[
https://issues.apache.org/jira/browse/HDFS-13532?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=16565634#comment-16565634
]
CR Hota commented on HDFS-13532:
--------------------------------
Thanks [~ajayydv] for going through the doc.
The main discussion (around cons for Approach 1) was around avoiding calls to
KDC. Router does maintain a pool of connections, but that pool/connection gets
recycled every x interval and new connections are created if needed again. The
lesser this architecture overall relies on KDC, the better router can perform
as a pure proxy with lower latencies. With end to end delegation token route,
router remains more aligned as a proxy rather than a gateway.
> RBF: Adding security
> --------------------
>
> Key: HDFS-13532
> URL: https://issues.apache.org/jira/browse/HDFS-13532
> Project: Hadoop HDFS
> Issue Type: New Feature
> Reporter: Íñigo Goiri
> Assignee: Sherwood Zheng
> Priority: Major
> Attachments: RBF _ Security delegation token thoughts.pdf,
> Security_for_Router-based Federation_design_doc.pdf
>
>
> HDFS Router based federation should support security. This includes
> authentication and delegation tokens.
--
This message was sent by Atlassian JIRA
(v7.6.3#76005)
---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]