Uploaded image for project: 'Hadoop Common'
  1. Hadoop Common
  2. HADOOP-18886 S3A: AWS SDK V2 Migration: stabilization and S3Express
  3. HADOOP-19066

AWS SDK V2 - Enabling FIPS should be allowed with central endpoint

    XMLWordPrintableJSON

Details

    Description

      FIPS support can be enabled by setting "fs.s3a.endpoint.fips". Since the SDK considers overriding endpoint and enabling fips as mutually exclusive, we fail fast if fs.s3a.endpoint is set with fips support (details on HADOOP-18975).

      Now, we no longer override SDK endpoint for central endpoint since we enable cross region access (details on HADOOP-19044) but we would still fail fast if endpoint is central and fips is enabled.

      Changes proposed:

      • S3A to fail fast only if FIPS is enabled and non-central endpoint is configured.
      • Tests to ensure S3 bucket is accessible with default region us-east-2 with cross region access (expected with central endpoint).
      • Document FIPS support with central endpoint on connecting.html.

      Note: there are two patches here on trunk; they've been coalesced into one on branch-3.4.

      Attachments

        Issue Links

          Activity

            People

              vjasani Viraj Jasani
              vjasani Viraj Jasani
              Votes:
              0 Vote for this issue
              Watchers:
              3 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved: