hadoop-common-issues mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From "Alejandro Abdelnur (JIRA)" <j...@apache.org>
Subject [jira] [Commented] (HADOOP-10769) Add getDelegationToken() method to KeyProvider
Date Tue, 01 Jul 2014 21:36:24 GMT

    [ https://issues.apache.org/jira/browse/HADOOP-10769?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=14049352#comment-14049352
] 

Alejandro Abdelnur commented on HADOOP-10769:
---------------------------------------------

[~lmccay], if the {{KeyProvider}} is not accessible from services/tasks in the cluster it
is pretty much useless. And DelegationTokens enable secure access to it from processes without
Kerberos credentials. A local KeyProvider (such as JavaKeyStore or User) only serve special
and restricted usecases where distributed access is not required. Given that, I believe getting
delegation tokens belongs the basic {{KeyProvider}} API.

> Add getDelegationToken() method to KeyProvider
> ----------------------------------------------
>
>                 Key: HADOOP-10769
>                 URL: https://issues.apache.org/jira/browse/HADOOP-10769
>             Project: Hadoop Common
>          Issue Type: Improvement
>          Components: security
>    Affects Versions: 3.0.0
>            Reporter: Alejandro Abdelnur
>            Assignee: Arun Suresh
>
> The KeyProvider API needs to return delegation tokens to enable access to the KeyProvider
from processes without Kerberos credentials (ie Yarn containers).
> This is required for HDFS encryption and KMS integration.



--
This message was sent by Atlassian JIRA
(v6.2#6252)

Mime
View raw message