Daryn Sharp created HADOOP-14146:
------------------------------------
Summary: KerberosAuthenticationHandler should authenticate with
SPN in AP-REQ
Key: HADOOP-14146
URL: https://issues.apache.org/jira/browse/HADOOP-14146
Project: Hadoop Common
Issue Type: Bug
Components: security
Affects Versions: 2.5.0
Reporter: Daryn Sharp
Assignee: Daryn Sharp
Many attempts (HADOOP-10158, HADOOP-11628, HADOOP-13565) have tried to add
multiple SPN host and/or realm support to spnego authentication. The basic
problem is the server tries to guess and/or brute force what SPN the client
used. The server should just decode the SPN from the AP-REQ.
--
This message was sent by Atlassian JIRA
(v6.3.15#6346)
---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]