Skip to content
Snippets Groups Projects
Commit 3fa290df authored by František Dvořák's avatar František Dvořák
Browse files

Activate SPNEGO even without SSL - http signature secret file needed

parent fec48847
Branches
No related tags found
No related merge requests found
...@@ -118,6 +118,13 @@ class local_kerberos { ...@@ -118,6 +118,13 @@ class local_kerberos {
} }
File['/etc/security/keytab'] -> Kerberos::Keytab <| |> File['/etc/security/keytab'] -> Kerberos::Keytab <| |>
file{'/etc/security/http-auth-signature-secret':
content => '$http_signature_secret',
mode => '0600',
owner => 'root',
group => 'root',
}
} }
class local_kerberos_master { class local_kerberos_master {
......
...@@ -192,6 +192,13 @@ class local_kerberos { ...@@ -192,6 +192,13 @@ class local_kerberos {
} }
File['/etc/security/keytab'] -> Kerberos::Keytab <| |> File['/etc/security/keytab'] -> Kerberos::Keytab <| |>
file{'/etc/security/http-auth-signature-secret':
content => '$http_signature_secret',
mode => '0600',
owner => 'root',
group => 'root',
}
} }
class local_kerberos_master { class local_kerberos_master {
......
...@@ -25,6 +25,7 @@ class ComponentHadoopCommon: ...@@ -25,6 +25,7 @@ class ComponentHadoopCommon:
'realm': 'HADOOP', 'realm': 'HADOOP',
'kerberos_admin_password': config['secrets']['kerberos_admin_password'], 'kerberos_admin_password': config['secrets']['kerberos_admin_password'],
'kerberos_master_password': config['secrets']['kerberos_master_password'], 'kerberos_master_password': config['secrets']['kerberos_master_password'],
'http_signature_secret': config['secrets']['http_signature_secret'],
'data_dirs': data_dirs, 'data_dirs': data_dirs,
} }
......
...@@ -190,6 +190,13 @@ class local_kerberos { ...@@ -190,6 +190,13 @@ class local_kerberos {
} }
File['/etc/security/keytab'] -> Kerberos::Keytab <| |> File['/etc/security/keytab'] -> Kerberos::Keytab <| |>
file{'/etc/security/http-auth-signature-secret':
content => '$http_signature_secret',
mode => '0600',
owner => 'root',
group => 'root',
}
} }
class local_kerberos_master { class local_kerberos_master {
......
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Please register or to comment