jjiang037 opened a new pull request, #6085:
URL: https://github.com/apache/hive/pull/6085
…rberos users
<!--
Thanks for sending a pull request! Here are some tips for you:
1. If this is your first time, please read our contributor guidelines:
https://cwiki.apache.org/confluence/display/Hive/HowToContribute
2. Ensure that you have created an issue on the Hive project JIRA:
https://issues.apache.org/jira/projects/HIVE/summary
3. Ensure you have added or run the appropriate tests for your PR:
4. If the PR is unfinished, add '[WIP]' in your PR title, e.g.,
'[WIP]HIVE-XXXXX: Your PR title ...'.
5. Be sure to keep the PR description updated to reflect all changes.
6. Please write your PR title to summarize what this PR proposes.
7. If possible, provide a concise example to reproduce the issue for a
faster review.
-->
### What changes were proposed in this pull request?
<!--
Please clarify what changes you are proposing. The purpose of this section
is to outline the changes and how this PR fixes the issue.
If possible, please consider writing useful notes for better and faster
reviews in your PR. See the examples below.
1. If you refactor some codes with changing classes, showing the class
hierarchy will help reviewers.
2. If you fix some SQL features, you can provide some references of other
DBMSes.
3. If there is design documentation, please add the link.
4. If there is a discussion in the mailing list, please add the link.
-->
This PR adds the capability to apply LDAP group filters to
Kerberos-authenticated users in both HS2 and HMS.
Key changes:
1. New configuration:
hive.server2.authentication.ldap.enableGroupCheckAfterKerberos (default: false)
to enable LDAP filtering for Kerberos users
2. LdapGroupCallbackHandler: New SASL callback handler that intercepts
Kerberos authentication and applies existing LDAP filters (userSearchFilter,
groupSearchFilter, customLDAPQuery, userFilter, groupFilter)
3. HadoopThriftAuthBridge enhancement: Modified to accept custom callback
handlers for both HMS and HiveServer2
4. ThriftHttpServlet enhancement: Added LDAP filter enforcement for HTTP
transport mode
5. Filter reuse: Leverages LdapAuthenticationProviderImpl.resolveFilter() to
ensure consistent filter resolution across authentication methods
### Why are the changes needed?
<!--
Please clarify why the changes are needed. For instance,
1. If you propose a new API, clarify the use case for a new API.
2. If you fix a bug, you can clarify why it is a bug.
-->
Currently, Hive has an authorization inconsistency:
1. Users authenticating via LDAP are subject to LDAP group filters
2. Users authenticating via Kerberos bypass these filters entirely
This creates security and operational issues. This PR is created for fixing
these issues.
### Does this PR introduce _any_ user-facing change?
<!--
Note that it means *any* user-facing change including all aspects such as
the documentation fix.
If yes, please clarify the previous behavior and the change this PR proposes
- provide the console output, description, screenshot and/or a reproducable
example to show the behavior difference if possible.
If possible, please also clarify if this is a user-facing change compared to
the released Hive versions or within the unreleased branches such as master.
If no, write 'No'.
-->
Yes. This PR introduces a new optional configuration parameter.
Previous behavior: Kerberos-authenticated users bypass all LDAP group
filters.
New behavior: When
hive.server2.authentication.ldap.enableGroupCheckAfterKerberos=true:
1. Kerberos-authenticated users must pass configured LDAP filters
2. Requires valid LDAP bind credentials
3. Applies to both HiveServer2 and HMS
4. Does not affect proxy users
### How was this patch tested?
<!--
If tests were added, say they were added here. Please make sure to add some
test cases that check the changes thoroughly including negative and positive
cases if possible.
If it was tested in a way different from regular unit tests, please clarify
how you tested step by step, ideally copy and paste-able, so that other
reviewers can test and check, and descendants can verify in the future.
If tests were not added, please describe why they were not added and/or why
it was difficult to add.
-->
ut, regression tests, functional tests
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]
---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]