Daryn Sharp created HADOOP-14146: ------------------------------------ Summary: KerberosAuthenticationHandler should authenticate with SPN in AP-REQ Key: HADOOP-14146 URL: https://issues.apache.org/jira/browse/HADOOP-14146 Project: Hadoop Common Issue Type: Bug Components: security Affects Versions: 2.5.0 Reporter: Daryn Sharp Assignee: Daryn Sharp
Many attempts (HADOOP-10158, HADOOP-11628, HADOOP-13565) have tried to add multiple SPN host and/or realm support to spnego authentication. The basic problem is the server tries to guess and/or brute force what SPN the client used. The server should just decode the SPN from the AP-REQ. -- This message was sent by Atlassian JIRA (v6.3.15#6346) --------------------------------------------------------------------- To unsubscribe, e-mail: common-dev-unsubscr...@hadoop.apache.org For additional commands, e-mail: common-dev-h...@hadoop.apache.org