hive-issues mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From "David McGinnis (JIRA)" <j...@apache.org>
Subject [jira] [Updated] (HIVE-14888) SparkClientImpl checks for "kerberos" string in hiveconf only when determining whether to use keytab file.
Date Sat, 01 Jun 2019 04:23:13 GMT

     [ https://issues.apache.org/jira/browse/HIVE-14888?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
]

David McGinnis updated HIVE-14888:
----------------------------------
    Description: 
The SparkClientImpl will only provide a principal and keytab argument if the HADOOP_SECURITY_AUTHENTICATION
in hive conf is set to "kerberos". This will not work on clusters with Hadoop security enabled
that are not configured as "kerberos", for example, a cluster which is configured for "ldap".

The solution is to call UserGroupInformation.isSecurityEnabled() instead.

 

Code Review: [https://reviews.apache.org/r/70718/]

  was:
The SparkClientImpl will only provide a principal and keytab argument if the HADOOP_SECURITY_AUTHENTICATION
in hive conf is set to "kerberos". This will not work on clusters with Hadoop security enabled
that are not configured as "kerberos", for example, a cluster which is configured for "ldap".

The solution is to call UserGroupInformation.isSecurityEnabled() instead.

    Component/s: Spark

> SparkClientImpl checks for "kerberos" string in hiveconf only when determining whether
to use keytab file.
> ----------------------------------------------------------------------------------------------------------
>
>                 Key: HIVE-14888
>                 URL: https://issues.apache.org/jira/browse/HIVE-14888
>             Project: Hive
>          Issue Type: Bug
>          Components: Spark
>    Affects Versions: 2.1.0
>            Reporter: Thomas Rega
>            Assignee: David McGinnis
>            Priority: Major
>              Labels: pull-request-available
>             Fix For: 4.0.0
>
>         Attachments: HIVE-14888.1-spark.patch, HIVE-14888.2.patch, HIVE-14888.3.patch,
HIVE-14888.4.patch, HIVE-14888.5.patch
>
>   Original Estimate: 5m
>          Time Spent: 10m
>  Remaining Estimate: 0h
>
> The SparkClientImpl will only provide a principal and keytab argument if the HADOOP_SECURITY_AUTHENTICATION
in hive conf is set to "kerberos". This will not work on clusters with Hadoop security enabled
that are not configured as "kerberos", for example, a cluster which is configured for "ldap".
> The solution is to call UserGroupInformation.isSecurityEnabled() instead.
>  
> Code Review: [https://reviews.apache.org/r/70718/]



--
This message was sent by Atlassian JIRA
(v7.6.3#76005)

Mime
View raw message