<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>question Re: Running into auth_to_local rule issue during  Livy kerberos authentication in Support Questions</title>
    <link>https://community.cloudera.com/t5/Support-Questions/Running-into-auth-to-local-rule-issue-during-Livy-kerberos/m-p/296835#M218447</link>
    <description>&lt;P&gt;Thanks Bender.&amp;nbsp; I appreciate the response.&amp;nbsp; Just want to clarify a few things..&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;* Livy itself is running as&amp;nbsp;&lt;SPAN&gt;livyblauser@COMPANY.PRI&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;* mzeoli@COMPANY.PRI&amp;nbsp;is the user hitting the livy Web UI.&lt;/P&gt;&lt;P&gt;* Both livyblauser and mzeoli are AD accounts and have rights on the edge node livy is running on (nydc-pblalivy01, which is same box the HTTP service principal is for)&lt;/P&gt;&lt;P&gt;* Both have permission to read krb5.conf&amp;nbsp; &amp;nbsp;(its world readable, though I'm not sure why / how something would be hitting krb5.conf as mzeoli, since mzeoli is just the web UI user and should not own any process.&amp;nbsp; Or perhaps I misunderstood you)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Given that this works...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;[livyblauser@nydc-pblalivy01 hadoop]$ hadoop org.apache.hadoop.security.HadoopKerberosName mzeoli@COMPANY.PRI
Name: mzeoli@COMPANY.PRI to mzeoli&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;....It really feels like Livy isn't finding the rules it would expect to find, though I see the correct rules in /etc/hadoop/conf/core-site.xml.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;&amp;lt;name&amp;gt;hadoop.security.auth_to_local&amp;lt;/name&amp;gt;
&amp;lt;value&amp;gt;
RULE:[1:$1@$0](.*@\QBD.COMPANY.PRI\E$)s/@\QBD.COMPANY.PRI\E$//
RULE:[2:$1@$0](.*@\QBD.COMPANY.PRI\E$)s/@\QBD.COMPANY.PRI\E$//
RULE:[1:$1@$0](.*@\QCOMPANY.PRI\E$)s/@\QCOMPANY.PRI\E$//
RULE:[2:$1@$0](.*@\QCOMPANY.PRI\E$)s/@\QCOMPANY.PRI\E$//
DEFAULT
&amp;lt;/value&amp;gt;&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Mike&lt;/P&gt;</description>
    <pubDate>Thu, 28 May 2020 20:41:12 GMT</pubDate>
    <dc:creator>MikeZ</dc:creator>
    <dc:date>2020-05-28T20:41:12Z</dc:date>
  </channel>
</rss>

