You are viewing a plain text version of this content. The canonical link for it is here.
Posted to dev@ambari.apache.org by "Yusaku Sako (JIRA)" <ji...@apache.org> on 2013/07/17 02:30:49 UTC
[jira] [Commented] (AMBARI-2663) Security wizard: oozie principal
should be mapped to oozie user name via hadoop.security.auth_to_local
property
[ https://issues.apache.org/jira/browse/AMBARI-2663?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=13710537#comment-13710537 ]
Yusaku Sako commented on AMBARI-2663:
-------------------------------------
For the auth_to_local rules, it looks like we are matching against sub-domain realms and not the actual kerberos realm. This may be too permissive.
> Security wizard: oozie principal should be mapped to oozie user name via hadoop.security.auth_to_local property
> ---------------------------------------------------------------------------------------------------------------
>
> Key: AMBARI-2663
> URL: https://issues.apache.org/jira/browse/AMBARI-2663
> Project: Ambari
> Issue Type: Bug
> Components: client
> Affects Versions: 1.2.5
> Reporter: Jaimin D Jetly
> Assignee: Jaimin D Jetly
> Labels: security
> Fix For: 1.2.5
>
> Attachments: AMBARI-2663.patch
>
>
--
This message is automatically generated by JIRA.
If you think it was sent incorrectly, please contact your JIRA administrators
For more information on JIRA, see: http://www.atlassian.com/software/jira