[ 
https://issues.apache.org/jira/browse/HADOOP-18919?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17776092#comment-17776092
 ] 

ASF GitHub Bot commented on HADOOP-18919:
-----------------------------------------

dombizita opened a new pull request, #6194:
URL: https://github.com/apache/hadoop/pull/6194

   ### Description of PR
   
   Previously in #5638 there were methods added to ZKCuratorManager, where we 
are setting the SSL configuration in a ZKClientConfig if SSL is enabled for ZK. 
I moved this to SecurityUtil and use it to construct the same for HDFS. HDFS is 
creating ZooKeeper instance in ZKFC, where it is not using ZKCuratorManager. 
   
   I added HDFS configuration key called `dfs.ha.zkfc.client.ssl.enabled`, 
which is storing the enablement of SSL in ZKFC. If it is enabled, we are 
creating a TruststoreKeystore and give it to ActiveStandbyElector during 
initialisation and later set the SSL configs there, so the ZooKeeper will be 
created correctly.
   
   ### How was this patch tested?
   
   I added unit tests, which are checking if we are creating a ZK with/without 
TruststoreKeystore it is setting the truststore/keystore location and password 
accordingly in the ZKClientConfig.
   
   ### For code changes:
   
   - [x] Does the title or this PR starts with the corresponding JIRA issue id 
(e.g. 'HADOOP-17799. Your PR title ...')?
   - [ ] Object storage: have the integration tests been executed and the 
endpoint declared according to the connector-specific documentation?
   - [ ] If adding new dependencies to the code, are these dependencies 
licensed in a way that is compatible for inclusion under [ASF 
2.0](http://www.apache.org/legal/resolved.html#category-a)?
   - [ ] If applicable, have you updated the `LICENSE`, `LICENSE-binary`, 
`NOTICE-binary` files?
   
   




> Zookeeper SSL/TLS support in HDFS 
> ----------------------------------
>
>                 Key: HADOOP-18919
>                 URL: https://issues.apache.org/jira/browse/HADOOP-18919
>             Project: Hadoop Common
>          Issue Type: Improvement
>            Reporter: Zita Dombi
>            Assignee: Zita Dombi
>            Priority: Major
>
> HADOOP-18709 added support for Zookeeper to communicate with SSL/TLS enabled 
> in hadoop-common. With those changes we have the necessary parameters, that 
> we need to set to enable SSL/TLS in a ZK Client.
> In YARN-11468 the SSL communication can be set in Yarn, now we need to 
> similar changes in HDFS to enable it correctly. In HDFS ZK Client is used in 
> the Failover Controller. In this improvement we need to create the ZK client 
> with the necessary SSL configs if we enable it, which we can track under a 
> new HDFS config.  



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to