<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>question Re: CDH 6.3 YARN - Enabling SPNEGO causes HTTP ERROR 500 in Support Questions</title>
    <link>https://community.cloudera.com/t5/Support-Questions/CDH-6-3-YARN-Enabling-SPNEGO-causes-HTTP-ERROR-500/m-p/295530#M217785</link>
    <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/31473"&gt;@matagyula&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thank you for your feedback on the proposed actions and for accepting the reply as the solution! It will help Community Members facing with similar issues to find the answer faster.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Üdvözlettel:&lt;/P&gt;&lt;P&gt;Ferenc&lt;/P&gt;</description>
    <pubDate>Wed, 06 May 2020 14:57:25 GMT</pubDate>
    <dc:creator>Bender</dc:creator>
    <dc:date>2020-05-06T14:57:25Z</dc:date>
    <item>
      <title>CDH 6.3 YARN - Enabling SPNEGO causes HTTP ERROR 500</title>
      <link>https://community.cloudera.com/t5/Support-Questions/CDH-6-3-YARN-Enabling-SPNEGO-causes-HTTP-ERROR-500/m-p/295440#M217746</link>
      <description>&lt;P&gt;Greetings,&lt;/P&gt;
&lt;P&gt;After enabling "Kerberos Authentication for HTTP Web-Consoles" for YARN the Resource Manager WebUI and the HistoryServer Web UI become inaccessible with a valid Kerberos ticket (without a ticket the UI correctly gives the "Authentication required" HTTP 401 error message).&lt;/P&gt;
&lt;P&gt;Navigating to either of the interfaces returns the following error:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;HTTP ERROR 500

Problem accessing /jobhistory. Reason:

    Server Error

Caused by:

java.lang.IllegalArgumentException: Empty key
	at javax.crypto.spec.SecretKeySpec.&amp;lt;init&amp;gt;(SecretKeySpec.java:96)
	at org.apache.hadoop.security.authentication.util.Signer.computeSignature(Signer.java:93)
	at org.apache.hadoop.security.authentication.util.Signer.sign(Signer.java:59)
	at org.apache.hadoop.security.authentication.server.AuthenticationFilter.doFilter(AuthenticationFilter.java:587)
	at org.eclipse.jetty.servlet.ServletHandler$CachedChain.doFilter(ServletHandler.java:1767)
	at org.apache.hadoop.http.HttpServer2$QuotingInputFilter.doFilter(HttpServer2.java:1553)
	at org.eclipse.jetty.servlet.ServletHandler$CachedChain.doFilter(ServletHandler.java:1767)
	at org.apache.hadoop.http.NoCacheFilter.doFilter(NoCacheFilter.java:45)
	at org.eclipse.jetty.servlet.ServletHandler$CachedChain.doFilter(ServletHandler.java:1767)
	at org.eclipse.jetty.servlet.ServletHandler.doHandle(ServletHandler.java:583)
	at org.eclipse.jetty.server.handler.ScopedHandler.handle(ScopedHandler.java:143)
	at org.eclipse.jetty.security.SecurityHandler.handle(SecurityHandler.java:548)
	at org.eclipse.jetty.server.session.SessionHandler.doHandle(SessionHandler.java:226)
	at org.eclipse.jetty.server.handler.ContextHandler.doHandle(ContextHandler.java:1180)
	at org.eclipse.jetty.servlet.ServletHandler.doScope(ServletHandler.java:513)
	at org.eclipse.jetty.server.session.SessionHandler.doScope(SessionHandler.java:185)
	at org.eclipse.jetty.server.handler.ContextHandler.doScope(ContextHandler.java:1112)
	at org.eclipse.jetty.server.handler.ScopedHandler.handle(ScopedHandler.java:141)
	at org.eclipse.jetty.server.handler.HandlerCollection.handle(HandlerCollection.java:119)
	at org.eclipse.jetty.server.handler.HandlerWrapper.handle(HandlerWrapper.java:134)
	at org.eclipse.jetty.server.Server.handle(Server.java:539)
	at org.eclipse.jetty.server.HttpChannel.handle(HttpChannel.java:333)
	at org.eclipse.jetty.server.HttpConnection.onFillable(HttpConnection.java:251)
	at org.eclipse.jetty.io.AbstractConnection$ReadCallback.succeeded(AbstractConnection.java:283)
	at org.eclipse.jetty.io.FillInterest.fillable(FillInterest.java:108)
	at org.eclipse.jetty.io.ssl.SslConnection.onFillable(SslConnection.java:259)
	at org.eclipse.jetty.io.AbstractConnection$ReadCallback.succeeded(AbstractConnection.java:283)
	at org.eclipse.jetty.io.FillInterest.fillable(FillInterest.java:108)
	at org.eclipse.jetty.io.SelectChannelEndPoint$2.run(SelectChannelEndPoint.java:93)
	at org.eclipse.jetty.util.thread.strategy.ExecuteProduceConsume.executeProduceConsume(ExecuteProduceConsume.java:303)
	at org.eclipse.jetty.util.thread.strategy.ExecuteProduceConsume.produceConsume(ExecuteProduceConsume.java:148)
	at org.eclipse.jetty.util.thread.strategy.ExecuteProduceConsume.run(ExecuteProduceConsume.java:136)
	at org.eclipse.jetty.util.thread.QueuedThreadPool.runJob(QueuedThreadPool.java:671)
	at org.eclipse.jetty.util.thread.QueuedThreadPool$2.run(QueuedThreadPool.java:589)
	at java.lang.Thread.run(Thread.java:748)&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;Meanwhile, in Cloudera Manager the YARN health checks report bad status for every component.&amp;nbsp; In the YARN logs (hadoop-cmf-yarn-RESOURCEMANAGER) the following WARN messages appear:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;2020-05-05 11:56:42,835 WARN org.eclipse.jetty.servlet.ServletHandler: /jmx
java.lang.IllegalArgumentException: Empty key
...
2020-05-05 11:57:56,461 WARN org.eclipse.jetty.servlet.ServletHandler: /ws/v1/cluster/info
java.lang.IllegalArgumentException: Empty key
        at javax.crypto.spec.SecretKeySpec.&amp;lt;init&amp;gt;(SecretKeySpec.java:96)
        at org.apache.hadoop.security.authentication.util.Signer.computeSignature(Signer.java:93)
        at org.apache.hadoop.security.authentication.util.Signer.sign(Signer.java:59)
        at org.apache.hadoop.security.authentication.server.AuthenticationFilter.doFilter(AuthenticationFilter.java:587)
        at org.apache.hadoop.yarn.server.security.http.RMAuthenticationFilter.doFilter(RMAuthenticationFilter.java:82)
        at org.eclipse.jetty.servlet.ServletHandler$CachedChain.doFilter(ServletHandler.java:1767)
        at org.apache.hadoop.http.HttpServer2$QuotingInputFilter.doFilter(HttpServer2.java:1553)
        at org.eclipse.jetty.servlet.ServletHandler$CachedChain.doFilter(ServletHandler.java:1767)
        at org.apache.hadoop.http.NoCacheFilter.doFilter(NoCacheFilter.java:45)
        at org.eclipse.jetty.servlet.ServletHandler$CachedChain.doFilter(ServletHandler.java:1767)
        at org.eclipse.jetty.servlet.ServletHandler.doHandle(ServletHandler.java:583)
        at org.eclipse.jetty.server.handler.ScopedHandler.handle(ScopedHandler.java:143)
        at org.eclipse.jetty.security.SecurityHandler.handle(SecurityHandler.java:548)
        at org.eclipse.jetty.server.session.SessionHandler.doHandle(SessionHandler.java:226)
        at org.eclipse.jetty.server.handler.ContextHandler.doHandle(ContextHandler.java:1180)
        at org.eclipse.jetty.servlet.ServletHandler.doScope(ServletHandler.java:513)
        at org.eclipse.jetty.server.session.SessionHandler.doScope(SessionHandler.java:185)
        at org.eclipse.jetty.server.handler.ContextHandler.doScope(ContextHandler.java:1112)
        at org.eclipse.jetty.server.handler.ScopedHandler.handle(ScopedHandler.java:141)
        at org.eclipse.jetty.server.handler.HandlerCollection.handle(HandlerCollection.java:119)
        at org.eclipse.jetty.server.handler.HandlerWrapper.handle(HandlerWrapper.java:134)
        at org.eclipse.jetty.server.Server.handle(Server.java:536)
        at org.eclipse.jetty.server.HttpChannel.handle(HttpChannel.java:333)
        at org.eclipse.jetty.server.HttpConnection.onFillable(HttpConnection.java:251)
        at org.eclipse.jetty.io.AbstractConnection$ReadCallback.succeeded(AbstractConnection.java:283)
        at org.eclipse.jetty.io.FillInterest.fillable(FillInterest.java:108)
        at org.eclipse.jetty.io.ssl.SslConnection.onFillable(SslConnection.java:259)
        at org.eclipse.jetty.io.AbstractConnection$ReadCallback.succeeded(AbstractConnection.java:283)
        at org.eclipse.jetty.io.FillInterest.fillable(FillInterest.java:108)
        at org.eclipse.jetty.io.SelectChannelEndPoint$2.run(SelectChannelEndPoint.java:93)
        at org.eclipse.jetty.util.thread.strategy.ExecuteProduceConsume.executeProduceConsume(ExecuteProduceConsume.java:303)
        at org.eclipse.jetty.util.thread.strategy.ExecuteProduceConsume.produceConsume(ExecuteProduceConsume.java:148)
        at org.eclipse.jetty.util.thread.strategy.ExecuteProduceConsume.run(ExecuteProduceConsume.java:136)
        at org.eclipse.jetty.util.thread.QueuedThreadPool.runJob(QueuedThreadPool.java:671)
        at org.eclipse.jetty.util.thread.QueuedThreadPool$2.run(QueuedThreadPool.java:589)
        at java.lang.Thread.run(Thread.java:748)&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The cluster is Kerberized, TLS/SSL is enabled. As a side note, SPNEGO is enabled for the HBase WebUI and that works without issues.&lt;/P&gt;
&lt;P&gt;Looking through the documentation and various online forums I only found hints that suggested adding the Service Monitor Kerberos Principal to hdfs-site.xml, but obviously my issue is with Yarn, not HDFS.&lt;/P&gt;
&lt;P&gt;Thank you for your help in advance!&lt;/P&gt;
&lt;P&gt;Kind regards,&lt;/P&gt;
&lt;P&gt;Julius&lt;/P&gt;</description>
      <pubDate>Tue, 05 May 2020 12:45:09 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/CDH-6-3-YARN-Enabling-SPNEGO-causes-HTTP-ERROR-500/m-p/295440#M217746</guid>
      <dc:creator>matagyula</dc:creator>
      <dc:date>2020-05-05T12:45:09Z</dc:date>
    </item>
    <item>
      <title>Re: CDH 6.3 YARN - Enabling SPNEGO causes HTTP ERROR 500</title>
      <link>https://community.cloudera.com/t5/Support-Questions/CDH-6-3-YARN-Enabling-SPNEGO-causes-HTTP-ERROR-500/m-p/295509#M217774</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/31473"&gt;@matagyula&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thank you for sharing with us the exceptions you are getting after enabling for&amp;nbsp;&lt;SPAN&gt;"Kerberos Authentication for HTTP Web-Consoles" for YARN. You will need to configure SPNEGO [1] and enable authentication for HDFS too [2] to overcome the issues described.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please let us know if the proposed changes resolved your issue!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you:&lt;BR /&gt;Ferenc&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;[1]&amp;nbsp;&lt;A href="https://docs.cloudera.com/documentation/enterprise/latest/topics/cdh_sg_browser_access_kerberos_protected_url.html" target="_blank" rel="noopener"&gt;https://docs.cloudera.com/documentation/enterprise/latest/topics/cdh_sg_browser_access_kerberos_protected_url.html&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;[2]&amp;nbsp;CM -&amp;gt; HDFS service -&amp;gt; search for and enable "Enable Kerberos Authentication for HTTP Web-Consoles", deploy client configuration, restart HDFS and YARN services&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 06 May 2020 09:02:48 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/CDH-6-3-YARN-Enabling-SPNEGO-causes-HTTP-ERROR-500/m-p/295509#M217774</guid>
      <dc:creator>Bender</dc:creator>
      <dc:date>2020-05-06T09:02:48Z</dc:date>
    </item>
    <item>
      <title>Re: CDH 6.3 YARN - Enabling SPNEGO causes HTTP ERROR 500</title>
      <link>https://community.cloudera.com/t5/Support-Questions/CDH-6-3-YARN-Enabling-SPNEGO-causes-HTTP-ERROR-500/m-p/295529#M217784</link>
      <description>&lt;P&gt;Dear &lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/12296"&gt;@Bender&lt;/a&gt; ,&lt;/P&gt;&lt;P&gt;Thank you very much for your prompt response. Enabling SPNEGO for HDFS did indeed solve our issue with YARN. The UIs are now accessible again (with a valid Kerberos ticket).&lt;/P&gt;&lt;P&gt;Üdvözlettel &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Gyuszi&lt;/P&gt;</description>
      <pubDate>Wed, 06 May 2020 14:38:52 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/CDH-6-3-YARN-Enabling-SPNEGO-causes-HTTP-ERROR-500/m-p/295529#M217784</guid>
      <dc:creator>matagyula</dc:creator>
      <dc:date>2020-05-06T14:38:52Z</dc:date>
    </item>
    <item>
      <title>Re: CDH 6.3 YARN - Enabling SPNEGO causes HTTP ERROR 500</title>
      <link>https://community.cloudera.com/t5/Support-Questions/CDH-6-3-YARN-Enabling-SPNEGO-causes-HTTP-ERROR-500/m-p/295530#M217785</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/31473"&gt;@matagyula&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thank you for your feedback on the proposed actions and for accepting the reply as the solution! It will help Community Members facing with similar issues to find the answer faster.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Üdvözlettel:&lt;/P&gt;&lt;P&gt;Ferenc&lt;/P&gt;</description>
      <pubDate>Wed, 06 May 2020 14:57:25 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/CDH-6-3-YARN-Enabling-SPNEGO-causes-HTTP-ERROR-500/m-p/295530#M217785</guid>
      <dc:creator>Bender</dc:creator>
      <dc:date>2020-05-06T14:57:25Z</dc:date>
    </item>
  </channel>
</rss>

