Fixed Issues in Apache Knox
Review the list of Knox issues that are resolved in Cloudera Base on premises 7.3.1, its service packs and cumulative hotfixes.
Cloudera Runtime 7.3.1.500 SP3
- OPSAPS-73038: False-positive port conflict error message displayed in Cloudera Manager
- This issue is fixed now. A new health port has
been added as a configuration to the Knox configuration. The health topology
port can be set with topology port mapping. By setting the new
configuration, the
checkDeployment
script will use the new health port. - CDPD-81958: Improve cookie security in Knox-proxied
web UIs with
Secure
andHttpOnly
attributes - The
pac4jCsrfToken
cookie has now bothSecure
andHttpOnly
flags in Knox proxied applications, improving the security provided by Knox.
Cloudera Runtime 7.3.1.400 SP2
- CDPD-8148: Knox UI session timeout is not working with SAML authentication
- This issue is resolved by the
pac4j.cookie.max.age
parameter introduced for the pac4j provider, which Knox uses for SAML authentication. This parameter enforces cookie timeout for the cookies created by the pac4j provider.
Cloudera Runtime 7.3.1.300 SP1 CHF 1
- CDPD-27801: Knox is missing HSTS header for HTTP 404 responses
- 7.3.1.300, 7.1.9 CHF8
- CDPD-73368: Knox token management is not working if Cookie Management is enabled
- 7.3.1.300
- CDPD-74843: Logs missing in third-party libraries
- 7.3.1.300
- CDPD-78656: Health test for Knox fails if the gateway.client.auth.needed = true is set
- 7.1.9 CHF7, 7.3.1.300
Cloudera Runtime 7.3.1.200 SP1
- CDPD-77233: Knox Token TTL value of -1 set to never expire
- 7.3.1.200
- CDPD-79963: Knox service might fail due to JARs picked up from the /usr/share/java folder
- 7.3.1.200
- CDPD-76104: Unable to update the log level for Knox from Cloudera Manager
- 7.3.1.200
Cloudera Runtime 7.3.1.100 CHF 1
- CDPD-74114: Proxyuser groups are not included in POST and PATCH requests
- 7.3.1.100
Cloudera Runtime 7.3.1
- CDPD-73275: HTTP 404 responses while Knox is redeploying topologies
- 7.3.1
- CDPD-70313: KNOX did not send Authentication header on FIPS configuration
- 7.3.1
- CDPD-67478: Custom topologies cannot be deleted
- 7.3.1
- OPSAPS-67480: Default Ranger policy in Cloudera Base on premises 7.1.9 includes cdp-proxy-token topology for new installations, but upgrades do not add cdp-proxy-token to cm_knox policies automatically.
- 7.3.1
- CDPD-69305: /plugins/policies/importPoliciesFromFile API returns 500 service connectivity error through Knox Proxy
- 7.3.1
Apache patch information
- KNOX-3073
- KNOX-3058
- KNOX-3055
- KNOX-3054
- KNOX-3053
- KNOX-3052
- KNOX-3050
- KNOX-3049
- KNOX-3045
- KNOX-3040
- KNOX-3038
- KNOX-3037
- KNOX-3036
- KNOX-3029
- KNOX-3028
- KNOX-3026
- KNOX-3024
- KNOX-3023
- KNOX-3022
- KNOX-3020
- KNOX-3019
- KNOX-3018
- KNOX-3017
- KNOX-3016
- KNOX-3012
- KNOX-3007
- KNOX-3006
- KNOX-3005
- KNOX-3002
- KNOX-3001
- KNOX-3000
- KNOX-2994
- KNOX-2985
- KNOX-2983
- KNOX-2980
- KNOX-2979
- KNOX-2978
- KNOX-2976
- KNOX-2975
- KNOX-2974
- KNOX-2973
- KNOX-2972
- KNOX-2971
- KNOX-2970
- KNOX-2969
- KNOX-2968
- KNOX-2966
- KNOX-2963
- KNOX-2961
- KNOX-2960
- KNOX-2959
- KNOX-2958
- KNOX-2955
- KNOX-2951
- KNOX-2949
- KNOX-2948
- KNOX-2947
- KNOX-2946
- KNOX-2929
- KNOX-2896
- KNOX-2881