[ https://issues.apache.org/jira/browse/HADOOP-8518?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=13398901#comment-13398901 ]
Kihwal Lee commented on HADOOP-8518: ------------------------------------ bq. I'm not up to speed on spnego, so could you educate me as to why the client needs to canonicalize the remote host? HADOOP-8043 might offer you some background/hint. > SPNEGO client side should use KerberosName rules > ------------------------------------------------ > > Key: HADOOP-8518 > URL: https://issues.apache.org/jira/browse/HADOOP-8518 > Project: Hadoop Common > Issue Type: Improvement > Components: security > Affects Versions: 1.0.3, 2.0.0-alpha > Reporter: Alejandro Abdelnur > Assignee: Alejandro Abdelnur > Fix For: 1.1.0, 2.0.1-alpha > > > currently KerberosName is used only on the server side to resolve the client > name, we should use it on the client side as well to resolve the server name > before getting the kerberos ticket. -- This message is automatically generated by JIRA. If you think it was sent incorrectly, please contact your JIRA administrators: https://issues.apache.org/jira/secure/ContactAdministrators!default.jspa For more information on JIRA, see: http://www.atlassian.com/software/jira