[ 
https://issues.apache.org/jira/browse/HADOOP-10863?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=14111853#comment-14111853
 ] 

Arun Suresh commented on HADOOP-10863:
--------------------------------------

[~benoyantony], Thank you for the suggestion.

In KMS's case, the KMS operation is actually encoded in the key name. I am of 
the opinion that keeping this as uppercase would make it stand out signifying 
that it is an operation, thus conveying intent better. Also this op matches the 
KMSAcls.Type enum, which is uppercase.


> KMS should have a blacklist for decrypting EEKs
> -----------------------------------------------
>
>                 Key: HADOOP-10863
>                 URL: https://issues.apache.org/jira/browse/HADOOP-10863
>             Project: Hadoop Common
>          Issue Type: Improvement
>          Components: security
>    Affects Versions: 3.0.0
>            Reporter: Alejandro Abdelnur
>            Assignee: Arun Suresh
>         Attachments: HADOOP-10863.1.patch, HADOOP-10863.2.patch, 
> HADOOP-10863.3.patch
>
>
> In particular, we'll need to put HDFS admin user there by default to prevent 
> an HDFS admin from getting file encryption keys.



--
This message was sent by Atlassian JIRA
(v6.2#6252)

Reply via email to