You are viewing a plain text version of this content. The canonical link for it is here.
Posted to common-issues@hadoop.apache.org by "Mingjiang Shi (JIRA)" <ji...@apache.org> on 2013/09/15 15:39:55 UTC

[jira] [Commented] (HADOOP-9621) Document/analyze current Hadoop security model

    [ https://issues.apache.org/jira/browse/HADOOP-9621?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=13767797#comment-13767797 ] 

Mingjiang Shi commented on HADOOP-9621:
---------------------------------------

On page 1, in the middle
"This selection is based on the type of server to which the connection is being established and thetypeoftokenitrequires. (See Connector constructor in ..."

I think the Connector should be Connection according to the version 2.1.0 beta code base.
                
> Document/analyze current Hadoop security model
> ----------------------------------------------
>
>                 Key: HADOOP-9621
>                 URL: https://issues.apache.org/jira/browse/HADOOP-9621
>             Project: Hadoop Common
>          Issue Type: Task
>          Components: security
>            Reporter: Brian Swan
>            Priority: Minor
>              Labels: documentation
>         Attachments: HadoopSecurityAnalysis-20130612.pdf, HadoopSecurityAnalysis-20130614.pdf, HadoopSecurityAnalysis-20130624.pdf, ThreatsforToken-basedAuthN-20130619.pdf
>
>   Original Estimate: 336h
>  Remaining Estimate: 336h
>
> In light of the proposed changes to Hadoop security in Hadoop-9533 and Hadoop-9392, having a common, detailed understanding (in the form of a document) of the benefits/drawbacks of the current security model and how it works would be useful. The document should address all security principals, their authentication mechanisms, and handling of shared secrets through the lens of the following principles: Minimize attack surface area, Establish secure defaults, Principle of Least privilege, Principle of Defense in depth, Fail securely, Don’t trust services, Separation of duties, Avoid security by obscurity, Keep security simple, Fix security issues correctly.

--
This message is automatically generated by JIRA.
If you think it was sent incorrectly, please contact your JIRA administrators
For more information on JIRA, see: http://www.atlassian.com/software/jira