Gregory Chanan created SOLR-9324:
------------------------------------

             Summary: Support Secure Impersonation / Proxy User for solr 
authentication
                 Key: SOLR-9324
                 URL: https://issues.apache.org/jira/browse/SOLR-9324
             Project: Solr
          Issue Type: Improvement
      Security Level: Public (Default Security Level. Issues are Public)
          Components: SolrCloud
            Reporter: Gregory Chanan


Solr should support Proxy User / Secure Impersonation for authentication, as 
supported by hadoop 
(http://hadoop.apache.org/docs/current/hadoop-project-dist/hadoop-common/Superusers.html)
 and supported by the hadoop AuthenticationFilter (which we use for the 
KerberosPlugin).

There are a number of use cases, but a common one is this:
There is a front end for searches (say, Hue http://gethue.com/) that supports 
its own login mechanisms.  If the cluster uses kerberos for authentication, hue 
must have kerberos credentials for each user, which is a pain to manage.  
Instead, hue can be allowed to impersonate known users from known machines so 
it only needs its own kerberos credentials.



--
This message was sent by Atlassian JIRA
(v6.3.4#6332)

---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to