mailing-List: contact issues-help@hive.apache.org; run by ezmlm Precedence: bulk List-Help: List-Unsubscribe: List-Post: List-Id: Reply-To: dev@hive.apache.org Delivered-To: mailing list issues@hive.apache.org Received: (qmail 76985 invoked by uid 99); 20 Oct 2016 20:57:58 -0000 Received: from arcas.apache.org (HELO arcas) (140.211.11.28) by apache.org (qpsmtpd/0.29) with ESMTP; Thu, 20 Oct 2016 20:57:58 +0000 Received: from arcas.apache.org (localhost [127.0.0.1]) by arcas (Postfix) with ESMTP id 7108B2C0D55 for ; Thu, 20 Oct 2016 20:57:58 +0000 (UTC) Date: Thu, 20 Oct 2016 20:57:58 +0000 (UTC) From: "Jimmy Xiang (JIRA)" To: issues@hive.apache.org Message-ID: In-Reply-To: References: Subject: [jira] [Commented] (HIVE-14984) Hive-WebUI access results in Request is a replay (34) attack MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: 7bit X-JIRA-FingerPrint: 30527f35849b9dde25b450d4833f0394 archived-at: Thu, 20 Oct 2016 20:58:00 -0000 [ https://issues.apache.org/jira/browse/HIVE-14984?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=15592987#comment-15592987 ] Jimmy Xiang commented on HIVE-14984: ------------------------------------ Good. Thanks. > Hive-WebUI access results in Request is a replay (34) attack > ------------------------------------------------------------ > > Key: HIVE-14984 > URL: https://issues.apache.org/jira/browse/HIVE-14984 > Project: Hive > Issue Type: Bug > Components: HiveServer2 > Affects Versions: 1.2.0 > Reporter: Venkat Sambath > Assignee: Barna Zsombor Klara > Attachments: HIVE-14984.patch > > > When trying to access kerberized webui of HS2, The following error is received > GSSException: Failure unspecified at GSS-API level (Mechanism level: Request is a replay (34)) > While this is not happening for RM webui (checked if kerberos webui is enabled) > To reproduce the issue > Try running > curl --negotiate -u : -b ~/cookiejar.txt -c ~/cookiejar.txt http://:10002/ > from any cluster nodes > or > Try accessing the URL from a VM with windows machine and firefox browser to replicate the issue > The following workaround helped, but need a permanent solution for the bug > Workaround: > ========= > First access the index.html directly and then actual URL of webui > curl --negotiate -u : -b ~/cookiejar.txt -c ~/cookiejar.txt http://:10002/index.html > curl --negotiate -u : -b ~/cookiejar.txt -c ~/cookiejar.txt http://:10002 > In browser: > First access > http://:10002/index.html > then > http://:10002 -- This message was sent by Atlassian JIRA (v6.3.4#6332)