[ 
https://issues.apache.org/jira/browse/AMBARI-11001?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=15051118#comment-15051118
 ] 

Jeffrey E  Rodriguez commented on AMBARI-11001:
-----------------------------------------------

Thanks for your prompt answer Robert. I had the need to kerberize amber-server 
so hdfs file view access would work and everything is working fine, but I was 
curious about where and how is Ambari renewing the TGT ticket, since it would 
expire. Jaas setting "renewTGT=true" with "useTicketCache=true" is one way. 
Many other components in the stack do it that way, e.g. check Knox. 
>From you comment I read that we use "kinit -k 
>/etc/security/keytabs/ambari.keytab", but without knowing where in the code I 
>am assuming that is done that way. Can you please let us know where in the 
>code this is done? 
Again Thanks.

> Ambari uses users' interactive ticket cache
> -------------------------------------------
>
>                 Key: AMBARI-11001
>                 URL: https://issues.apache.org/jira/browse/AMBARI-11001
>             Project: Ambari
>          Issue Type: Bug
>          Components: ambari-server
>    Affects Versions: 2.1.0
>            Reporter: Robert Levas
>            Assignee: Robert Levas
>            Priority: Critical
>              Labels: JAAS
>             Fix For: 2.1.0
>
>         Attachments: AMBARI-11001_01.patch
>
>
> It appears that it is necessary to kinit prior to starting ambari-server, 
> even after ambari-server setup-security (#3). It seems that this should be 
> automatically handled by Ambari. 
> Ambari-server should NOT use the same ticket cache as the interactive user. 
> STR:
> 1. kinit
> 2. ambari-server start
> 3. verify that ambari-server can authenticate with ticket specified in #1
> 4. kdestroy
> 5. try to authenticate through Ambari again (it will not work)
> *Solution*
> Ensure JAAS Login works properly such that the Kerberos tickets for the 
> account that executes Ambari is not relevant.



--
This message was sent by Atlassian JIRA
(v6.3.4#6332)

Reply via email to