[ 
https://issues.apache.org/jira/browse/HDFS-13532?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=16565634#comment-16565634
 ] 

CR Hota commented on HDFS-13532:
--------------------------------

Thanks [~ajayydv] for going through the doc.
The main discussion (around cons for Approach 1) was around avoiding calls to 
KDC. Router does maintain a pool of connections, but that pool/connection gets 
recycled every x interval and new connections are created if needed again. The 
lesser this architecture overall relies on KDC, the better router can perform 
as a pure proxy with lower latencies. With end to end delegation token route, 
router remains more aligned as a proxy rather than a gateway.

> RBF: Adding security
> --------------------
>
>                 Key: HDFS-13532
>                 URL: https://issues.apache.org/jira/browse/HDFS-13532
>             Project: Hadoop HDFS
>          Issue Type: New Feature
>            Reporter: Íñigo Goiri
>            Assignee: Sherwood Zheng
>            Priority: Major
>         Attachments: RBF _ Security delegation token thoughts.pdf, 
> Security_for_Router-based Federation_design_doc.pdf
>
>
> HDFS Router based federation should support security. This includes 
> authentication and delegation tokens.



--
This message was sent by Atlassian JIRA
(v7.6.3#76005)

---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to