- Subscribe to RSS Feed
- Mark Question as New
- Mark Question as Read
- Float this Question for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Nesus scan seems to kill hbase thrift server. Has anyone seen this before ?
- Labels:
-
Apache HBase
-
Security
Created on 03-12-2014 04:46 AM - edited 09-16-2022 01:55 AM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I have opened a case, but was also wanting to check with the community.
When our security team runs nesus to scan hosts, it kills the hbase thrift server.
I was curious if anyone has seen this before, and might now which part of the nesus scanning is causing the hbase thrift server to die.
I was unable to find any useful information in the thrift server log.
Created 03-17-2014 07:17 AM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Cloudera Support was able to solve the case.
The thrift server is set to die from a kill -9 upon error.
The error was a java out of memory error when being scanned.
We upped the thift server heap size to 4G and all is well.
Created 03-12-2014 09:55 AM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi Ranks,
HBase Thrift Server does not authenticate requests, so it should not be used if you care about security until this issue is fixed.
Thanks,
Darren
Created 03-12-2014 12:24 PM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Im not a nesus expert, but our security team said they tried to turn off authentication on the scan, and that didnt stop it from crashing.
If you really think this may be the issue, I'll follow up more with them, for them to double check what they are doing.
Created 03-12-2014 12:29 PM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I'm not saying that this is the reason why it was killed. I don't really know anything about nesus or why it might kill a process. It just sounds like you are doing security audits, and if so you should know that HBase Thrift server is a security hole that should fail any comprehensive security audit. In general, regardless of nesus, if you care about security in your cluster, you should not use this role.
Thanks,
Darren
Created 03-12-2014 12:32 PM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Created 03-17-2014 07:17 AM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Cloudera Support was able to solve the case.
The thrift server is set to die from a kill -9 upon error.
The error was a java out of memory error when being scanned.
We upped the thift server heap size to 4G and all is well.