Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Original file line number Diff line number Diff line change
Expand Up @@ -104,10 +104,15 @@ public static void checkSaslComplete(SaslParticipant sasl,
String negotiatedQop = sasl.getNegotiatedQop();
LOG.debug("{}: Verifying QOP: requested = {}, negotiated = {}",
sasl, requestedQop, negotiatedQop);
if (negotiatedQop != null && !requestedQop.contains(negotiatedQop)) {
// Treat null negotiated QOP as "auth" for the purpose of verification
// Code elsewhere does the same implicitly
if(negotiatedQop == null) {
negotiatedQop = "auth";
}
if (!requestedQop.contains(negotiatedQop)) {
throw new IOException(String.format("SASL handshake completed, but " +
"channel does not have acceptable quality of protection, " +
"requested = %s, negotiated = %s", requestedQop, negotiatedQop));
"requested = %s, negotiated(effective) = %s", requestedQop, negotiatedQop));
}
}

Expand All @@ -130,12 +135,11 @@ public static boolean requestedQopContainsPrivacy(
* @param encryptionAlgorithm to use for SASL negotation
* @return properties of encrypted SASL negotiation
*/
public static Map<String, String> createSaslPropertiesForEncryption(
String encryptionAlgorithm) {
Map<String, String> saslProps = Maps.newHashMapWithExpectedSize(3);
saslProps.put(Sasl.QOP, QualityOfProtection.PRIVACY.getSaslQop());
public static Map<String, String> createSaslPropertiesForEncryption() {
Map<String, String> saslProps = Maps.newHashMapWithExpectedSize(2);
// This is equivalent to not setting QOP, but the rest of Hadoop expects this to be set
saslProps.put(Sasl.QOP, QualityOfProtection.AUTHENTICATION.getSaslQop());
saslProps.put(Sasl.SERVER_AUTH, "true");
saslProps.put("com.sun.security.sasl.digest.cipher", encryptionAlgorithm);
return saslProps;
}

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -315,8 +315,7 @@ private IOStreamPair getEncryptedStreams(InetAddress addr,
Token<BlockTokenIdentifier> accessToken,
SecretKey secretKey)
throws IOException {
Map<String, String> saslProps = createSaslPropertiesForEncryption(
encryptionKey.encryptionAlgorithm);
Map<String, String> saslProps = createSaslPropertiesForEncryption();
if (secretKey != null) {
LOG.debug("DataNode overwriting downstream QOP" +
saslProps.get(Sasl.QOP));
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -173,8 +173,7 @@ private IOStreamPair getEncryptedStreams(Peer peer,
return new IOStreamPair(underlyingIn, underlyingOut);
}

Map<String, String> saslProps = createSaslPropertiesForEncryption(
dnConf.getEncryptionAlgorithm());
Map<String, String> saslProps = createSaslPropertiesForEncryption();

if (LOG.isDebugEnabled()) {
LOG.debug("Server using encryption algorithm " +
Expand Down
Loading