<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>question Re: webHDFS 403 error in Support Questions</title>
    <link>https://community.cloudera.com/t5/Support-Questions/webHDFS-403-error/m-p/242316#M204119</link>
    <description>&lt;P&gt;&lt;EM&gt;&lt;A href="https://community.hortonworks.com/questions/232883/@Javert%20Kirilov"&gt;@Javert Kirilov&lt;/A&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;I have just completed the kerberization of a Single node Centos 7 HDP3.1.0.0 running Ambari 2.7.3.0 everything went as planned no hiccups. &lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;See attached screenshots&lt;BR /&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;krb5.conf&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;PRE&gt;&lt;EM&gt;[libdefaults]
  renew_lifetime = 7d
  forwardable = true
  default_realm = UGANDA.UG
  ticket_lifetime = 24h
  dns_lookup_realm = false
  dns_lookup_kdc = false
  default_ccache_name = /tmp/krb5cc_%{uid}
  #default_tgs_enctypes = aes des3-cbc-sha1 rc4 des-cbc-md5
  #default_tkt_enctypes = aes des3-cbc-sha1 rc4 des-cbc-md5
[domain_realm]
  .uganda.ug = UGANDA.UG
  uganda.ug = UGANDA.UG
[logging]
  default = FILE:/var/log/krb5kdc.log
  admin_server = FILE:/var/log/kadmind.log
  kdc = FILE:/var/log/krb5kdc.log
[realms]
  UGANDA.UG = {
    admin_server = pawor.uganda.ug
    kdc = pawor.uganda.ug
  }&lt;/EM&gt;&lt;/PRE&gt;&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;kadm5.acl&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;PRE&gt;&lt;EM&gt;*/admin@UGANDA.UG       *&lt;/EM&gt;&lt;/PRE&gt;&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;kdc.conf&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;PRE&gt;&lt;EM&gt;[kdcdefaults]
 kdc_ports = 88
 kdc_tcp_ports = 88
[realms]
 UGANDA.UG = {
  #master_key_type = aes256-cts
  acl_file = /var/kerberos/krb5kdc/kadm5.acl
  dict_file = /usr/share/dict/words
  admin_keytab = /var/kerberos/krb5kdc/kadm5.keytab
  supported_enctypes = aes256-cts:normal aes128-cts:normal des3-hmac-sha1:normal arcfour-hmac:normal camellia256-cts:normal camellia128-cts:normal des-hmac-sha1:normal des-cbc-md5:normal des-cbc-crc:normal
 }&lt;/EM&gt;&lt;/PRE&gt;&lt;P&gt;&lt;EM&gt;To help in the diagnostics can you align your configuration to mine mapping your REALM and Server values and retest!  Can you try start the services manually, run the &lt;STRONG&gt;start date nodes&lt;/STRONG&gt; command on all the data nodes&lt;/EM&gt;&lt;/P&gt;&lt;PRE&gt;&lt;EM&gt;su -l hdfs -c "/usr/hdp/current/hadoop-hdfs-namenode/../hadoop/sbin/hadoop-daemon.sh start secondarynamenode"
su -l hdfs -c "/usr/hdp/current/hadoop-hdfs-datanode/../hadoop/sbin/hadoop-daemon.sh start datanode"&lt;/EM&gt;&lt;/PRE&gt;&lt;P&gt;&lt;EM&gt;Take a keen interest in the supported_enctypes  and compare with your cluster I don't think adding all the encryption types will help:-)&lt;/EM&gt;&lt;/P&gt;&lt;BR /&gt;&lt;IMG src="https://community.cloudera.com/t5/image/serverpage/image-id/8019i1418EA7B566C5789/image-size/large?v=1.0&amp;amp;px=999" border="0" alt="kirilov02.png" title="kirilov02.png" /&gt;&lt;IMG src="https://community.cloudera.com/t5/image/serverpage/image-id/8021iD3795A5C08F168F5/image-size/large?v=1.0&amp;amp;px=999" border="0" alt="kirilov04.png" title="kirilov04.png" /&gt;&lt;IMG src="https://community.cloudera.com/t5/image/serverpage/image-id/8022i7A29D8BB2485DA8D/image-size/large?v=1.0&amp;amp;px=999" border="0" alt="kirilov03.png" title="kirilov03.png" /&gt;&lt;IMG src="https://community.cloudera.com/t5/image/serverpage/image-id/8024i27954A97CEB9A257/image-size/large?v=1.0&amp;amp;px=999" border="0" alt="kirilov01.png" title="kirilov01.png" /&gt;</description>
    <pubDate>Thu, 17 Jan 2019 08:29:35 GMT</pubDate>
    <dc:creator>Shelton</dc:creator>
    <dc:date>2019-01-17T08:29:35Z</dc:date>
  </channel>
</rss>

