+1 (binding)

I have tested the release candidate as follows:


- Verified the signatures

- Reviewed NOTICE, LICENSE and CHANGES files

- Built from source and ran all tests (clean verify)

- Tested the binary distribution

- Exercised Knox Homepage

- Exercised the Admin UI

    - Created provider configs and descriptors

    - Verified non-admin user cannot see contents

- Exercised the token management UI

- Tested the CLIENTID API, APIKEY API, KNOXTOKEN, all deployed in the same
topology with different param values




On Tue, Sep 8, 2026 at 8:12 AM Tamás Hanicz <[email protected]> wrote:

> +1 (binding)
> I executed the below tests:
>
>    - Built from source and ran all unit tests
>    - Reviewed NOTICE, LICENSE and CHANGES files
>    - Tested UI upgrades
>    - Tested LDAP cache
>    - Tested SSE support in HA and non-HA mode
>    - Tested loadbalancing
>    - Tested Oracle DB support
>    - Tested recent KnoxToken, passcode, admin api, sso redirect
> improvements
>    - Tested async.supported.topologies gateway-site config
>
>
> Sandor Molnar <[email protected]> ezt írta (időpont: 2026. szept. 8., K,
> 13:37):
>
> > +1 (binding)
> >
> > Hi Tamas!
> >
> > First of all, thank you for bringing 3.0.0 to life.
> >
> > Here is my +1 for v3.0.0 RC2. I focused on the areas I contributed to and
> > executed the following tests:
> >
> > - Verified the signatures and checksums
> > - Reviewed NOTICE, LICENSE and CHANGES files
> > - Checked out the v3.0.0 branch and built the source and ran all tests
> > (mvn clean -Dshellcheck=true verify -Prelease,package) on ARM64; all
> worked
> > properly
> > - Cross-checked the CHANGES entries for fix version 3.0.0 against my
> > resolved issues
> > - Deployed the binary distribution locally and tested the embedded Knox
> > LDAP server:
> >   - LDAPS on the embedded server; anonymous bind/search rejected once
> bind
> > credentials are configured
> >   - LDAP system password resolved from the gateway credential store
> > (fallback when not in the topology)
> >   - recursive/nested group resolution
> >   - role lookup for a user with no group (roles written out as full DNs)
> >   - pluggable file-based role lookup
> >   - end-to-end login against a backing LDAP over LDAPS (both the search
> > bind and the user bind go over TLS)
> > - Group/role headers propagated to downstream services:
> >   - role header uses the raw prefix while group headers keep their
> indexed
> > form
> >   - inherited roles present in the headers
> >   - group header capped by byte size rather than by count
> >   - group-based renew/revoke whitelist enforced (allowed group in, others
> > rejected)
> > - OAuth / RFC 8693 token exchange:
> >   - form-urlencoded token exchange reaches the handler and validates the
> > actor token
> >   - issued token subject is the subject (not the actor) on a
> > non-server-managed topology
> >   - client-credentials subject reconciliation
> >   - invalid/mismatched client_id/secret rejected
> >   - client_credentials, refresh_token and token_exchange all still work
> > after the grant-type refactor
> > - Token State Service / limits / UI:
> >   - deprecated TokenStateService implementations removed; supported
> > backends work
> >   - topology-level token-per-user limit overrides the gateway-level
> setting
> >   - API_KEY tokens show the correct icon in Token Management
> > - Auth providers:
> >   - RemoteAuthFilter no longer NPEs when the cache-key header is absent
> >   - virtual group membership computed from a request parameter
> >   - HadoopGroup provider no longer NPEs when the groups instance isn't
> > initialized
> > - Admin API / dynamic config:
> >   - publicCert endpoint returns the signing keystore certificate when SSL
> > is disabled
> >   - gateway-reloadable.xml changes are picked up without a restart
> >   - knoxcli user-auth-test works under JDK 17
> > - SSO across a local + remote k8s cluster: the remote cluster set as the
> > SSO authN URL, the local cluster verifying tokens against the remote's
> JWKS
> > URL with the cookie domain configured
> > - Cloudera Manager service discovery in real CM clusters: scheme
> selection
> > (ICEBERG-REST), discovery against CM without TLS, the dedicated CM client
> > TLS config, a FIPS host, rolling-restart staleness handling, and
> confirmed
> > configuration-change monitoring is postponed until the gateway is up
> > - Docker-based startup exercised by the automated E2E tests (single-EKU
> > startup within the wait window, token hash-key alias auto-creation on a
> > fresh container, ALIAS_PASSPHRASE handling)
> >
> > On 2026/09/02 09:39:08 Tamás Hanicz wrote:
> > >  Hi Folks,
> > >
> > > Release candidate #2 for the Apache Knox 3.0.0 release is available at:
> > > https://dist.apache.org/repos/dist/dev/knox/knox-3.0.0/
> > >
> > > The release candidate is a zip archive of the sources in:
> > > https://https://gitbox.apache.org/repos/asf/knox.git
> > > Branch v3.0.0 (git checkout -b v3.0.0)
> > >
> > > The KEYS file for signature validation is available at:
> > > https://dist.apache.org/repos/dist/release/knox/KEYS
> > >
> > > Please find the most recent changes here:
> > > https://github.com/apache/knox/blob/v3.0.0/CHANGES
> > >
> > > KnoxShell User Guide:
> > >
> >
> https://github.com/apache/knox/blob/v3.0.0/knox-site/docs/knoxshell-guide/knoxshell_user_guide.md
> > >
> > > Gateway User Guide:
> > > https://github.com/apache/knox/blob/v3.0.0/knox-site/docs/book.md
> > >
> > > Dev Guide:
> > >
> >
> https://github.com/apache/knox/blob/v3.0.0/knox-site/docs/dev-guide/book.md
> > >
> > > Please vote on releasing this package as Apache Knox 3.0.0.
> > > The vote is open for the next 168 hours and passes if a majority of at
> > > least three +1 Apache Knox PMC votes are cast.
> > >
> > > [ ] +1 Release this package as Apache Knox 3.0.0
> > > [ ] -1 Do not release this package because...
> > >
> > > Thanks,Tamás
> > >
> >
>

Reply via email to