|
@@ -39,9 +39,9 @@ OZONE-SITE.XML_ozone.acl.enabled=true
|
|
OZONE-SITE.XML_ozone.acl.authorizer.class=org.apache.hadoop.ozone.security.acl.OzoneNativeAuthorizer
|
|
OZONE-SITE.XML_ozone.acl.authorizer.class=org.apache.hadoop.ozone.security.acl.OzoneNativeAuthorizer
|
|
OZONE-SITE.XML_ozone.administrators=*
|
|
OZONE-SITE.XML_ozone.administrators=*
|
|
OZONE-SITE.XML_hdds.scm.http.kerberos.principal=HTTP/scm@EXAMPLE.COM
|
|
OZONE-SITE.XML_hdds.scm.http.kerberos.principal=HTTP/scm@EXAMPLE.COM
|
|
-OZONE-SITE.XML_hdds.scm.http.kerberos.keytab.file=/etc/security/keytabs/HTTP.keytab
|
|
|
|
|
|
+OZONE-SITE.XML_hdds.scm.http.kerberos.keytab=/etc/security/keytabs/HTTP.keytab
|
|
OZONE-SITE.XML_ozone.om.http.kerberos.principal=HTTP/om@EXAMPLE.COM
|
|
OZONE-SITE.XML_ozone.om.http.kerberos.principal=HTTP/om@EXAMPLE.COM
|
|
-OZONE-SITE.XML_ozone.om.http.kerberos.keytab.file=/etc/security/keytabs/HTTP.keytab
|
|
|
|
|
|
+OZONE-SITE.XML_ozone.om.http.kerberos.keytab=/etc/security/keytabs/HTTP.keytab
|
|
HDFS-SITE.XML_dfs.datanode.kerberos.principal=dn/_HOST@EXAMPLE.COM
|
|
HDFS-SITE.XML_dfs.datanode.kerberos.principal=dn/_HOST@EXAMPLE.COM
|
|
HDFS-SITE.XML_dfs.datanode.keytab.file=/etc/security/keytabs/dn.keytab
|
|
HDFS-SITE.XML_dfs.datanode.keytab.file=/etc/security/keytabs/dn.keytab
|
|
HDFS-SITE.XML_dfs.web.authentication.kerberos.principal=HTTP/_HOST@EXAMPLE.COM
|
|
HDFS-SITE.XML_dfs.web.authentication.kerberos.principal=HTTP/_HOST@EXAMPLE.COM
|
|
@@ -54,6 +54,21 @@ CORE-SITE.XML_hadoop.security.authentication=kerberos
|
|
CORE-SITE.XML_hadoop.security.auth_to_local=RULE:[2:$1@$0](.*)s/.*/root/
|
|
CORE-SITE.XML_hadoop.security.auth_to_local=RULE:[2:$1@$0](.*)s/.*/root/
|
|
CORE-SITE.XML_hadoop.security.key.provider.path=kms://http@kms:9600/kms
|
|
CORE-SITE.XML_hadoop.security.key.provider.path=kms://http@kms:9600/kms
|
|
|
|
|
|
|
|
+CORE-SITE.XML_hadoop.http.authentication.simple.anonymous.allowed=false
|
|
|
|
+CORE-SITE.XML_hadoop.http.authentication.signature.secret.file=/etc/security/http_secret
|
|
|
|
+CORE-SITE.XML_hadoop.http.authentication.type=kerberos
|
|
|
|
+CORE-SITE.XML_hadoop.http.authentication.kerberos.principal=HTTP/_HOST@EXAMPLE.COM
|
|
|
|
+CORE-SITE.XML_hadoop.http.authentication.kerberos.keytab=/etc/security/keytabs/HTTP.keytab
|
|
|
|
+CORE-SITE.XML_hadoop.http.filter.initializers=org.apache.hadoop.security.AuthenticationFilterInitializer
|
|
|
|
+
|
|
|
|
+LOG4J.PROPERTIES_log4j.logger.org.apache.hadoop.security.authentication.server
|
|
|
|
+.AuthenticationFilter=DEBUG
|
|
|
|
+LOG4J.PROPERTIES_log4j.logger.org.apache.hadoop.security.authentication.server
|
|
|
|
+.KerberosAuthenticationHandler=TRACE
|
|
|
|
+LOG4J.PROPERTIES_log4j.logger.org.apache.hadoop.http.HttpServer2=TRACE
|
|
|
|
+
|
|
|
|
+
|
|
|
|
+
|
|
CORE-SITE.XML_hadoop.security.authorization=true
|
|
CORE-SITE.XML_hadoop.security.authorization=true
|
|
HADOOP-POLICY.XML_ozone.om.security.client.protocol.acl=*
|
|
HADOOP-POLICY.XML_ozone.om.security.client.protocol.acl=*
|
|
HADOOP-POLICY.XML_hdds.security.client.datanode.container.protocol.acl=*
|
|
HADOOP-POLICY.XML_hdds.security.client.datanode.container.protocol.acl=*
|