<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>question GSS exception error seen in a scenario even after having valid kerberos ticket in Support Questions</title>
    <link>https://community.cloudera.com/t5/Support-Questions/GSS-exception-error-seen-in-a-scenario-even-after-having/m-p/231196#M193040</link>
    <description>&lt;P&gt;We have a application which ingest files from LOCAL file system to HDFS in AD kerberos enabled environment . This basically moves files from Local directory to HDFS path. Once the ingestion process start , after 20 hours, we see the below error given randomly and after sometime, we see the error continuously . And finally, no files are moved. &lt;/P&gt;&lt;P&gt;Error :&lt;/P&gt;&lt;P&gt;java.io.IOException: java.io.IOException: java.io.IOException: Failed on local exception: java.io.IOException: javax.security.sasl.SaslException: GSS initiate failed [Caused by GSSException: No valid credentials provided (Mechanism level: Failed to find any Kerberos tgt)]; Host Details : local host is: "example1.com/xxxxx"; destination host is: "example2.com":8020; &lt;/P&gt;&lt;P&gt;We have the application running  in two environment i.e, Env-1 and Env-2 . &lt;/P&gt;&lt;P&gt;The same ingestion process is working fine without any error in Env-1 , and in Env-2  we see the GSS exception error .&lt;/P&gt;&lt;P&gt;There is difference of load and incoming files in Env-1 and Env-2 . &lt;/P&gt;&lt;P&gt;Env-1 - Per day , 5 files are moved to HDFS and without any error .And the same process goes on everyday.&lt;/P&gt;&lt;P&gt;Env-2 - Per 5 minute , 6000 files are moved to HDFS and the GSS exception error is seen after 20 hours. 6000 files are moved into HDFS from 42 different directories  simultaneously and total number of threads used are 150 . At a time, 150 files can be moved simultaneously , once the threads are released, it will pick the next files. Hence, the process goes on.&lt;/P&gt;&lt;P&gt;Can anyone comment on the below concern and issue seen :&lt;/P&gt;&lt;P&gt;1. Is there something to do with load in KDC server.&lt;/P&gt;&lt;P&gt;2. Are there any parameters in AD server which  restrict the number of count of TGT  to be generated  from KDC at a time.&lt;/P&gt;&lt;P&gt;3. Is there something to do with Kerberos tolerance time. In AD server, Maximum tolerance time is set to 5 min.&lt;/P&gt;&lt;P&gt;4. Please suggest If any parameters need to be added in krb5.conf to handle load and handle huge number of requests incoming to AD at a time. &lt;/P&gt;&lt;P&gt;We had checked the below in AD server and Env-2 :&lt;/P&gt;&lt;P&gt;1. AD server and Env-2 time are in sync.&lt;/P&gt;&lt;P&gt;2. Kerberos ticket is not expired. We have set a cron job to renew kerberos ticket every 4 hours. &lt;/P&gt;&lt;P&gt;3. Lifetime of ticket is set in krb5.conf accordingly : &lt;/P&gt;&lt;P&gt;renew_lifetime = 7d&lt;/P&gt;&lt;P&gt;ticket_lifetime = 24h&lt;/P&gt;&lt;P&gt;Can anyone suggest what might be the issue.&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;</description>
    <pubDate>Fri, 16 Sep 2022 12:40:31 GMT</pubDate>
    <dc:creator>vishakhaa9</dc:creator>
    <dc:date>2022-09-16T12:40:31Z</dc:date>
  </channel>
</rss>

