All Downloads are FREE. Search and download functionalities are using the official Maven repository.

org.apache.hadoop.security.token.delegation.web.KerberosDelegationTokenAuthenticationHandler Maven / Gradle / Ivy

There is a newer version: 3.4.0
Show newest version
/**
 * Licensed to the Apache Software Foundation (ASF) under one
 * or more contributor license agreements.  See the NOTICE file
 * distributed with this work for additional information
 * regarding copyright ownership.  The ASF licenses this file
 * to you under the Apache License, Version 2.0 (the
 * "License"); you may not use this file except in compliance
 * with the License.  You may obtain a copy of the License at
 *
 *     http://www.apache.org/licenses/LICENSE-2.0
 *
 * Unless required by applicable law or agreed to in writing, software
 * distributed under the License is distributed on an "AS IS" BASIS,
 * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
 * See the License for the specific language governing permissions and
 * limitations under the License.
 */
package org.apache.hadoop.security.token.delegation.web;

import org.apache.hadoop.classification.InterfaceAudience;
import org.apache.hadoop.classification.InterfaceStability;
import org.apache.hadoop.security.authentication.server.AuthenticationHandler;
import org.apache.hadoop.security.authentication.server.KerberosAuthenticationHandler;

/**
 * An {@link AuthenticationHandler} that implements Kerberos SPNEGO mechanism
 * for HTTP and supports Delegation Token functionality.
 * 

* In addition to the {@link KerberosAuthenticationHandler} configuration * properties, this handler supports: *

    *
  • kerberos.delegation-token.token-kind: the token kind for generated tokens * (no default, required property).
  • *
  • kerberos.delegation-token.update-interval.sec: secret manager master key * update interval in seconds (default 1 day).
  • *
  • kerberos.delegation-token.max-lifetime.sec: maximum life of a delegation * token in seconds (default 7 days).
  • *
  • kerberos.delegation-token.renewal-interval.sec: renewal interval for * delegation tokens in seconds (default 1 day).
  • *
  • kerberos.delegation-token.removal-scan-interval.sec: delegation tokens * removal scan interval in seconds (default 1 hour).
  • *
*/ @InterfaceAudience.Private @InterfaceStability.Evolving public class KerberosDelegationTokenAuthenticationHandler extends DelegationTokenAuthenticationHandler { public KerberosDelegationTokenAuthenticationHandler() { super(new KerberosAuthenticationHandler(KerberosAuthenticationHandler.TYPE + TYPE_POSTFIX)); } }




© 2015 - 2024 Weber Informatics LLC | Privacy Policy