You are viewing a plain text version of this content. The canonical link for it is here.
Posted to common-issues@hadoop.apache.org by "Daryn Sharp (JIRA)" <ji...@apache.org> on 2013/12/17 20:26:07 UTC
[jira] [Commented] (HADOOP-10173) Remove UGI from DIGEST-MD5 SASL
server creation
[ https://issues.apache.org/jira/browse/HADOOP-10173?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=13850808#comment-13850808 ]
Daryn Sharp commented on HADOOP-10173:
--------------------------------------
This jira will accelerate token auth, but not kerberos auth. HADOOP-10174 should eventually supersede this jira and accelerate both.
> Remove UGI from DIGEST-MD5 SASL server creation
> -----------------------------------------------
>
> Key: HADOOP-10173
> URL: https://issues.apache.org/jira/browse/HADOOP-10173
> Project: Hadoop Common
> Issue Type: Improvement
> Components: ipc
> Affects Versions: 0.23.0, 3.0.0, 2.4.0
> Reporter: Daryn Sharp
> Assignee: Daryn Sharp
> Priority: Critical
>
> Instantiation of SASL server instances within the readers threads is performed within a {{UGI.getCurrentUser().doAs}}. {{getCurrentUser}} is synchronized, and doAs also degrades performance. GSSAPI (kerberos) requires instantiation within a doAs, but DIGEST-MD5 (token) does not.
--
This message was sent by Atlassian JIRA
(v6.1.4#6159)