Our Community is getting an upgrade! To get everything ready for the relaunch, we’ll be placing the site in read-only mode starting September 21st. We really appreciate your understanding while we get things set up behind the scenes. Catch up on all the exciting details about the move here. Need help or have questions? Drop us a line at [email protected]
Short description: This article describes how to enable Knox SSO authentication on Kerberos enabled Oozie UI
The goal is to provide a single authentication handler for redirecting to an external endpoint for acquiring a JWT (JSONWebToken) token to be used as a SSO representation of an authentication event.
The hadoop common JWTRedirectAuthenticationHandler can be used to add this support to component UIs. It is an extension of AltKerberosAuthenticationHandler, which require kerberos to be enabled on the HTTP endpoints in order to work. This means that UIs will use SSO for authentication, but at the same time REST APIs will still be using kerberos.
For authenticating REST APIs with Knox SSO as well, there is a filter based authentication provider in Knox.
SSL must be enabled on Oozie server to be able to use redirection.
Enable SSL on Oozie
Configuration in Ambari
Set the following properties at the Oozie config page: