<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>question Re: Kerberos KDC not reachable in Support Questions</title>
    <link>https://community.cloudera.com/t5/Support-Questions/Kerberos-KDC-not-reachable/m-p/141036#M103643</link>
    <description>&lt;P&gt;It doesnt work for me even though i faced same problem and i did same steps mentioned..&lt;/P&gt;</description>
    <pubDate>Fri, 03 Mar 2017 16:14:55 GMT</pubDate>
    <dc:creator>hardikv_desai</dc:creator>
    <dc:date>2017-03-03T16:14:55Z</dc:date>
    <item>
      <title>Kerberos KDC not reachable</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Kerberos-KDC-not-reachable/m-p/141026#M103633</link>
      <description>&lt;P&gt;&lt;A href="https://community.cloudera.com/legacyfs/online/attachments/2951-kdc-unreachable.jpg" target="_blank"&gt;kdc-unreachable.jpg&lt;/A&gt;I am trying to kereeberise my HDP cluster. I have installed a KDC on the ambari host itself and i want to use that. so i selected option 1 (existing KDC) in ambari. But when i try to test the KDC connection it fails and i get the following error.&lt;/P&gt;&lt;P&gt;23 Mar 2016 13:16:29,457  WARN [qtp-ambari-client-18131] KdcServerConnectionVerification:187 - An unexpected exception occurred while attempting to communicate with the KDC server at hostname:88 over TCP
23 Mar 2016 13:16:29,459  WARN [qtp-ambari-client-18131] KdcServerConnectionVerification:187 - An unexpected exception occurred while attempting to communicate with the KDC server at hostname:88 over UDP
23 Mar 2016 13:16:29,460 ERROR [qtp-ambari-client-18131] KdcServerConnectionVerification:113 - Failed to connect to the KDC at hostname:88 using either TCP or UDP&lt;/P&gt;&lt;P&gt;But when i try to do kinit or invoke any kerberos command from the ambari/KDC host it is working fine. It is pretty strange and i dont see any network related issues. this error is seen only when a wrong kdc information is provided. But in my case even after providing the correct details it fails. From the logs i couldnt trace anything.&lt;/P&gt;&lt;P&gt;Is there any way to debug or trace it.&lt;/P&gt;&lt;P&gt;i used ping, telenet to do the basic checks and everything is fine.&lt;/P&gt;&lt;P&gt;P.s i have just replaced my KDC host names with the string "hostname"in the above error message.&lt;/P&gt;</description>
      <pubDate>Fri, 16 Sep 2022 10:10:40 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Kerberos-KDC-not-reachable/m-p/141026#M103633</guid>
      <dc:creator>arunpoy</dc:creator>
      <dc:date>2022-09-16T10:10:40Z</dc:date>
    </item>
    <item>
      <title>Re: Kerberos KDC not reachable</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Kerberos-KDC-not-reachable/m-p/141027#M103634</link>
      <description>&lt;P&gt;Can you try restarting the ambari-server and retrying the kerberos wizard, but this time specifying the correct information the first time?&lt;/P&gt;</description>
      <pubDate>Wed, 23 Mar 2016 21:35:22 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Kerberos-KDC-not-reachable/m-p/141027#M103634</guid>
      <dc:creator>pcodding</dc:creator>
      <dc:date>2016-03-23T21:35:22Z</dc:date>
    </item>
    <item>
      <title>Re: Kerberos KDC not reachable</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Kerberos-KDC-not-reachable/m-p/141028#M103635</link>
      <description>&lt;P&gt;Looking at the following error message, you specified the KDC host as "hostname" not the FQDN of the relevant host.&lt;/P&gt;&lt;PRE&gt;An unexpected exception occurred while attempting to communicate with the KDC server at hostname:88 over TCP&lt;/PRE&gt;&lt;P&gt;Rerun the Enable Kerberos Wizard and make sure you set the correct hostname for the KDC and admin hosts. &lt;/P&gt;</description>
      <pubDate>Wed, 23 Mar 2016 22:39:21 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Kerberos-KDC-not-reachable/m-p/141028#M103635</guid>
      <dc:creator>rlevas</dc:creator>
      <dc:date>2016-03-23T22:39:21Z</dc:date>
    </item>
    <item>
      <title>Re: Kerberos KDC not reachable</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Kerberos-KDC-not-reachable/m-p/141029#M103636</link>
      <description>&lt;P&gt;&lt;A rel="user" href="https://community.cloudera.com/users/322/rlevas.html" nodeid="322"&gt;@Robert Levas&lt;/A&gt;, i have used the FQDN only.&lt;/P&gt;</description>
      <pubDate>Thu, 24 Mar 2016 07:52:09 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Kerberos-KDC-not-reachable/m-p/141029#M103636</guid>
      <dc:creator>arunpoy</dc:creator>
      <dc:date>2016-03-24T07:52:09Z</dc:date>
    </item>
    <item>
      <title>Re: Kerberos KDC not reachable</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Kerberos-KDC-not-reachable/m-p/141030#M103637</link>
      <description>&lt;A rel="user" href="https://community.cloudera.com/users/32/paul.html" nodeid="32"&gt;@Paul Codding&lt;/A&gt;&lt;P&gt;, &lt;A rel="user" href="https://community.cloudera.com/users/393/aervits.html" nodeid="393"&gt;@Artem Ervits&lt;/A&gt;, &lt;A rel="user" href="https://community.cloudera.com/users/322/rlevas.html" nodeid="322"&gt;@Robert Levas&lt;/A&gt;, &lt;/P&gt;&lt;P&gt;One strange thing i noticed is, i am able to connect to the same KDC from ambari running in a different environment. But ambari in that environment is 2.1 and the one from where i am not able to connect is 2.2.1&lt;/P&gt;&lt;P&gt;This is weird. How do i resolve this. IS there a way i can just uninstall ambari alone or how do i fix this. I dont think this is a bug in amabri 2.2.1. i have tried this in sandbox before and it worked fine.&lt;/P&gt;</description>
      <pubDate>Thu, 24 Mar 2016 18:31:25 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Kerberos-KDC-not-reachable/m-p/141030#M103637</guid>
      <dc:creator>arunpoy</dc:creator>
      <dc:date>2016-03-24T18:31:25Z</dc:date>
    </item>
    <item>
      <title>Re: Kerberos KDC not reachable</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Kerberos-KDC-not-reachable/m-p/141031#M103638</link>
      <description>&lt;P&gt;IS this could be because of the ambari upgrade from 2.1 to 2.2?&lt;/P&gt;</description>
      <pubDate>Thu, 31 Mar 2016 13:21:59 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Kerberos-KDC-not-reachable/m-p/141031#M103638</guid>
      <dc:creator>arunpoy</dc:creator>
      <dc:date>2016-03-31T13:21:59Z</dc:date>
    </item>
    <item>
      <title>Re: Kerberos KDC not reachable</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Kerberos-KDC-not-reachable/m-p/141032#M103639</link>
      <description>&lt;P&gt;&lt;A rel="user" href="https://community.cloudera.com/users/2302/arunpoy.html" nodeid="2302"&gt;@ARUNKUMAR RAMASAMY&lt;/A&gt; &lt;/P&gt;&lt;P&gt;I think I lost track of this issue... sorry about that. Are you still having issue?&lt;/P&gt;&lt;P&gt;The version of Ambari shouldn't make a difference here.  Yu should make sure that you can manually connect to the KDC from the command line of the host where Ambari is running.  Maybe there is a DNS issue?&lt;/P&gt;&lt;P&gt;Make sure the /etc/krb5.conf file is set to point to your KDC, then issue some command like:&lt;/P&gt;&lt;PRE&gt;kadmin -p &amp;lt;ADMIN PRINCIPAL&amp;gt; -q "get_principal &amp;lt;ADMIN PRINCIPAL&amp;gt;"&lt;/PRE&gt;&lt;P&gt;For example:&lt;/P&gt;&lt;PRE&gt;# kadmin -p admin/admin@EXAMPLE.COM -q "get_principal admin/admin@EXAMPLE.COM"
Authenticating as principal admin/admin@EXAMPLE.COM with password.
Password for admin/admin@EXAMPLE.COM:
Principal: admin/admin@EXAMPLE.COM
Expiration date: [never]
Last password change: Mon Apr 25 16:11:27 UTC 2016
Password expiration date: [none]
Maximum ticket life: 1 day 00:00:00
Maximum renewable life: 0 days 00:00:00
Last modified: Mon Apr 25 16:11:27 UTC 2016 (root/admin@EXAMPLE.COM)
Last successful authentication: [never]
Last failed authentication: [never]
Failed password attempts: 0
Number of keys: 6
Key: vno 1, aes256-cts-hmac-sha1-96, no salt
Key: vno 1, aes128-cts-hmac-sha1-96, no salt
Key: vno 1, des3-cbc-sha1, no salt
Key: vno 1, arcfour-hmac, no salt
Key: vno 1, des-hmac-sha1, no salt
Key: vno 1, des-cbc-md5, no salt
MKey: vno 1
Attributes:
Policy: [none]
&lt;/PRE&gt;&lt;P&gt;If it fails, you might get something like:&lt;/P&gt;&lt;PRE&gt;# kadmin -p admin/admin@EXAMPLE.COM -q "get_principal admin/admin@EXAMPLE.COM"
Authenticating as principal admin/admin@EXAMPLE.COM with password.
kadmin: Cannot contact any KDC for requested realm while initializing kadmin interface
&lt;/PRE&gt;</description>
      <pubDate>Tue, 26 Apr 2016 22:44:26 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Kerberos-KDC-not-reachable/m-p/141032#M103639</guid>
      <dc:creator>rlevas</dc:creator>
      <dc:date>2016-04-26T22:44:26Z</dc:date>
    </item>
    <item>
      <title>Re: Kerberos KDC not reachable</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Kerberos-KDC-not-reachable/m-p/141033#M103640</link>
      <description>&lt;P&gt;I have the same problem...&lt;/P&gt;&lt;P&gt;Ambari Version: 2.2.2.0&lt;/P&gt;&lt;P&gt;HDP Version: 2.4.2.0-258&lt;/P&gt;&lt;P&gt;I can ping KDC from Ambari Server and telnet port 88/749 as well as running kadmin command without error:&lt;/P&gt;&lt;P&gt;/usr/bin/kadmin -s KDC_SERVER:749 -p admin -w ****** -r EXAMPLE.COM -q "get_principal admin"&lt;/P&gt;&lt;P&gt;I've also checked the src code but no luck:&lt;/P&gt;&lt;P&gt;&lt;A href="https://github.com/apache/ambari/blob/trunk/ambari-server/src/main/java/org/apache/ambari/server/KdcServerConnectionVerification.java" target="_blank"&gt;https://github.com/apache/ambari/blob/trunk/ambari-server/src/main/java/org/apache/ambari/server/KdcServerConnectionVerification.java&lt;/A&gt;&lt;/P&gt;&lt;P&gt;After retarting Ambari Server in DEBUG mode, found the problem:&lt;/P&gt;&lt;P&gt;Caused by: java.lang.IllegalArgumentException: Algorithm AES256 not enabled&lt;/P&gt;&lt;P&gt;Still testing how to enable it...&lt;/P&gt;&lt;P&gt;modify the krb.conf, but doesn't work.&lt;/P&gt;&lt;P&gt;It looks like the JCE installation issue (confirm the JCE policy jars were in the right place...)&lt;/P&gt;</description>
      <pubDate>Thu, 12 May 2016 12:41:02 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Kerberos-KDC-not-reachable/m-p/141033#M103640</guid>
      <dc:creator>davidlu1001</dc:creator>
      <dc:date>2016-05-12T12:41:02Z</dc:date>
    </item>
    <item>
      <title>Re: Kerberos KDC not reachable</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Kerberos-KDC-not-reachable/m-p/141034#M103641</link>
      <description>&lt;P&gt;Install JCE with unlimited strength.&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.oracle.com/technetwork/java/javase/downloads/index.html"&gt;http://www.oracle.com/technetwork/java/javase/downloads/index.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;I did this and the issue got resolved. after that i did a restart of ambari server.&lt;/P&gt;</description>
      <pubDate>Thu, 12 May 2016 14:19:28 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Kerberos-KDC-not-reachable/m-p/141034#M103641</guid>
      <dc:creator>arunpoy</dc:creator>
      <dc:date>2016-05-12T14:19:28Z</dc:date>
    </item>
    <item>
      <title>Re: Kerberos KDC not reachable</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Kerberos-KDC-not-reachable/m-p/141035#M103642</link>
      <description>&lt;P&gt;It works great!&lt;/P&gt;&lt;P&gt;By the way, you can download the JCE in this url:&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.hortonworks.com/HDPDocuments/Ambari-2.2.1.1/bk_Ambari_Security_Guide/content/_distribute_and_install_the_jce.html"&gt;https://docs.hortonworks.com/HDPDocuments/Ambari-2.2.1.1/bk_Ambari_Security_Guide/content/_distribute_and_install_the_jce.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Mon, 08 Aug 2016 14:12:44 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Kerberos-KDC-not-reachable/m-p/141035#M103642</guid>
      <dc:creator>alberto_garciag</dc:creator>
      <dc:date>2016-08-08T14:12:44Z</dc:date>
    </item>
    <item>
      <title>Re: Kerberos KDC not reachable</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Kerberos-KDC-not-reachable/m-p/141036#M103643</link>
      <description>&lt;P&gt;It doesnt work for me even though i faced same problem and i did same steps mentioned..&lt;/P&gt;</description>
      <pubDate>Fri, 03 Mar 2017 16:14:55 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Kerberos-KDC-not-reachable/m-p/141036#M103643</guid>
      <dc:creator>hardikv_desai</dc:creator>
      <dc:date>2017-03-03T16:14:55Z</dc:date>
    </item>
    <item>
      <title>Re: Kerberos KDC not reachable</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Kerberos-KDC-not-reachable/m-p/314082#M225883</link>
      <description>&lt;P&gt;Hi,&amp;nbsp;&lt;/P&gt;&lt;P&gt;You must deploy the jce policy on every cluster nodes if you are using built-in openjdk.&lt;/P&gt;&lt;P&gt;Please follow the steps.&lt;/P&gt;&lt;P&gt;[root@hostname]# locate local_policy.jar&lt;/P&gt;&lt;P&gt;[root@hostname]#&amp;nbsp;&lt;SPAN&gt;wget --no-check-certificate --no-cookies --header "Cookie: oraclelicense=accept-securebackup-cookie" "&lt;A href="http://download.oracle.com/otn-pub/java/jce/8/jce_policy-8.zip" target="_blank"&gt;http://download.oracle.com/otn-pub/java/jce/8/jce_policy-8.zip&lt;/A&gt;"&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;[root@hostname]#&amp;nbsp;&lt;SPAN&gt;unzip -o -j -q jce_policy-8.zip &lt;/SPAN&gt;&lt;SPAN class="hljs-_"&gt;-d&amp;nbsp;/usr/jdk64/jdk1.8.0_112/jre/lib/security/&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="hljs-_"&gt;[root@hostname]# ambari-server rstart&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="hljs-_"&gt;Now test the connection. Hopes it will resolves the issue.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 06 Apr 2021 05:51:58 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Kerberos-KDC-not-reachable/m-p/314082#M225883</guid>
      <dc:creator>alam_shakeen</dc:creator>
      <dc:date>2021-04-06T05:51:58Z</dc:date>
    </item>
  </channel>
</rss>

