You are viewing a plain text version of this content. The canonical link for it is here.
Posted to dev@zeppelin.apache.org by "Jeff Zhang (JIRA)" <ji...@apache.org> on 2016/08/17 00:44:21 UTC

[jira] [Created] (ZEPPELIN-1340) Impersonation for interpreter

Jeff Zhang created ZEPPELIN-1340:
------------------------------------

             Summary: Impersonation for interpreter
                 Key: ZEPPELIN-1340
                 URL: https://issues.apache.org/jira/browse/ZEPPELIN-1340
             Project: Zeppelin
          Issue Type: Sub-task
            Reporter: Jeff Zhang


In the kerberized environment, all the interpreter use the same keytab/principal, this is pretty dangerous. E.g. User A can use shell interpreter which run as user B to delete all the files owned by user B. 

Although some interpreter has implement its kerbosed usage, I just feel we might need to make a general impersonation framework for all the interpreter (If not possible for all interpreter, but at least this framework should cover most of the interpreter). 



--
This message was sent by Atlassian JIRA
(v6.3.4#6332)