[
https://issues.apache.org/jira/browse/TEZ-4749?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
]
László Bodor reassigned TEZ-4749:
---------------------------------
Assignee: Gergely Farkas
> Support SSL/TLS connections to ZooKeeper in ZkAMRegistry and
> ZkAMRegistryClient
> --------------------------------------------------------------------------------
>
> Key: TEZ-4749
> URL: https://issues.apache.org/jira/browse/TEZ-4749
> Project: Apache Tez
> Issue Type: Improvement
> Reporter: Gergely Farkas
> Assignee: Gergely Farkas
> Priority: Major
> Time Spent: 10m
> Remaining Estimate: 0h
>
> Currently, ZkAMRegistry and ZkAMRegistryClient can only connect to ZooKeeper
> over SSL/TLS by setting JVM-wide system properties (zookeeper.client.secure,
> zookeeper.clientCnxnSocket). This is inflexible in environments where
> multiple ZK connections with different security requirements coexist in the
> same JVM.
> This Jira tracks adding explicit SSL/TLS configuration support for Tez's
> ZooKeeper connections:
> * New configuration properties:
> ** tez.am.zookeeper.ssl.enable - explicitly enable/disable SSL for the ZK
> connection
> ** tez.am.zookeeper.ssl.keystore.location / password
> ** tez.am.zookeeper.ssl.truststore.location / password
> * New SSLZookeeperFactory that configures a Netty-based secure ZK client
> connection when SSL is enabled in ZkConfig.
> * When tez.am.zookeeper.ssl.enable is set to "true", the CuratorFramework is
> built with SSLZookeeperFactory. When set to "false", JVM-level secure client
> properties are explicitly overridden to force an insecure connection. When
> unset, the existing behavior (JVM defaults) is preserved.
--
This message was sent by Atlassian Jira
(v8.20.10#820010)