[
https://issues.apache.org/jira/browse/HDFS-14390?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=16803330#comment-16803330
]
Ashvin commented on HDFS-14390:
-------------------------------
Thanks [~virajith] [~elgoiri] for reviewing the patch.
[~virajith], the {{KerberosInfo/clientPrincipal}} is used only if service level
authorization is enabled for the {{AliasMap}}. The {{clientPrincipal}} can be
removed when it is not configured and for the scope of this jira. Perhaps it
better to address service acl and authorization changes in a different patch?
[~elgoiri], reorganizing the test case and reusing security utils wherever
available makes sense. Will update the patch accordingly.
> Provide kerberos support for AliasMap service used by Provided storage
> ----------------------------------------------------------------------
>
> Key: HDFS-14390
> URL: https://issues.apache.org/jira/browse/HDFS-14390
> Project: Hadoop HDFS
> Issue Type: Improvement
> Reporter: Ashvin
> Assignee: Ashvin
> Priority: Major
> Attachments: HDFS-14390.001.patch
>
>
> With {{PROVIDED}} storage (-HDFS-9806)-, HDFS can address data stored in
> external storage systems. This feature is not supported in a secure HDFS
> cluster. The {{AliasMap}} service does not support kerberos, and as a result
> the cluster nodes will fail to communicate with it. This JIRA is to enable
> kerberos support for the {{AliasMap}} service.
--
This message was sent by Atlassian JIRA
(v7.6.3#76005)
---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]