SPNEGO TLS verification

Signed-off-by: Akira Ajisaka <aajisaka@apache.org>
(cherry picked from commit ba66f3b454)

 Conflicts:
	hadoop-hdfs-project/hadoop-hdfs-client/src/main/java/org/apache/hadoop/hdfs/web/WebHdfsFileSystem.java
This commit is contained in:
Eric Yang 2020-03-31 13:37:55 -04:00 committed by Akira Ajisaka
parent 4cf7bbf043
commit 28715b584a
No known key found for this signature in database
GPG Key ID: C1EDBB9CA400FD50
1 changed files with 9 additions and 0 deletions

View File

@ -140,6 +140,7 @@ public class WebHdfsFileSystem extends FileSystem
+ "/v" + VERSION;
public static final String EZ_HEADER = "X-Hadoop-Accept-EZ";
public static final String FEFINFO_HEADER = "X-Hadoop-feInfo";
public static final String DFS_HTTP_POLICY_KEY = "dfs.http.policy";
/**
* Default connection factory may be overridden in tests to use smaller
@ -169,6 +170,7 @@ public class WebHdfsFileSystem extends FileSystem
new ObjectMapper().reader(Map.class);
private DFSOpsCountStatistics storageStatistics;
private boolean isTLSKrb;
/**
* Return the protocol scheme for the FileSystem.
@ -231,6 +233,8 @@ public class WebHdfsFileSystem extends FileSystem
.newDefaultURLConnectionFactory(connectTimeout, readTimeout, conf);
}
this.isTLSKrb = "HTTPS_ONLY".equals(conf.get(DFS_HTTP_POLICY_KEY));
ugi = UserGroupInformation.getCurrentUser();
this.uri = URI.create(uri.getScheme() + "://" + uri.getAuthority());
this.nnAddrs = resolveNNAddr();
@ -690,6 +694,11 @@ public class WebHdfsFileSystem extends FileSystem
//redirect hostname and port
redirectHost = null;
if (url.getProtocol().equals(getTransportScheme()) &&
UserGroupInformation.isSecurityEnabled() &&
isTLSKrb) {
throw new IOException("Access denied: dfs.http.policy is HTTPS_ONLY.");
}
// resolve redirects for a DN operation unless already resolved
if (op.getRedirect() && !redirected) {