[
https://issues.apache.org/jira/browse/HADOOP-9446?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=13738744#comment-13738744
]
Yu Gao commented on HADOOP-9446:
--------------------------------
Regarding the latest patch test report,
(1) there are 13 java doc warnings in total. Besides the known 11 warnings
introduced by sun APIs, which are expected, there are 2 new ones from
hadoop-minikdc module:
[WARNING] Javadoc Warnings
[WARNING]
org/apache/directory/api/ldap/model/name/Dn.class(org/apache/directory/api/ldap/model/name:Dn.class):
warning: Cannot find annotation method 'value()' in type
'edu.umd.cs.findbugs.annotations.SuppressWarnings': class file for
edu.umd.cs.findbugs.annotations.SuppressWarnings not found
[WARNING]
org/apache/directory/api/ldap/model/name/Dn.class(org/apache/directory/api/ldap/model/name:Dn.class):
warning: Cannot find annotation method 'justification()' in type
'edu.umd.cs.findbugs.annotations.SuppressWarnings'
which was introduced by HADOOP-9848
(2) for the two findbugs issue, they are caused by two fields from class
org.apache.hadoop.metrics2.lib.DefaultMetricsSystem, which is also not
introduced or modified by this patch. Not sure why it popped up here...
> Support Kerberos HTTP SPNEGO authentication for non-SUN JDK
> -----------------------------------------------------------
>
> Key: HADOOP-9446
> URL: https://issues.apache.org/jira/browse/HADOOP-9446
> Project: Hadoop Common
> Issue Type: Improvement
> Components: security
> Affects Versions: 1.1.1, 2.0.2-alpha
> Reporter: Yu Gao
> Assignee: Yu Gao
> Attachments: HADOOP-9446-branch-2.patch,
> HADOOP-9446-branch-2-v2.patch, HADOOP-9446.patch, HADOOP-9446-v2.patch,
> TestKerberosHttpSPNEGO.java,
> TEST-org.apache.hadoop.security.authentication.client.TestKerberosAuthenticator.xml,
>
> TEST-org.apache.hadoop.security.authentication.server.TestKerberosAuthenticationHandler.xml
>
>
> Class KerberosAuthenticator and KerberosAuthenticationHandler currently only
> support running with SUN JDK when Kerberos is enabled. In order to support
> alternative JDKs like IBM JDK which has different options supported by
> Krb5LoginModule and different login module classes, the HTTP Kerberos
> authentication classes need to be changed.
> In addition, NT_GSS_KRB5_PRINCIPAL, which is used in KerberosAuthenticator to
> get the corresponding oid instance, is a field defined in SUN JDK, but not in
> IBM JDK.
> This JIRA is to fix the existing problems and add support for Kerberos HTTP
> SPNEGO authentication with non-SUN JDK.
--
This message is automatically generated by JIRA.
If you think it was sent incorrectly, please contact your JIRA administrators
For more information on JIRA, see: http://www.atlassian.com/software/jira