[ https://issues.apache.org/jira/browse/KNOX-2223?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ]
Kevin Risden updated KNOX-2223: ------------------------------- Affects Version/s: 1.1.0 1.2.0 1.3.0 > HS2 cookie not stored in HadoopAuthCookieStore > ---------------------------------------------- > > Key: KNOX-2223 > URL: https://issues.apache.org/jira/browse/KNOX-2223 > Project: Apache Knox > Issue Type: Bug > Affects Versions: 1.1.0, 1.2.0, 1.3.0 > Reporter: Kevin Risden > Assignee: Kevin Risden > Priority: Major > Fix For: 1.4.0 > > Time Spent: 20m > Remaining Estimate: 0h > > HadoopAuthCookieStore checks to see if the cookie corresponds to Knox after > KNOX-1341 and further improved in KNOX-2026. > The HS2 cookie format doesn't match what Knox expects though. Knox expects > the cookie to have the entire principal (knox/hostn...@realm.com). HS2 > generates the authentication cookie based on the short name just "knox". > https://github.com/apache/hive/blob/master/service/src/java/org/apache/hive/service/auth/HttpAuthUtils.java#L83 > This causes a mismatch and Knox never stores the HS2 cookie. This results in > repeated Knox Kerberos auth to HS2 which is a performance penalty. -- This message was sent by Atlassian Jira (v8.3.4#803005)