[ 
https://issues.apache.org/jira/browse/TEZ-4749?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
 ]

László Bodor reassigned TEZ-4749:
---------------------------------

    Assignee: Gergely Farkas

> Support SSL/TLS connections to ZooKeeper in ZkAMRegistry and 
> ZkAMRegistryClient 
> --------------------------------------------------------------------------------
>
>                 Key: TEZ-4749
>                 URL: https://issues.apache.org/jira/browse/TEZ-4749
>             Project: Apache Tez
>          Issue Type: Improvement
>            Reporter: Gergely Farkas
>            Assignee: Gergely Farkas
>            Priority: Major
>          Time Spent: 10m
>  Remaining Estimate: 0h
>
> Currently, ZkAMRegistry and ZkAMRegistryClient can only connect to ZooKeeper 
> over SSL/TLS by setting JVM-wide system properties (zookeeper.client.secure, 
> zookeeper.clientCnxnSocket). This is inflexible in environments where 
> multiple ZK connections with different security requirements coexist in the 
> same JVM.
> This Jira tracks adding explicit SSL/TLS configuration support for Tez's 
> ZooKeeper connections:
>  * New configuration properties:
>  ** tez.am.zookeeper.ssl.enable - explicitly enable/disable SSL for the ZK 
> connection
>  ** tez.am.zookeeper.ssl.keystore.location / password
>  ** tez.am.zookeeper.ssl.truststore.location / password
>  * New SSLZookeeperFactory that configures a Netty-based secure ZK client 
> connection when SSL is enabled in ZkConfig.
>  * When tez.am.zookeeper.ssl.enable is set to "true", the CuratorFramework is 
> built with SSLZookeeperFactory. When set to "false", JVM-level secure client 
> properties are explicitly overridden to force an insecure connection. When 
> unset, the existing behavior (JVM defaults) is preserved.



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to