<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>question Failing to connect to KDC during enable kerberos, CA certificate has been imported into Ambari &amp; Java trust stores in Support Questions</title>
    <link>https://community.cloudera.com/t5/Support-Questions/Failing-to-connect-to-KDC-during-enable-kerberos-CA/m-p/237339#M199152</link>
    <description>&lt;P&gt;Hi there good folks &lt;/P&gt;&lt;P&gt;We are trying to enable HDP kerberos integration, but we are getting stuck in the Wizard during "test kerberos client".&lt;/P&gt;&lt;PRE&gt;Failed to connect to KDC - Failed to communicate with the Active Directory at ldaps://ad-serverxxxx:636: simple bind failed: ad-serverxxxx:636
Make sure the server's SSL certificate or CA certificates have been imported into Ambari's truststore.&lt;/PRE&gt;&lt;P&gt;Verified both JAVA and AMBARI CA certs in Trust Stores. &lt;/P&gt;&lt;P&gt; $JAVA_HOME/bin/keytool -list -v -keystore $JAVA_HOME/lib/security/cacerts &amp;gt; /tmp/05122018_java_truststore_cert&lt;/P&gt;&lt;P&gt;--Did the same writing out the Ambari trust store cert. &lt;/P&gt;&lt;P&gt;The certs are there and confirmed not yet expired.&lt;/P&gt;&lt;P&gt;Next try to test the service account used and ensure the accounts works fine:&lt;/P&gt;&lt;P&gt;ldapsearch
-x -LLL -h ad-serverxxxxx -D
'CN=S_LDAP_HortonWrks_DEV,OU=Admin,OU=xxx,DC=xxxxxxx,DC=xxx,DC=xxx' -b
"OU=HDP,DC=xxx,DC=xxx,DC=xxx" -W&lt;/P&gt;&lt;P&gt;Queries for password , authenticates and returned successfully so the account seems fine. &lt;/P&gt;&lt;P&gt;The irony is that we did this just a few weeks before and didn't have issues but had to tear down and rebuild due to another un-related issue.&lt;/P&gt;&lt;P&gt;Last time we got stuck at the same place but then import the DC's cert into the JAVA cacerts trust store resolved the issue.&lt;/P&gt;&lt;P&gt; Now for some reason it's not. The master is a clean new server, the slaves are the old machines that have been cleared up using this blog. &lt;/P&gt;&lt;P&gt;&lt;A href="https://community.hortonworks.com/articles/97489/completely-uninstall-hdp-and-ambari.html" target="_blank"&gt;https://community.hortonworks.com/articles/97489/completely-uninstall-hdp-and-ambari.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Any help would be highly appreciated. Drawing a bit of a blank after all the troubleshooting done so far.&lt;/P&gt;&lt;P&gt;Kind Regards&lt;/P&gt;</description>
    <pubDate>Wed, 05 Dec 2018 23:18:33 GMT</pubDate>
    <dc:creator>nico_jordaan</dc:creator>
    <dc:date>2018-12-05T23:18:33Z</dc:date>
  </channel>
</rss>

