<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>question Re: After Kerberos, HBase doesn't start due to AuthFailed for /hbase-secure in Support Questions</title>
    <link>https://community.cloudera.com/t5/Support-Questions/After-Kerberos-HBase-doesn-t-start-due-to-AuthFailed-for/m-p/141518#M104118</link>
    <description>&lt;P&gt;Thank you &lt;A rel="user" href="https://community.cloudera.com/users/223/jelser.html" nodeid="223"&gt;@Josh Elser&lt;/A&gt; &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 08 Dec 2016 07:33:18 GMT</pubDate>
    <dc:creator>raju_ramakrishn</dc:creator>
    <dc:date>2016-12-08T07:33:18Z</dc:date>
    <item>
      <title>After Kerberos, HBase doesn't start due to AuthFailed for /hbase-secure</title>
      <link>https://community.cloudera.com/t5/Support-Questions/After-Kerberos-HBase-doesn-t-start-due-to-AuthFailed-for/m-p/141514#M104114</link>
      <description>&lt;P&gt;HBase is throwing an exception after enabling Kerberos-&lt;/P&gt;&lt;BLOCKQUOTE&gt;&lt;P&gt;2016-12-07 10:33:07,963 ERROR [main-SendThread(y.server.com:2181)] client.ZooKeeperSaslClient: SASL authentication failed using login context 'Client'.&lt;/P&gt;&lt;P&gt;2016-12-07 10:33:08,068 ERROR [main] master.HMasterCommandLine: Master exiting&lt;/P&gt;&lt;P&gt;java.lang.RuntimeException: Failed construction of Master: class org.apache.hadoop.hbase.master.HMaster&lt;/P&gt;&lt;P&gt;at org.apache.hadoop.hbase.master.HMaster.constructMaster(HMaster.java:2290)&lt;/P&gt;&lt;P&gt;at org.apache.hadoop.hbase.master.HMasterCommandLine.startMaster(HMasterCommandLine.java:233)&lt;/P&gt;&lt;P&gt;at org.apache.hadoop.hbase.master.HMasterCommandLine.run(HMasterCommandLine.java:139)&lt;/P&gt;&lt;P&gt;at org.apache.hadoop.util.ToolRunner.run(ToolRunner.java:70)&lt;/P&gt;&lt;P&gt;at org.apache.hadoop.hbase.util.ServerCommandLine.doMain(ServerCommandLine.java:126)&lt;/P&gt;&lt;P&gt;at org.apache.hadoop.hbase.master.HMaster.main(HMaster.java:2304)&lt;/P&gt;&lt;P&gt;Caused by: org.apache.zookeeper.KeeperException$AuthFailedException: KeeperErrorCode = AuthFailed for /hbase-secure&lt;/P&gt;&lt;P&gt;at org.apache.zookeeper.KeeperException.create(KeeperException.java:123)&lt;/P&gt;&lt;P&gt;at org.apache.zookeeper.KeeperException.create(KeeperException.java:51)&lt;/P&gt;&lt;P&gt;at org.apache.zookeeper.ZooKeeper.create(ZooKeeper.java:783)&lt;/P&gt;&lt;P&gt;at org.apache.hadoop.hbase.zookeeper.RecoverableZooKeeper.createNonSequential(RecoverableZooKeeper.java:576)&lt;/P&gt;&lt;P&gt;at org.apache.hadoop.hbase.zookeeper.RecoverableZooKeeper.create(RecoverableZooKeeper.java:555)&lt;/P&gt;&lt;P&gt;at org.apache.hadoop.hbase.zookeeper.ZKUtil.createWithParents(ZKUtil.java:1313)&lt;/P&gt;&lt;P&gt;at org.apache.hadoop.hbase.zookeeper.ZKUtil.createWithParents(ZKUtil.java:1291)&lt;/P&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;I connected to zookepeer with the following command, and couldn't find the "hbase-secure" directory created. Only "hbase" directory exists - &lt;/P&gt;&lt;PRE&gt;/usr/hdp/current/zookeeper-client/bin/zkCli.sh -server &lt;A href="http://x.server.com/"&gt;x.server.com&lt;/A&gt;,&lt;A href="http://y.server.com/"&gt;y.server.com&lt;/A&gt;,&lt;A href="http://z.server.com/"&gt;z.server.com&lt;/A&gt; get /&lt;/PRE&gt;</description>
      <pubDate>Wed, 07 Dec 2016 18:05:04 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/After-Kerberos-HBase-doesn-t-start-due-to-AuthFailed-for/m-p/141514#M104114</guid>
      <dc:creator>raju_ramakrishn</dc:creator>
      <dc:date>2016-12-07T18:05:04Z</dc:date>
    </item>
    <item>
      <title>Re: After Kerberos, HBase doesn't start due to AuthFailed for /hbase-secure</title>
      <link>https://community.cloudera.com/t5/Support-Questions/After-Kerberos-HBase-doesn-t-start-due-to-AuthFailed-for/m-p/141515#M104115</link>
      <description>&lt;P&gt;Check the HBase master log for additional information about the ZooKeeper Kerberos login. You should see information shortly after the process starts which prints the ticket lifetime information. There may be other exceptions in the log about failure to login to Kerberos that result in this znode creation failing.&lt;/P&gt;</description>
      <pubDate>Thu, 08 Dec 2016 00:23:30 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/After-Kerberos-HBase-doesn-t-start-due-to-AuthFailed-for/m-p/141515#M104115</guid>
      <dc:creator>elserj</dc:creator>
      <dc:date>2016-12-08T00:23:30Z</dc:date>
    </item>
    <item>
      <title>Re: After Kerberos, HBase doesn't start due to AuthFailed for /hbase-secure</title>
      <link>https://community.cloudera.com/t5/Support-Questions/After-Kerberos-HBase-doesn-t-start-due-to-AuthFailed-for/m-p/141516#M104116</link>
      <description>&lt;P&gt;Thanks &lt;A rel="user" href="https://community.cloudera.com/users/223/jelser.html" nodeid="223"&gt;@Josh Elser&lt;/A&gt; &lt;/P&gt;&lt;P&gt;I analyzed the issue further, and found that the problem in Zookeeper SASL. After kerberos, Zookeeper is expecting the port number 2888-3888 to be opened between all the 3 Zookeper servers. However, I hadn't opened that range of ports. Hence SASL error was thrown even with a simple ./zkCli.sh command. I have asked the customer to open the port range.&lt;/P&gt;&lt;P&gt;Please let me know if this is not correct.&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Thu, 08 Dec 2016 04:16:24 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/After-Kerberos-HBase-doesn-t-start-due-to-AuthFailed-for/m-p/141516#M104116</guid>
      <dc:creator>raju_ramakrishn</dc:creator>
      <dc:date>2016-12-08T04:16:24Z</dc:date>
    </item>
    <item>
      <title>Re: After Kerberos, HBase doesn't start due to AuthFailed for /hbase-secure</title>
      <link>https://community.cloudera.com/t5/Support-Questions/After-Kerberos-HBase-doesn-t-start-due-to-AuthFailed-for/m-p/141517#M104117</link>
      <description>&lt;P&gt;Your terminology is off, but the explanation seems plausible :). 2888-3888 is the range used by ZK internal communication (ZK servers talking to each other). I can imagine that if ZK servers couldn't communicate with each other, ZK would not operate as expected. SASL is just way of performing authentication and has nothing to do with the low-level transport over the wire.&lt;/P&gt;</description>
      <pubDate>Thu, 08 Dec 2016 04:48:45 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/After-Kerberos-HBase-doesn-t-start-due-to-AuthFailed-for/m-p/141517#M104117</guid>
      <dc:creator>elserj</dc:creator>
      <dc:date>2016-12-08T04:48:45Z</dc:date>
    </item>
    <item>
      <title>Re: After Kerberos, HBase doesn't start due to AuthFailed for /hbase-secure</title>
      <link>https://community.cloudera.com/t5/Support-Questions/After-Kerberos-HBase-doesn-t-start-due-to-AuthFailed-for/m-p/141518#M104118</link>
      <description>&lt;P&gt;Thank you &lt;A rel="user" href="https://community.cloudera.com/users/223/jelser.html" nodeid="223"&gt;@Josh Elser&lt;/A&gt; &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 08 Dec 2016 07:33:18 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/After-Kerberos-HBase-doesn-t-start-due-to-AuthFailed-for/m-p/141518#M104118</guid>
      <dc:creator>raju_ramakrishn</dc:creator>
      <dc:date>2016-12-08T07:33:18Z</dc:date>
    </item>
  </channel>
</rss>

