You are viewing a plain text version of this content. The canonical link for it is here.
Posted to dev@bookkeeper.apache.org by Enrico Olivelli - Diennea <en...@diennea.com> on 2016/06/22 12:11:44 UTC

BookieAuthProvider.Factory, SASL ?

Hi,
Do you know any production ready implementation of BookieAuthProvider.Factory ?

Recently I'm working with SASL, maybe we can provide some out-of-the-box implementations for simple SASL mechs.
JDK builtin support of SASL provides username/password auth and GSSAPI

What do you think ?




--
Enrico Olivelli
Software Development Manager @Diennea
Tel.: (+39) 0546 066100 - Int. 925
Viale G.Marconi 30/14 - 48018 Faenza (RA)

MagNews - E-mail Marketing Solutions
http://www.magnews.it
Diennea - Digital Marketing Solutions
http://www.diennea.com


________________________________

Iscriviti alla nostra newsletter per rimanere aggiornato su digital ed email marketing! http://www.magnews.it/newsletter/

The information in this email is confidential and may be legally privileged. If you are not the intended recipient please notify the sender immediately and destroy this email. Any unauthorized, direct or indirect, disclosure, copying, storage, distribution or other use is strictly forbidden.

________________________________

[http://www.magnews.it/wp-content/uploads/2016/06/img.jpg] <http://www.magnews.it/2016/02/22/global-summit-marketing-digital-2016/?utm_source=footer-email&utm_medium=email&utm_campaign=global-summit>


Re: BookieAuthProvider.Factory, SASL ?

Posted by Sijie Guo <si...@apache.org>.
Sounds good to me.

- Sijie

On Wed, Jun 22, 2016 at 10:56 PM, Enrico Olivelli <eo...@gmail.com>
wrote:

> Thanks Sijie.
> I think that security will be one next big features after 4.5.0.
> Most important issues are:
> - provide some out of the box auth providers, like IP whitelist/blacklist,
> maybe sale SASL
> - zookeeper auth
> - ssl
>
> I think that most of these issues are already tracked in JIRA. I will check
> and create the standard auth providers issues.
>
> For me actually I need the embedded bookie stuff and the improvements on
> data placements. Then I will be happy to work on the security side.
>
> - Enrico
>
> Il Mer 22 Giu 2016 23:45 Sijie Guo <si...@apache.org> ha scritto:
>
> > Hello Enrico:
> >
> > The BookieAuthProvider was introduced in last release by Yahoo. I think
> > Yahoo has its internal auth mechanism. Matteo can chime in here.
> >
> > I think there was a ticket to track the security support for bookkeeper.
> If
> > you are interested in contributing to this part, it would be great.
> >
> > - Sijie
> >
> > On Wed, Jun 22, 2016 at 5:11 AM, Enrico Olivelli - Diennea <
> > enrico.olivelli@diennea.com> wrote:
> >
> > > Hi,
> > > Do you know any production ready implementation of
> > > BookieAuthProvider.Factory ?
> > >
> > > Recently I'm working with SASL, maybe we can provide some
> out-of-the-box
> > > implementations for simple SASL mechs.
> > > JDK builtin support of SASL provides username/password auth and GSSAPI
> > >
> > > What do you think ?
> > >
> > >
> > >
> > >
> > > --
> > > Enrico Olivelli
> > > Software Development Manager @Diennea
> > > Tel.: (+39) 0546 066100 - Int. 925
> > > Viale G.Marconi 30/14 - 48018 Faenza (RA)
> > >
> > > MagNews - E-mail Marketing Solutions
> > > http://www.magnews.it
> > > Diennea - Digital Marketing Solutions
> > > http://www.diennea.com
> > >
> > >
> > > ________________________________
> > >
> > > Iscriviti alla nostra newsletter per rimanere aggiornato su digital ed
> > > email marketing! http://www.magnews.it/newsletter/
> > >
> > > The information in this email is confidential and may be legally
> > > privileged. If you are not the intended recipient please notify the
> > sender
> > > immediately and destroy this email. Any unauthorized, direct or
> indirect,
> > > disclosure, copying, storage, distribution or other use is strictly
> > > forbidden.
> > >
> > > ________________________________
> > >
> > > [http://www.magnews.it/wp-content/uploads/2016/06/img.jpg] <
> > >
> >
> http://www.magnews.it/2016/02/22/global-summit-marketing-digital-2016/?utm_source=footer-email&utm_medium=email&utm_campaign=global-summit
> > > >
> > >
> > >
> >
> --
>
>
> -- Enrico Olivelli
>

Re: BookieAuthProvider.Factory, SASL ?

Posted by Enrico Olivelli <eo...@gmail.com>.
Thanks Sijie.
I think that security will be one next big features after 4.5.0.
Most important issues are:
- provide some out of the box auth providers, like IP whitelist/blacklist,
maybe sale SASL
- zookeeper auth
- ssl

I think that most of these issues are already tracked in JIRA. I will check
and create the standard auth providers issues.

For me actually I need the embedded bookie stuff and the improvements on
data placements. Then I will be happy to work on the security side.

- Enrico

Il Mer 22 Giu 2016 23:45 Sijie Guo <si...@apache.org> ha scritto:

> Hello Enrico:
>
> The BookieAuthProvider was introduced in last release by Yahoo. I think
> Yahoo has its internal auth mechanism. Matteo can chime in here.
>
> I think there was a ticket to track the security support for bookkeeper. If
> you are interested in contributing to this part, it would be great.
>
> - Sijie
>
> On Wed, Jun 22, 2016 at 5:11 AM, Enrico Olivelli - Diennea <
> enrico.olivelli@diennea.com> wrote:
>
> > Hi,
> > Do you know any production ready implementation of
> > BookieAuthProvider.Factory ?
> >
> > Recently I'm working with SASL, maybe we can provide some out-of-the-box
> > implementations for simple SASL mechs.
> > JDK builtin support of SASL provides username/password auth and GSSAPI
> >
> > What do you think ?
> >
> >
> >
> >
> > --
> > Enrico Olivelli
> > Software Development Manager @Diennea
> > Tel.: (+39) 0546 066100 - Int. 925
> > Viale G.Marconi 30/14 - 48018 Faenza (RA)
> >
> > MagNews - E-mail Marketing Solutions
> > http://www.magnews.it
> > Diennea - Digital Marketing Solutions
> > http://www.diennea.com
> >
> >
> > ________________________________
> >
> > Iscriviti alla nostra newsletter per rimanere aggiornato su digital ed
> > email marketing! http://www.magnews.it/newsletter/
> >
> > The information in this email is confidential and may be legally
> > privileged. If you are not the intended recipient please notify the
> sender
> > immediately and destroy this email. Any unauthorized, direct or indirect,
> > disclosure, copying, storage, distribution or other use is strictly
> > forbidden.
> >
> > ________________________________
> >
> > [http://www.magnews.it/wp-content/uploads/2016/06/img.jpg] <
> >
> http://www.magnews.it/2016/02/22/global-summit-marketing-digital-2016/?utm_source=footer-email&utm_medium=email&utm_campaign=global-summit
> > >
> >
> >
>
-- 


-- Enrico Olivelli

Re: BookieAuthProvider.Factory, SASL ?

Posted by Sijie Guo <si...@apache.org>.
Hello Enrico:

The BookieAuthProvider was introduced in last release by Yahoo. I think
Yahoo has its internal auth mechanism. Matteo can chime in here.

I think there was a ticket to track the security support for bookkeeper. If
you are interested in contributing to this part, it would be great.

- Sijie

On Wed, Jun 22, 2016 at 5:11 AM, Enrico Olivelli - Diennea <
enrico.olivelli@diennea.com> wrote:

> Hi,
> Do you know any production ready implementation of
> BookieAuthProvider.Factory ?
>
> Recently I'm working with SASL, maybe we can provide some out-of-the-box
> implementations for simple SASL mechs.
> JDK builtin support of SASL provides username/password auth and GSSAPI
>
> What do you think ?
>
>
>
>
> --
> Enrico Olivelli
> Software Development Manager @Diennea
> Tel.: (+39) 0546 066100 - Int. 925
> Viale G.Marconi 30/14 - 48018 Faenza (RA)
>
> MagNews - E-mail Marketing Solutions
> http://www.magnews.it
> Diennea - Digital Marketing Solutions
> http://www.diennea.com
>
>
> ________________________________
>
> Iscriviti alla nostra newsletter per rimanere aggiornato su digital ed
> email marketing! http://www.magnews.it/newsletter/
>
> The information in this email is confidential and may be legally
> privileged. If you are not the intended recipient please notify the sender
> immediately and destroy this email. Any unauthorized, direct or indirect,
> disclosure, copying, storage, distribution or other use is strictly
> forbidden.
>
> ________________________________
>
> [http://www.magnews.it/wp-content/uploads/2016/06/img.jpg] <
> http://www.magnews.it/2016/02/22/global-summit-marketing-digital-2016/?utm_source=footer-email&utm_medium=email&utm_campaign=global-summit
> >
>
>