Posts: 24
Registered: ‎11-15-2016

Short name mapping: "Non-simple name"


I'm having some issues configuring the mapping from kerberos SPN/UPN to Hadoop short-names.
I've a complex AD setup with two distinct domains:


  • SERVICES.COM: this is a domain dedicated to host and services. This is the one used for the cluster configuration via Cloudera Manager.
  • USERS.COM: this is the domain with all the users in the company (it's a different domain for organizational reasons, managed by different teams with different policies)

The cluster is using RHEL 7 as OS, and I've joined all the host to SERVICES.COM using SSSD (we do this for all the linux hosts). With SSSD all users from USERS.COM are "available" in our servers as

My problem is: I can't configure the mapping from UPN user_name@USERS.COM to short-name I've actually managed to write a working rule but apparently Hadoop doesn't accept a short-name with a @ in it:

[root@host:~/test_mapping]# hadoop user_name@USERS.COM
Exception in thread "main"$NoMatchingRule: Non-simple name after auth_to_local rule RULE:[1:$1@$0](.*@\QUSERS.COM\E$)s/(.*)@\QUSERS.COM\E$/$

Digging through the issues in Hadoop's upstream JIRA I've found this:
This seams to be a fix to my issue merged in Hadoop 2.8/3.0.

Any change this will be backported to a future 5.11.x?