[
https://issues.apache.org/jira/browse/HIVE-20583?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=16618132#comment-16618132
]
Gopal V commented on HIVE-20583:
--------------------------------
Yes, this is only needed for SPNEGO.
This is okay for an intranet/vpn, but relying on reverse DNS will break
somewhat when used on the internet (+ a NAT).
> Use canonical hostname only for kerberos auth in HiveConnection
> ---------------------------------------------------------------
>
> Key: HIVE-20583
> URL: https://issues.apache.org/jira/browse/HIVE-20583
> Project: Hive
> Issue Type: Bug
> Affects Versions: 4.0.0, 3.2.0
> Reporter: Prasanth Jayachandran
> Assignee: Prasanth Jayachandran
> Priority: Major
> Attachments: HIVE-20583.1.patch
>
>
> HiveConnection uses canonical hostnames which is a requirement only for
> kerberos clusters (specifically on clusters that has reverse DNS resolution
> disabled). Use canonical hostnames only when kerberos auth is enabled.
> [~gopalv] provided this reference
> [http://web.mit.edu/kerberos/krb5-devel/doc/admin/princ_dns.html#service-principal-canonicalization]
>
--
This message was sent by Atlassian JIRA
(v7.6.3#76005)