Dan Burkert has posted comments on this change. ( http://gerrit.cloudera.org:8080/9374 )
Change subject: KUDU-2259: add real user to AuthenticationCredentialsPB ...................................................................... Patch Set 3: (8 comments) http://gerrit.cloudera.org:8080/#/c/9374/2/java/kudu-client/src/main/java/org/apache/kudu/client/SecurityContext.java File java/kudu-client/src/main/java/org/apache/kudu/client/SecurityContext.java: http://gerrit.cloudera.org:8080/#/c/9374/2/java/kudu-client/src/main/java/org/apache/kudu/client/SecurityContext.java@156 PS2, Line 156: getKerbero > Not sure I understand: the condition for this 'if' closure is 'pb.hasAuthnT I misunderstood, thanks for pointing that out. http://gerrit.cloudera.org:8080/#/c/9374/2/java/kudu-client/src/test/java/org/apache/kudu/client/TestSecurityContextRealUser.java File java/kudu-client/src/test/java/org/apache/kudu/client/TestSecurityContextRealUser.java: http://gerrit.cloudera.org:8080/#/c/9374/2/java/kudu-client/src/test/java/org/apache/kudu/client/TestSecurityContextRealUser.java@73 PS2, Line 73: try (KuduClient client = > wrap Done http://gerrit.cloudera.org:8080/#/c/9374/2/java/kudu-client/src/test/java/org/apache/kudu/client/TestSecurityContextRealUser.java@77 PS2, Line 77: > yea, probably.... guess it's worth a JIRA Done http://gerrit.cloudera.org:8080/#/c/9374/2/java/kudu-client/src/test/java/org/apache/kudu/client/TestSecurityContextRealUser.java@82 PS2, Line 82: // Try again with a correct real user. > mind wrapping this? Done http://gerrit.cloudera.org:8080/#/c/9374/2/src/kudu/client/client-internal.h File src/kudu/client/client-internal.h: http://gerrit.cloudera.org:8080/#/c/9374/2/src/kudu/client/client-internal.h@233 PS2, Line 233: // is built. > can you comment that this never changes after construction? ie it's effecti Done http://gerrit.cloudera.org:8080/#/c/9374/2/src/kudu/client/client-test.cc File src/kudu/client/client-test.cc: http://gerrit.cloudera.org:8080/#/c/9374/2/src/kudu/client/client-test.cc@5359 PS2, Line 5359: > ASSERT_OK ? Done http://gerrit.cloudera.org:8080/#/c/9374/2/src/kudu/client/client-test.cc@5362 PS2, Line 5362: table_creator->table_name(kTableName) > yea seems like probably should. maybe put this in the same JIRA as the oth Done http://gerrit.cloudera.org:8080/#/c/9374/2/src/kudu/client/client.proto File src/kudu/client/client.proto: http://gerrit.cloudera.org:8080/#/c/9374/2/src/kudu/client/client.proto@116 PS2, Line 116: root > nit: if I'm not mistaken, some time ago there was an idea to keep whole cer Isn't that kind of redundant? I thought with PKI you typically just trust root certs, and then intermediate / leaf certs are required to ship around any intermediate signing certs with themselves. -- To view, visit http://gerrit.cloudera.org:8080/9374 To unsubscribe, visit http://gerrit.cloudera.org:8080/settings Gerrit-Project: kudu Gerrit-Branch: master Gerrit-MessageType: comment Gerrit-Change-Id: I5d2d901d42501ecfc0f6372f68cf7335eb188b45 Gerrit-Change-Number: 9374 Gerrit-PatchSet: 3 Gerrit-Owner: Dan Burkert <danburk...@apache.org> Gerrit-Reviewer: Alexey Serbin <aser...@cloudera.com> Gerrit-Reviewer: Dan Burkert <danburk...@apache.org> Gerrit-Reviewer: Kudu Jenkins Gerrit-Reviewer: Tidy Bot Gerrit-Reviewer: Todd Lipcon <t...@apache.org> Gerrit-Comment-Date: Tue, 13 Mar 2018 19:04:25 +0000 Gerrit-HasComments: Yes