[ https://issues.apache.org/jira/browse/HDFS-6667?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ]
Jing Zhao moved HADOOP-10519 to HDFS-6667: ------------------------------------------ Component/s: (was: security) security Key: HDFS-6667 (was: HADOOP-10519) Project: Hadoop HDFS (was: Hadoop Common) > In HDFS HA mode, Distcp/SLive with webhdfs on secure cluster fails with > Client cannot authenticate via:[TOKEN, KERBEROS] error > ------------------------------------------------------------------------------------------------------------------------------ > > Key: HDFS-6667 > URL: https://issues.apache.org/jira/browse/HDFS-6667 > Project: Hadoop HDFS > Issue Type: Bug > Components: security > Reporter: Jian He > > Opening on [~arpitgupta]'s behalf. > We observed that, in HDFS HA mode, running Distcp/SLive with webhdfs will > fail on YARN. In non-HA mode, it'll pass. > The reason is in HA mode, only webhdfs delegation token is generated for the > job, but YARN also requires the regular hdfs token to do localization, > log-aggregation etc. > In non-HA mode, both tokens are generated for the job. -- This message was sent by Atlassian JIRA (v6.2#6252)