mintao has uploaded this change for review. ( 
http://gerrit.cloudera.org:8080/24834


Change subject: [thrift] Initialize OpenSSL before creating TLS client sockets
......................................................................

[thrift] Initialize OpenSSL before creating TLS client sockets

CreateClientProtocol() sets the manual OpenSSL initialization mode for
all Thrift's TSSLSocketFactory instances on the premise that Kudu has
already initialized the OpenSSL library. However, the HMS client can
be the first user of the library in a process, and with OpenSSL
versions before 1.1.0 SSL_CTX_new() fails with 'library has no
ciphers' unless SSL_library_init() has been called at least once.

Call security::InitializeOpenSSL() before creating the TLS socket so
that the TLS client helper doesn't depend on some other part of Kudu
having touched the library first. This fixes creating an HMS client
over TLS in a process that hasn't initialized OpenSSL yet (e.g., the
hms_catalog-test/hms_client-test binaries on CentOS 7 with OpenSSL
1.0.2).

Change-Id: I4e71884dde5a252278a2cc67f8c66d76c2e462f5
---
M src/kudu/thrift/client.cc
1 file changed, 9 insertions(+), 0 deletions(-)



  git pull ssh://gerrit.cloudera.org:29418/kudu refs/changes/34/24834/1
--
To view, visit http://gerrit.cloudera.org:8080/24834
To unsubscribe, visit http://gerrit.cloudera.org:8080/settings

Gerrit-Project: kudu
Gerrit-Branch: master
Gerrit-MessageType: newchange
Gerrit-Change-Id: I4e71884dde5a252278a2cc67f8c66d76c2e462f5
Gerrit-Change-Number: 24834
Gerrit-PatchSet: 1
Gerrit-Owner: mintao <[email protected]>

Reply via email to