Robert Kanter created OOZIE-2485:
------------------------------------

             Summary: Oozie client keeps trying to use expired auth token
                 Key: OOZIE-2485
                 URL: https://issues.apache.org/jira/browse/OOZIE-2485
             Project: Oozie
          Issue Type: Bug
          Components: client, security
    Affects Versions: trunk
            Reporter: Robert Kanter
            Assignee: Robert Kanter
            Priority: Blocker
             Fix For: trunk


When using Hadoop 2.4.0 or later, the Oozie client doesn't update the auth 
token when it expires.  The client doesn't typically give you an error because 
it will still fallback and authenticate via Kerberos or Pseudo.  However, this 
is inefficient.

This appears to be due to HADOOP-10301, which made an incompatible change with 
how the AuthHandler tells the Authenticator when a token has expired.  It used 
to give a 401 when the token expired, but now it will do SPNEGO (if you have 
Kerberos credentials) and return a new token, all in the same call.  Oozie 
client's code doesn't handle that case.



--
This message was sent by Atlassian JIRA
(v6.3.4#6332)

Reply via email to