[ 
https://issues.apache.org/jira/browse/HIVE-14984?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=15592115#comment-15592115
 ] 

Aihua Xu commented on HIVE-14984:
---------------------------------

+1.


> Hive-WebUI access results in Request is a replay (34) attack
> ------------------------------------------------------------
>
>                 Key: HIVE-14984
>                 URL: https://issues.apache.org/jira/browse/HIVE-14984
>             Project: Hive
>          Issue Type: Bug
>          Components: HiveServer2
>    Affects Versions: 1.2.0
>            Reporter: Venkat Sambath
>            Assignee: Barna Zsombor Klara
>         Attachments: HIVE-14984.patch
>
>
> When trying to access kerberized webui of HS2, The following error is received
> GSSException: Failure unspecified at GSS-API level (Mechanism level: Request 
> is a replay (34))
> While this is not happening for RM webui (checked if kerberos webui is 
> enabled)
> To reproduce the issue 
> Try running
> curl --negotiate -u : -b ~/cookiejar.txt -c ~/cookiejar.txt 
> http://<hostname>:10002/
> from any cluster nodes
> or 
> Try accessing the URL from a VM with windows machine and firefox browser to 
> replicate the issue
> The following workaround helped, but need a permanent solution for the bug
> Workaround:
> =========
> First access the index.html directly and then actual URL of webui
> curl --negotiate -u : -b ~/cookiejar.txt -c ~/cookiejar.txt 
> http://<hostname>:10002/index.html
> curl --negotiate -u : -b ~/cookiejar.txt -c ~/cookiejar.txt 
> http://<hostname>:10002
> In browser:
> First access
> http://<hostname>:10002/index.html
> then
> http://<hostname>:10002



--
This message was sent by Atlassian JIRA
(v6.3.4#6332)

Reply via email to