-----------------------------------------------------------
This is an automatically generated e-mail. To reply, visit:
https://reviews.apache.org/r/1958/
-----------------------------------------------------------

Review request for zookeeper.


Summary
-------

Currently, in Zookeeper trunk, there are two problems with Kerberos TGT renewal:

1. TGTs obtained from a keytab are not refreshed periodically. They should be, 
just as those from ticket cache are refreshed.

2. Ticket renewal should be retried if it fails. Ticket renewal might fail if 
two or more separate processes (different JVMs) running as the same user try to 
renew Kerberos credentials at the same time.


Diffs
-----

  src/java/main/org/apache/zookeeper/Login.java de64d0d 

Diff: https://reviews.apache.org/r/1958/diff


Testing
-------

Have tested this with a Kerberized HBase/Hadoop cluster on Amazon EC2. Tested 
with a short Kerberos ticket life (modprinc -maxlife "5 minutes") for zookeeper 
server and clients. Tested with zookeeper server using a keytab and zookeeper 
client with ticket cache. Ran YCSB on HBase successfully on a one master, 3 
regionserver cluster, where the master and 2 of the regionservers ran Quorum 
Peers.


Thanks,

Eugene

Reply via email to