Alexey Serbin has posted comments on this change. ( 
http://gerrit.cloudera.org:8080/12474 )

Change subject: KUDU-1900: add loopback check and test
......................................................................


Patch Set 5:

(1 comment)

http://gerrit.cloudera.org:8080/#/c/12474/5/src/kudu/integration-tests/security-itest.cc
File src/kudu/integration-tests/security-itest.cc:

http://gerrit.cloudera.org:8080/#/c/12474/5/src/kudu/integration-tests/security-itest.cc@406
PS5, Line 406: true
> What is the combination of rpc_encrypt_loopback_connections, rpc_authentica
The idea behind passing or not passing authn token over the connection is 
simple: if the issuer (or just the holder) of the token knows that the 
connection is confidential, the token can be passed over the connection.  
Otherwise, the holder of the token should not pass the token over the 
connection.

The 'confidential' means that there is no risk of capturing the token by 
sniffers over the wire.  And we should assume that all loopback connections are 
confidential, I think.

I suggest to leave this as is now, and maybe address in a separate patch.



--
To view, visit http://gerrit.cloudera.org:8080/12474
To unsubscribe, visit http://gerrit.cloudera.org:8080/settings

Gerrit-Project: kudu
Gerrit-Branch: master
Gerrit-MessageType: comment
Gerrit-Change-Id: I3483a9729ddeeb7901e3738532a45b49e713208f
Gerrit-Change-Number: 12474
Gerrit-PatchSet: 5
Gerrit-Owner: Greg Solovyev <[email protected]>
Gerrit-Reviewer: Adar Dembo <[email protected]>
Gerrit-Reviewer: Alexey Serbin <[email protected]>
Gerrit-Reviewer: Greg Solovyev <[email protected]>
Gerrit-Reviewer: Kudu Jenkins (120)
Gerrit-Comment-Date: Thu, 14 Feb 2019 20:49:26 +0000
Gerrit-HasComments: Yes

Reply via email to