You are viewing a plain text version of this content. The canonical link for it is here.
Posted to dev@ambari.apache.org by "Jayush Luniya (JIRA)" <ji...@apache.org> on 2015/03/18 02:26:38 UTC

[jira] [Commented] (AMBARI-8912) ADKerberosOperationHandler should strip realmname from principal name before creating principal

    [ https://issues.apache.org/jira/browse/AMBARI-8912?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=14366445#comment-14366445 ] 

Jayush Luniya commented on AMBARI-8912:
---------------------------------------

Dilli Arumugam
Is this issue still valid and is it required for 2.0.0 or can it be moved to 2.1.0?
cc: Robert Levas Erik Bergenholtz

> ADKerberosOperationHandler should strip realmname from principal name before creating principal
> -----------------------------------------------------------------------------------------------
>
>                 Key: AMBARI-8912
>                 URL: https://issues.apache.org/jira/browse/AMBARI-8912
>             Project: Ambari
>          Issue Type: Bug
>          Components: ambari-server
>    Affects Versions: 2.0.0
>            Reporter: Dilli Arumugam
>            Assignee: Dilli Arumugam
>             Fix For: 2.0.0
>
>         Attachments: AMBARI-8912.1.patch
>
>
> If principalName passed to ADKerberosOperationHandler contains realm suffix such as nn/c6401.ambari.apache.org@KNOX.COM, the suffix realm should be stripped before we create ldap entry in AD.  We already suffix the realm name in user principal name in ADKerberosOperationHandler. So, if we do not strip the realmname in incoming principalname we end up with realm name suffixed twice.



--
This message was sent by Atlassian JIRA
(v6.3.4#6332)