You are viewing a plain text version of this content. The canonical link for it is here.
Posted to dev@lucene.apache.org by "Gregory Chanan (JIRA)" <ji...@apache.org> on 2016/07/20 17:24:20 UTC

[jira] [Created] (SOLR-9324) Support Secure Impersonation / Proxy User for solr authentication

Gregory Chanan created SOLR-9324:
------------------------------------

             Summary: Support Secure Impersonation / Proxy User for solr authentication
                 Key: SOLR-9324
                 URL: https://issues.apache.org/jira/browse/SOLR-9324
             Project: Solr
          Issue Type: Improvement
      Security Level: Public (Default Security Level. Issues are Public)
          Components: SolrCloud
            Reporter: Gregory Chanan


Solr should support Proxy User / Secure Impersonation for authentication, as supported by hadoop (http://hadoop.apache.org/docs/current/hadoop-project-dist/hadoop-common/Superusers.html) and supported by the hadoop AuthenticationFilter (which we use for the KerberosPlugin).

There are a number of use cases, but a common one is this:
There is a front end for searches (say, Hue http://gethue.com/) that supports its own login mechanisms.  If the cluster uses kerberos for authentication, hue must have kerberos credentials for each user, which is a pain to manage.  Instead, hue can be allowed to impersonate known users from known machines so it only needs its own kerberos credentials.



--
This message was sent by Atlassian JIRA
(v6.3.4#6332)

---------------------------------------------------------------------
To unsubscribe, e-mail: dev-unsubscribe@lucene.apache.org
For additional commands, e-mail: dev-help@lucene.apache.org