You are viewing a plain text version of this content. The canonical link for it is here.
Posted to issues@kudu.apache.org by "Todd Lipcon (JIRA)" <ji...@apache.org> on 2017/01/26 18:56:24 UTC

[jira] [Assigned] (KUDU-1845) Kerberos client keytab should be periodically renewed

     [ https://issues.apache.org/jira/browse/KUDU-1845?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ]

Todd Lipcon reassigned KUDU-1845:
---------------------------------

    Assignee: Sailesh Mukil

> Kerberos client keytab should be periodically renewed
> -----------------------------------------------------
>
>                 Key: KUDU-1845
>                 URL: https://issues.apache.org/jira/browse/KUDU-1845
>             Project: Kudu
>          Issue Type: Improvement
>          Components: security
>            Reporter: Todd Lipcon
>            Assignee: Sailesh Mukil
>            Priority: Critical
>
> Currently, security/init.cc initializes the Kerberos client keytab on startup, but never renews it. The credentials expire after some time so it's important to have some thread which renews it before expiration (hopefully in such a way that if a renewal transiently fails, we don't lose our previously good ticket)



--
This message was sent by Atlassian JIRA
(v6.3.4#6332)