Skip to main content

VSQLOH, HDFS enrcyption and Kerberos authentication

  • August 18, 2017
  • 2 replies
  • 13 views

DieterC
Forum|alt.badge.img+2

Hi forum,
a Vertica VSQLOH prospect is running a POC. They are facing authentication issues related to WebHDFS. This is the email I received. Can you please help with the two issues the prospects raises.
Thank you

Dieter

Hello Dieter,
we have installed a Vertica on Hadoop cluster and run the first tests.
Our HDFS has the following structure:

  • /vertica : Data storage location for Vertica, Read/Write access for Vertica user.
  • /tenants/tenant-XXXX : source data which will be used for Vertica external tables, access for Kerberos user tenant-XXXX
    (multiple tenants access the same AWS cluster, each tenant can see their own source data only)

We have applied an HDFS Encryption Zone to /tenants/tenant-XXXX. Its key can only be used by the corresponding tenant-XXXX user.
Authentication is done through Kerberos.

We have these questions / encountered these problems on the topic:

1) When we try to use an external table from the directory with Encryption Zone we get an error. It indicates that WebHDFS was used instead of the native HDFS connector. This is described in this blog entry on Vertica 7.2.3
https://my.vertica.com/blog/what-s-new-in-7-2-3-new-apache-hadoop-integration-featuresba-p236946/)
For example, if it finds that the Hadoop cluster it is trying to read data from uses Kerberos authentication, it switches back to webHDFS.

The problem with WebHDFS seems to be that it uses always the same HDFS user. This would disable tenant ecryption as each tenant would see all data on the system (loss of data protection).

Is there a chance to use the native Hadoop connector when accessing /tenants/tenant-XXXX?

2) similar issue to 1)
Is there a chance to place a HDFS Encryption Zone on Vertica data storage?
Also in this case we need the native HDFS connector - and we need to use Kerberos for authentication.

Thanks
your prospect

2 replies

SatishSathiya
  • New Participant
  • August 18, 2017

what version of Vertica is this ? Can you also copy paste the exact error message ? Also provide details on how the kinit and then subsequent vsql session was done.


DieterC
Forum|alt.badge.img+2
  • Author
  • Participating Frequently
  • August 30, 2017

Hi forum,
in our POC we are still facing authentication issues regarding HDFS access.
Can you please have a look at this snippet from our email exchange and recommend solutions?
Thank you
Dieter

Hello Dieter,

we are still having problems getting the communication via hdfs:// scheme to work (falls back to webhdfs://).
Are there any additional hdfs settings that may need adjustment?
We think that the IO via webhdfs may be a big bottleneck.

The hadoop version we are using is 2.7.3
Just for reference if that helps.

Best Regards,
Odilo

On 22 August 2017 at 17:58, Odilo Hildebrandt o.hildebrandt@celonis.com wrote:
Hi Satish,

thanks for your quick response.
We tried setting "dfs.encrypt.data.transfer" to "false" and "hadoop.rpc.protection" to "authentication".
The warning about not using libhdfs remained the same thou.
Are there more hadoop configuration values that need to be changed to temporarily deactivate wire encryption?
The webhdfs access works so far, but it would be great to get a performance boost via native implementation.

Thanks and Best Regards,
Odilo

On 22 August 2017 at 16:35, Sathiyavageswaran, Satish (HPSW Big Data Platform Presales) satish.sathiya@hpe.com wrote:
Hello,

Vertica 8.1.1 as of now doesn’t support wire encryption especially when using hdfs:// scheme.
If it detects “wire encryption” enabled , then it falls back to use webhdfs.
To access that , you might have to use “swebhdfs:///” instead of “webhdfs:///” .
There is an open JIRA to support “wire encryption” with hdfs:///.
Hope this helps.