<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>question Re: webHDFS 403 error in Support Questions</title>
    <link>https://community.cloudera.com/t5/Support-Questions/webHDFS-403-error/m-p/242319#M204122</link>
    <description>&lt;P&gt;&lt;A rel="user" href="https://community.cloudera.com/users/97392/ggoldman.html" nodeid="97392"&gt;@Geoffrey Goldman&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Important question (should I post it as a new question? It does kind of follow up from your latest comment, so I post it here): so how should ideally the "default_tkt_enctypes", "default_tgs_enctypes" and "permitted_enctypes" should look like for a normal HDP cluster (not a test sandbox), which would work 100% of the times and also provide high level security?&lt;/P&gt;&lt;P&gt;1. When I've tried the default suggested settings of "des3-cbc-sha1 des3-hmac-sha1 des3-cbc-sha1-kd", I would get errors that the security level was too low. I've then further added "aes256-cts-hmac-sha1-96", but it seems more than one decent enctype is required for proper encryption?&lt;/P&gt;&lt;P&gt;2. The default Kerberos settings, suggested by Ambari, also suggests "des3-cbc-sha1 des3-hmac-sha1 des3-cbc-sha1-kd", &lt;STRONG&gt;but comments it out by default, &lt;/STRONG&gt;so I guess it ends up using some default values, which doesn't seem stable (what if the default will change over time or new version of kerberos). &lt;/P&gt;&lt;P&gt;3. Now I've added all possible configs, &lt;EM&gt;"&lt;/EM&gt;&lt;EM&gt;aes256-cts-hmac-sha1-96 aes256-cts:normal aes128-cts:normal des3-hmac-sha1:normal arcfour-hmac:normal camellia256-cts:normal camellia128-cts:normal des-hmac-sha1:normal des-cbc-md5:normal des-cbc-crc:normal"&lt;/EM&gt;, but when using ``xst -k `` from ``kadmin`` service, it exports arounds 2-3 entries in the keytab with different encryptions, but not all 8+. Suggesting, that only some types are actually important. &lt;/P&gt;</description>
    <pubDate>Thu, 17 Jan 2019 17:20:02 GMT</pubDate>
    <dc:creator>mRabramS</dc:creator>
    <dc:date>2019-01-17T17:20:02Z</dc:date>
  </channel>
</rss>

