<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>question Re: HDFS is not accessible from an user after kerberos implementation in Support Questions</title>
    <link>https://community.cloudera.com/t5/Support-Questions/HDFS-is-not-accessible-from-an-user-after-kerberos/m-p/317541#M227214</link>
    <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/20288"&gt;@Shelton&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#FF9900"&gt;[konar@simba ~]$ kinit -kt konar.keytab konar@KENYA.KE&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;The above should throw any error&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Now validate the user has a valid ticket&lt;/P&gt;&lt;P&gt;&lt;FONT color="#FF9900"&gt;[konar@simba ~]$ klist&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#FF9900"&gt;Ticket cache: FILE:/tmp/krb5cc_1024&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#FF9900"&gt;Default principal: konar@KENYA.KE&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#FF9900"&gt;Valid starting Expires Service principal&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#FF9900"&gt;08/25/2019 18:53:40 08/26/2019 18:53:40 krbtgt/KENYA.KE@KENYA.KE&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;Bravo you have a valid ticket and hence access to the cluster let's validate that the below&amp;nbsp; HDFS list&amp;nbsp; directory should succeed&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;I am getting following error after executing kinit -kt command for hive user =&lt;BR /&gt;&lt;BR /&gt;[hive@server-hdp ~]$ kinit -kt hive.keytab hive@MYDOMAIN.COM&lt;BR /&gt;kinit: Password incorrect while getting initial credentials&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Pls suggest how to solve this issue thanks.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My krb5.conf =&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[hive@server-hdp ~]$ cat /etc/krb5.conf

[libdefaults]
  #renew_lifetime = 7d
  forwardable = true
  default_realm = MYDOMAIN.COM
  ticket_lifetime = 24h
  dns_lookup_realm = false
  dns_lookup_kdc = false
  default_ccache_name = /tmp/krb5cc_%{uid}
  #default_tgs_enctypes = aes des3-cbc-sha1 rc4 des-cbc-md5
  #default_tkt_enctypes = aes des3-cbc-sha1 rc4 des-cbc-md5

[domain_realm]
  mydomain.com = MYDOMAIN.COM

[logging]
  default = FILE:/var/log/krb5kdc.log
  admin_server = FILE:/var/log/kadmind.log
  kdc = FILE:/var/log/krb5kdc.log

[realms]
  MYDOMAIN.COM = {
    admin_server = server-hdp.mydomain.com
    kdc = server-hdp.mydomain.com
  }&lt;/LI-CODE&gt;&lt;P&gt;keytab works for user1 &amp;amp; user1 can access hdfs without any issue.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Amey.&lt;/P&gt;</description>
    <pubDate>Wed, 02 Jun 2021 10:26:43 GMT</pubDate>
    <dc:creator>dmharshit</dc:creator>
    <dc:date>2021-06-02T10:26:43Z</dc:date>
  </channel>
</rss>

