Yi Liu created HADOOP-10768:
-------------------------------
Summary: Optimize Hadoop RPC encryption performance
Key: HADOOP-10768
URL: https://issues.apache.org/jira/browse/HADOOP-10768
Project: Hadoop Common
Issue Type: Improvement
Components: performance, security
Affects Versions: 3.0.0
Reporter: Yi Liu
Assignee: Yi Liu
Fix For: 3.0.0
Hadoop RPC encryption is enabled by setting {{hadoop.rpc.protection}} to
"privacy". It utilized SASL {{GSSAPI}} and {{DIGEST-MD5}} mechanisms for secure
authentication and data protection. Even {{GSSAPI}} supports using AES, but
without AES-NI support by default, so the encryption is slow and will become
bottleneck.
After discuss with [~atm], [~tucu00] and [~umamaheswararao], we can do the same
optimization as in HDFS-6606. Use AES-NI with more than *20x* speedup.
On the other hand, RPC message is small, but RPC is frequent and there may be
lots of RPC calls in one connection, we needs to setup benchmark to see real
improvement and then make a trade-off.
--
This message was sent by Atlassian JIRA
(v6.2#6252)