[ 
https://issues.apache.org/jira/browse/HDFS-14390?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=16803330#comment-16803330
 ] 

Ashvin commented on HDFS-14390:
-------------------------------

Thanks [~virajith] [~elgoiri] for reviewing the patch.

[~virajith], the {{KerberosInfo/clientPrincipal}} is used only if service level 
authorization is enabled for the {{AliasMap}}. The {{clientPrincipal}} can be 
removed when it is not configured and for the scope of this jira. Perhaps it 
better to address service acl and authorization changes in a different patch?

[~elgoiri], reorganizing the test case and reusing security utils wherever 
available makes sense. Will update the patch accordingly.

 

> Provide kerberos support for AliasMap service used by Provided storage
> ----------------------------------------------------------------------
>
>                 Key: HDFS-14390
>                 URL: https://issues.apache.org/jira/browse/HDFS-14390
>             Project: Hadoop HDFS
>          Issue Type: Improvement
>            Reporter: Ashvin
>            Assignee: Ashvin
>            Priority: Major
>         Attachments: HDFS-14390.001.patch
>
>
> With {{PROVIDED}} storage (-HDFS-9806)-, HDFS can address data stored in 
> external storage systems. This feature is not supported in a secure HDFS 
> cluster. The {{AliasMap}} service does not support kerberos, and as a result 
> the cluster nodes will fail to communicate with it. This JIRA is to enable 
> kerberos support for the {{AliasMap}} service.



--
This message was sent by Atlassian JIRA
(v7.6.3#76005)

---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to