Support Questions
Find answers, ask questions, and share your expertise

use of hadoop.security.token.service.use_ip=false with Isilon

Previously it had always recommended adding the following to the core-site.xml to limit hostname and IP exposure when getting Kerberos delegation tokens: hadoop.security.token.service.use_ip=false when using Kerberos with HDP and Isilon.

But in recent deployments, this setting does not appear as critical as previously required if full forward and DNS is implemented correctly. (PTR's on all Isilon Pool IP's).

I'm looking for any field experience on this issue, is this setting still required or needed to avoid delegation token issues?

1 REPLY 1

Cloudera Employee

Specify the following configurations in Cloudera Manager on the Clusters > Isilon Service > Configuration tab:

  • In the Isilon Cluster-wide Advanced Configuration Snippet (Safety Valve) for core-site.xml property for the Isilon service, set the value  use_ip property to FALSE.

 

hadoop.security.token.service.use_ip = false

 

For more info click here