[jira] [Commented] (HADOOP-15896) Refine Kerberos based AuthenticationHandler to check proxyuser ACL

2018-11-02 Thread Eric Yang (JIRA)
[ https://issues.apache.org/jira/browse/HADOOP-15896?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=16673673#comment-16673673 ] Eric Yang commented on HADOOP-15896: [~daryn] It would be naive to think that every host with a

[jira] [Commented] (HADOOP-15896) Refine Kerberos based AuthenticationHandler to check proxyuser ACL

2018-11-02 Thread Daryn Sharp (JIRA)
[ https://issues.apache.org/jira/browse/HADOOP-15896?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=16673610#comment-16673610 ] Daryn Sharp commented on HADOOP-15896: -- You seriously need to google "kerberos replay attack". >

[jira] [Commented] (HADOOP-15896) Refine Kerberos based AuthenticationHandler to check proxyuser ACL

2018-11-02 Thread Eric Yang (JIRA)
[ https://issues.apache.org/jira/browse/HADOOP-15896?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=16673605#comment-16673605 ] Eric Yang commented on HADOOP-15896: {quote}The only nugget of truth in the description is the host

[jira] [Commented] (HADOOP-15896) Refine Kerberos based AuthenticationHandler to check proxyuser ACL

2018-11-02 Thread Daryn Sharp (JIRA)
[ https://issues.apache.org/jira/browse/HADOOP-15896?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=16673580#comment-16673580 ] Daryn Sharp commented on HADOOP-15896: -- Let's unpack the description: Other than guilt through

[jira] [Commented] (HADOOP-15896) Refine Kerberos based AuthenticationHandler to check proxyuser ACL

2018-11-02 Thread Larry McCay (JIRA)
[ https://issues.apache.org/jira/browse/HADOOP-15896?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=16673559#comment-16673559 ] Larry McCay commented on HADOOP-15896: -- JWTRedirectAuthenticationHandler is not specific to proxy