You are viewing a plain text version of this content. The canonical link for it is here.
Posted to dev@ambari.apache.org by "Eron Wright (JIRA)" <ji...@apache.org> on 2015/03/12 03:44:38 UTC
[jira] [Created] (AMBARI-10037) Support creation of a secure
cluster (w/ blueprints)
Eron Wright created AMBARI-10037:
-------------------------------------
Summary: Support creation of a secure cluster (w/ blueprints)
Key: AMBARI-10037
URL: https://issues.apache.org/jira/browse/AMBARI-10037
Project: Ambari
Issue Type: Improvement
Components: ambari-server
Reporter: Eron Wright
While it is possible to enable Kerberos on an existing cluster, it should be possible to create a new cluster with Kerberos enabled in a single step. Ideally the blueprint API could be used in that case.
Note that any service added to an already-secured cluster is immediately secured. Therefore, a possible workaround is to create a cluster with no services, secure it, then add services. But this workaround is incompatible with blueprints.
Among the benefits:
# reduced time spent in an insecure configuration; close a potential vulnerability.
# more convenient; no additional step to perform.
# faster; fewer restarts.
# improved interoperability with HCFS.
--
This message was sent by Atlassian JIRA
(v6.3.4#6332)