<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>question Re: Execution of '/usr/bin/kinit -kt /etc/security/keytabs/hdfs.headless.keytab hdfs-uktehdpprod@EUROPE.ODCORP.NET' returned 1. kinit: Clients credentials have been revoked while getting initial credentials in Support Questions</title>
    <link>https://community.cloudera.com/t5/Support-Questions/Execution-of-usr-bin-kinit-kt-etc-security-keytabs-hdfs/m-p/207196#M169157</link>
    <description>&lt;P&gt;&lt;EM&gt;@&lt;A href="https://community.hortonworks.com/users/2384/arjunm5573.html"&gt;arjun more&lt;/A&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;If you have KDC and AD integrated, this simply means the account to which the keytab is related has been disabled, locked, expired, or deleted. &lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;The AD service account should NEVER expire. &lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;If not could you validate the below steps &lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Make sure the&lt;STRONG&gt; [realms]&lt;/STRONG&gt; and&lt;STRONG&gt; [domain_realms] &lt;/STRONG&gt;entries in cat /etc/krb5.conf is correct. &lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Validate the contents of these 2 files&lt;STRONG&gt; /var/kerberos/krb5kdc/kdc.conf &lt;/STRONG&gt;, &lt;STRONG&gt;/var/kerberos/krb5kdc/kadm5.acl &lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Check the hdfs prinncipal&lt;/EM&gt;&lt;/P&gt;&lt;PRE&gt;&lt;EM&gt;# kadmin.local 
Authenticating as principal hdfs-uktehdpprod/admin@EUROPE.ODCORP.NET with password. 
kadmin.local: listprincs hdfs* 
hdfs-uktehdpprod@EUROPE.ODCORP.NET 
kadmin.local: &lt;/EM&gt;&lt;/PRE&gt;&lt;P&gt;&lt;EM&gt;Get the correct prncipal for hdfs &lt;/EM&gt;&lt;/P&gt;&lt;PRE&gt;&lt;EM&gt;# klist -kt /etc/security/keytabs/hdfs.headless.keytab 
Keytab name: FILE:/etc/security/keytabs/hdfs.headless.keytab 
KVNO Timestamp Principal ---- ------------------- ------------------------------------------------------ 
1 08/24/2017 15:42:23 hdfs-uktehdpprod@EUROPE.ODCORP.NET 
1 08/24/2017 15:42:23 hdfs-uktehdpprod@EUROPE.ODCORP.NET 
1 08/24/2017 15:42:23 hdfs-uktehdpprod@EUROPE.ODCORP.NET &lt;/EM&gt;&lt;/PRE&gt;&lt;P&gt;&lt;EM&gt;Try grabbing a valid Kerberos ticket &lt;/EM&gt;&lt;/P&gt;&lt;PRE&gt;&lt;EM&gt;# kinit -kt /etc/security/keytabs/hdfs.headless.keytab hdfs-uktehdpprod@EUROPE.ODCORP.NET &lt;/EM&gt;&lt;/PRE&gt;&lt;P&gt;&lt;EM&gt; Validate the avalability period &lt;/EM&gt;&lt;/P&gt;&lt;PRE&gt;&lt;EM&gt;# klist 
Ticket cache: FILE:/tmp/krb5cc_0 
Default principal: hdfs-uktehdpprod@EUROPE.ODCORP.NET 
Valid       starting      Expires              Service principal 
10/04/2017  19:36:12      10/05/2017 19:36:12 krbtgt/EUROPE.ODCORP.NET@EUROPE.ODCORP.NET&lt;/EM&gt;&lt;/PRE&gt;&lt;P&gt;&lt;EM&gt;Please revert&lt;/EM&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 05 Oct 2017 00:56:49 GMT</pubDate>
    <dc:creator>Shelton</dc:creator>
    <dc:date>2017-10-05T00:56:49Z</dc:date>
  </channel>
</rss>

