<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>question Re: CDP 7.1.6  Ranger KMS test conection failed &amp;quot; User:ranger not allowed to do 'GET_KEYS' &amp;quot; in Support Questions</title>
    <link>https://community.cloudera.com/t5/Support-Questions/CDP-7-1-6-Ranger-KMS-test-conection-failed-quot-User-ranger/m-p/319575#M227877</link>
    <description>&lt;P&gt;Thanks &lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/35149"&gt;@Scharan&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I don't think it's in sync since the test connection failed.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="kms-4.PNG" style="width: 999px;"&gt;&lt;img src="https://community.cloudera.com/t5/image/serverpage/image-id/31727i7830D9C1D0AA2157/image-size/large?v=v2&amp;amp;px=999" role="button" title="kms-4.PNG" alt="kms-4.PNG" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="kms-5.PNG" style="width: 999px;"&gt;&lt;img src="https://community.cloudera.com/t5/image/serverpage/image-id/31728i3BAAD3F141A67425/image-size/large?v=v2&amp;amp;px=999" role="button" title="kms-5.PNG" alt="kms-5.PNG" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="kms-6.PNG" style="width: 999px;"&gt;&lt;img src="https://community.cloudera.com/t5/image/serverpage/image-id/31730i5AFFC763DBAC65B1/image-size/large?v=v2&amp;amp;px=999" role="button" title="kms-6.PNG" alt="kms-6.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 30 Jun 2021 08:19:39 GMT</pubDate>
    <dc:creator>jakezhang</dc:creator>
    <dc:date>2021-06-30T08:19:39Z</dc:date>
    <item>
      <title>CDP 7.1.6  Ranger KMS test conection failed " User:ranger not allowed to do 'GET_KEYS' "</title>
      <link>https://community.cloudera.com/t5/Support-Questions/CDP-7-1-6-Ranger-KMS-test-conection-failed-quot-User-ranger/m-p/319359#M227772</link>
      <description>&lt;P&gt;Hello Gurus,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am having Ranger KMS test connection failed, it is POC test.&lt;/P&gt;&lt;P&gt;CDP 7.1.6 with Isilon OneFS v8.2.2.0, AD kerberos enabled.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Ranger KMS is up and running" style="width: 999px;"&gt;&lt;img src="https://community.cloudera.com/t5/image/serverpage/image-id/31695iE68C5057DF4B05B3/image-size/large?v=v2&amp;amp;px=999" role="button" title="KMS-1.PNG" alt="Ranger KMS is up and running" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;Ranger KMS is up and running&lt;/span&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="default policy login as keyadmin" style="width: 999px;"&gt;&lt;img src="https://community.cloudera.com/t5/image/serverpage/image-id/31696i4EADE29DA020C876/image-size/large?v=v2&amp;amp;px=999" role="button" title="KMS-2.PNG" alt="default policy login as keyadmin" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;default policy login as keyadmin&lt;/span&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="test connection failed" style="width: 999px;"&gt;&lt;img src="https://community.cloudera.com/t5/image/serverpage/image-id/31697iB6B39FC7CB3C938D/image-size/large?v=v2&amp;amp;px=999" role="button" title="KMS-3.PNG" alt="test connection failed" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;test connection failed&lt;/span&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Already added following lines in kms-site.xml ( added in Ranger KMS -configuration )&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;hadoop.kms.proxyuser.rangeradmin.hosts=* 
hadoop.kms.proxyuser.rangeradmin.groups=* 
hadoop.kms.proxyuser.rangeradmin.users=*&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Ranger KMS debug:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;2021-06-26 06:51:38,420 DEBUG org.apache.ranger.plugin.classloader.RangerPluginClassLoader: ==&amp;gt; RangerPluginClassLoader.deactivate()
2021-06-26 06:51:38,420 DEBUG org.apache.ranger.plugin.classloader.RangerPluginClassLoader: &amp;lt;== RangerPluginClassLoader.deactivate()
2021-06-26 06:51:38,420 ERROR org.apache.hadoop.crypto.key.kms.server.KMS: Exception in getkeyNames.
org.apache.hadoop.security.authorize.AuthorizationException: User:ranger not allowed to do 'GET_KEYS'
2021-06-26 06:51:38,420 WARN org.apache.hadoop.crypto.key.kms.server.KMS: User ranger (auth:PROXY) via rangeradmin/n02.py.local@PY.LOCAL (auth:KERBEROS) request GET http://n03.py.local:9292/kms/v1/keys/names?doAs=ranger caused exception.
org.apache.hadoop.security.authorize.AuthorizationException: User:ranger not allowed to do 'GET_KEYS'
2021-06-26 06:52:04,559 INFO org.apache.ranger.audit.provider.BaseAuditHandler: Audit Status Log: name=kms.async.summary.multi_dest.batch.solr, interval=01:00.003 minutes, events=1, deferredCount=1, totalEvents=3, totalDeferredCount=3
2021-06-26 06:52:04,560 INFO org.apache.ranger.audit.destination.SolrAuditDestination: Solr zkHosts=null, solrURLs=null, collectionName=ranger_audits
2021-06-26 06:52:04,560 ERROR org.apache.ranger.audit.queue.AuditFileSpool: Error sending logs to consumer. provider=kms.async.summary.multi_dest.batch, consumer=kms.async.summary.multi_dest.batch.solr
2021-06-26 06:52:04,560 INFO org.apache.ranger.audit.queue.AuditFileSpool: Destination is down. sleeping for 30000 milli seconds. indexQueue=0, queueName=kms.async.summary.multi_dest.batch, consumer=kms.async.summary.multi_dest.batch.solr
2021-06-26 06:52:04,691 INFO org.apache.ranger.audit.provider.BaseAuditHandler: Audit Status Log: name=kms.async.summary.multi_dest.batch.hdfs, interval=01:00.012 minutes, events=1, deferredCount=1, totalEvents=3, totalDeferredCount=3&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there anything mis-configured or need to be checked? Thank you&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best Regards,&lt;/P&gt;&lt;P&gt;Jake Zhang&lt;/P&gt;</description>
      <pubDate>Fri, 25 Jun 2021 23:25:46 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/CDP-7-1-6-Ranger-KMS-test-conection-failed-quot-User-ranger/m-p/319359#M227772</guid>
      <dc:creator>jakezhang</dc:creator>
      <dc:date>2021-06-25T23:25:46Z</dc:date>
    </item>
    <item>
      <title>Re: CDP 7.1.6  Ranger KMS test conection failed " User:ranger not allowed to do 'GET_KEYS' "</title>
      <link>https://community.cloudera.com/t5/Support-Questions/CDP-7-1-6-Ranger-KMS-test-conection-failed-quot-User-ranger/m-p/319367#M227779</link>
      <description>&lt;P&gt;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/31768"&gt;@jakezhang&lt;/a&gt;&amp;nbsp;Assign getkeys permission for ranger user in ranger policy&lt;/P&gt;</description>
      <pubDate>Sat, 26 Jun 2021 15:54:34 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/CDP-7-1-6-Ranger-KMS-test-conection-failed-quot-User-ranger/m-p/319367#M227779</guid>
      <dc:creator>Scharan</dc:creator>
      <dc:date>2021-06-26T15:54:34Z</dc:date>
    </item>
    <item>
      <title>Re: CDP 7.1.6  Ranger KMS test conection failed " User:ranger not allowed to do 'GET_KEYS' "</title>
      <link>https://community.cloudera.com/t5/Support-Questions/CDP-7-1-6-Ranger-KMS-test-conection-failed-quot-User-ranger/m-p/319372#M227782</link>
      <description>&lt;P&gt;Thanks.&lt;/P&gt;&lt;P&gt;However the permissions are already assigned in the default policy:&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp; cm_kms&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="jakezhang_0-1624755445124.png" style="width: 400px;"&gt;&lt;img src="https://community.cloudera.com/t5/image/serverpage/image-id/31699i3643C5111AAD12F5/image-size/medium?v=v2&amp;amp;px=400" role="button" title="jakezhang_0-1624755445124.png" alt="jakezhang_0-1624755445124.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 27 Jun 2021 00:59:21 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/CDP-7-1-6-Ranger-KMS-test-conection-failed-quot-User-ranger/m-p/319372#M227782</guid>
      <dc:creator>jakezhang</dc:creator>
      <dc:date>2021-06-27T00:59:21Z</dc:date>
    </item>
    <item>
      <title>Re: CDP 7.1.6  Ranger KMS test conection failed " User:ranger not allowed to do 'GET_KEYS' "</title>
      <link>https://community.cloudera.com/t5/Support-Questions/CDP-7-1-6-Ranger-KMS-test-conection-failed-quot-User-ranger/m-p/319393#M227794</link>
      <description>&lt;P&gt;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/31768"&gt;@jakezhang&lt;/a&gt;&amp;nbsp;Check is&amp;nbsp; cm_kms policy is in sync&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also, modify the&amp;nbsp;&lt;SPAN&gt;Config Properties values in cm_kms as shown below&lt;/SPAN&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;tag.download.auth.users=kms
policy.download.auth.users=keyadmin,rangerkms&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 27 Jun 2021 16:42:31 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/CDP-7-1-6-Ranger-KMS-test-conection-failed-quot-User-ranger/m-p/319393#M227794</guid>
      <dc:creator>Scharan</dc:creator>
      <dc:date>2021-06-27T16:42:31Z</dc:date>
    </item>
    <item>
      <title>Re: CDP 7.1.6  Ranger KMS test conection failed " User:ranger not allowed to do 'GET_KEYS' "</title>
      <link>https://community.cloudera.com/t5/Support-Questions/CDP-7-1-6-Ranger-KMS-test-conection-failed-quot-User-ranger/m-p/319545#M227870</link>
      <description>&lt;P&gt;Thank you.&lt;/P&gt;&lt;P&gt;You might see they are already added in the previous screenshot.&lt;/P&gt;&lt;P&gt;Ranger user is added as well but it did not work.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;tag.download.auth.users=kms,ranger
policy.download.auth.users=keyadmin,rangerkms,ranger&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 29 Jun 2021 22:26:01 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/CDP-7-1-6-Ranger-KMS-test-conection-failed-quot-User-ranger/m-p/319545#M227870</guid>
      <dc:creator>jakezhang</dc:creator>
      <dc:date>2021-06-29T22:26:01Z</dc:date>
    </item>
    <item>
      <title>Re: CDP 7.1.6  Ranger KMS test conection failed " User:ranger not allowed to do 'GET_KEYS' "</title>
      <link>https://community.cloudera.com/t5/Support-Questions/CDP-7-1-6-Ranger-KMS-test-conection-failed-quot-User-ranger/m-p/319548#M227872</link>
      <description>&lt;P&gt;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/31768"&gt;@jakezhang&lt;/a&gt;&amp;nbsp; Can you check is &lt;STRONG&gt;cm_kms&lt;/STRONG&gt; policy is in sync after adding the ranger users to the policy&lt;/P&gt;&lt;P&gt;Share the screenshot of Ranger Ui =&amp;gt; Audit =&amp;gt; Plugins&lt;/P&gt;</description>
      <pubDate>Wed, 30 Jun 2021 05:02:47 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/CDP-7-1-6-Ranger-KMS-test-conection-failed-quot-User-ranger/m-p/319548#M227872</guid>
      <dc:creator>Scharan</dc:creator>
      <dc:date>2021-06-30T05:02:47Z</dc:date>
    </item>
    <item>
      <title>Re: CDP 7.1.6  Ranger KMS test conection failed " User:ranger not allowed to do 'GET_KEYS' "</title>
      <link>https://community.cloudera.com/t5/Support-Questions/CDP-7-1-6-Ranger-KMS-test-conection-failed-quot-User-ranger/m-p/319575#M227877</link>
      <description>&lt;P&gt;Thanks &lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/35149"&gt;@Scharan&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I don't think it's in sync since the test connection failed.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="kms-4.PNG" style="width: 999px;"&gt;&lt;img src="https://community.cloudera.com/t5/image/serverpage/image-id/31727i7830D9C1D0AA2157/image-size/large?v=v2&amp;amp;px=999" role="button" title="kms-4.PNG" alt="kms-4.PNG" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="kms-5.PNG" style="width: 999px;"&gt;&lt;img src="https://community.cloudera.com/t5/image/serverpage/image-id/31728i3BAAD3F141A67425/image-size/large?v=v2&amp;amp;px=999" role="button" title="kms-5.PNG" alt="kms-5.PNG" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="kms-6.PNG" style="width: 999px;"&gt;&lt;img src="https://community.cloudera.com/t5/image/serverpage/image-id/31730i5AFFC763DBAC65B1/image-size/large?v=v2&amp;amp;px=999" role="button" title="kms-6.PNG" alt="kms-6.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 30 Jun 2021 08:19:39 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/CDP-7-1-6-Ranger-KMS-test-conection-failed-quot-User-ranger/m-p/319575#M227877</guid>
      <dc:creator>jakezhang</dc:creator>
      <dc:date>2021-06-30T08:19:39Z</dc:date>
    </item>
    <item>
      <title>Re: CDP 7.1.6  Ranger KMS test conection failed " User:ranger not allowed to do 'GET_KEYS' "</title>
      <link>https://community.cloudera.com/t5/Support-Questions/CDP-7-1-6-Ranger-KMS-test-conection-failed-quot-User-ranger/m-p/319576#M227878</link>
      <description>&lt;P&gt;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/31768"&gt;@jakezhang&lt;/a&gt;&amp;nbsp;From the screenshot, I can see cm_kms policy is not in sync&lt;/P&gt;&lt;P&gt;Policy needs to be sync after ranger users is added to the policy, then only the Ranger user will be allowed to Get the keys&lt;/P&gt;</description>
      <pubDate>Wed, 30 Jun 2021 08:33:23 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/CDP-7-1-6-Ranger-KMS-test-conection-failed-quot-User-ranger/m-p/319576#M227878</guid>
      <dc:creator>Scharan</dc:creator>
      <dc:date>2021-06-30T08:33:23Z</dc:date>
    </item>
    <item>
      <title>Re: CDP 7.1.6  Ranger KMS test conection failed " User:ranger not allowed to do 'GET_KEYS' "</title>
      <link>https://community.cloudera.com/t5/Support-Questions/CDP-7-1-6-Ranger-KMS-test-conection-failed-quot-User-ranger/m-p/319622#M227898</link>
      <description>&lt;P&gt;Thanks, but how can I get the policy synced?&lt;/P&gt;</description>
      <pubDate>Wed, 30 Jun 2021 22:05:35 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/CDP-7-1-6-Ranger-KMS-test-conection-failed-quot-User-ranger/m-p/319622#M227898</guid>
      <dc:creator>jakezhang</dc:creator>
      <dc:date>2021-06-30T22:05:35Z</dc:date>
    </item>
    <item>
      <title>Re: CDP 7.1.6  Ranger KMS test conection failed " User:ranger not allowed to do 'GET_KEYS' "</title>
      <link>https://community.cloudera.com/t5/Support-Questions/CDP-7-1-6-Ranger-KMS-test-conection-failed-quot-User-ranger/m-p/319627#M227900</link>
      <description>&lt;P&gt;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/31768"&gt;@jakezhang&lt;/a&gt;&amp;nbsp;Check ranger KMS logs and see what is the error while refreshing the policy&lt;/P&gt;</description>
      <pubDate>Thu, 01 Jul 2021 00:51:53 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/CDP-7-1-6-Ranger-KMS-test-conection-failed-quot-User-ranger/m-p/319627#M227900</guid>
      <dc:creator>Scharan</dc:creator>
      <dc:date>2021-07-01T00:51:53Z</dc:date>
    </item>
    <item>
      <title>Re: CDP 7.1.6  Ranger KMS test conection failed " User:ranger not allowed to do 'GET_KEYS' "</title>
      <link>https://community.cloudera.com/t5/Support-Questions/CDP-7-1-6-Ranger-KMS-test-conection-failed-quot-User-ranger/m-p/319630#M227903</link>
      <description>&lt;P&gt;yeah, I was checking the KMS logs, not sure if there is something mis-configured....&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;2021-07-01 10:03:35,980 DEBUG org.apache.ranger.admin.client.RangerAdminRESTClient: ==&amp;gt; RangerAdminRESTClient.getServicePoliciesIfUpdated(-1, 1625097035937)
2021-07-01 10:03:35,980 DEBUG org.apache.ranger.admin.client.RangerAdminRESTClient: Checking Service policy if updated with old api call
2021-07-01 10:03:35,986 DEBUG org.apache.ranger.admin.client.datatype.RESTResponse: fromJson('Unauthenticated access not allowed') failed
org.codehaus.jackson.JsonParseException: Unexpected character ('U' (code 85)): expected a valid value (number, String, array, object, 'true', 'false' or 'null')
 at [Source: java.io.StringReader@7b831251; line: 1, column: 2]
        at org.codehaus.jackson.JsonParser._constructError(JsonParser.java:1433)
        at org.codehaus.jackson.impl.JsonParserMinimalBase._reportError(JsonParserMinimalBase.java:521)
        at org.codehaus.jackson.impl.JsonParserMinimalBase._reportUnexpectedChar(JsonParserMinimalBase.java:442)
        at org.codehaus.jackson.impl.ReaderBasedParser._handleUnexpectedValue(ReaderBasedParser.java:1198)
        at org.codehaus.jackson.impl.ReaderBasedParser.nextToken(ReaderBasedParser.java:485)
        at org.codehaus.jackson.map.ObjectMapper._initForReading(ObjectMapper.java:2770)
        at org.codehaus.jackson.map.ObjectMapper._readMapAndClose(ObjectMapper.java:2718)
        at org.codehaus.jackson.map.ObjectMapper.readValue(ObjectMapper.java:1863)
        at org.apache.ranger.plugin.util.JsonUtilsV2.jsonToObj(JsonUtilsV2.java:68)
        at org.apache.ranger.admin.client.datatype.RESTResponse.fromJson(RESTResponse.java:126)
        at org.apache.ranger.admin.client.datatype.RESTResponse.fromClientResponse(RESTResponse.java:100)
        at org.apache.ranger.admin.client.RangerAdminRESTClient.getServicePoliciesIfUpdated(RangerAdminRESTClient.java:195)
        at org.apache.ranger.plugin.util.PolicyRefresher.loadPolicyfromPolicyAdmin(PolicyRefresher.java:305)
        at org.apache.ranger.plugin.util.PolicyRefresher.loadPolicy(PolicyRefresher.java:244)
        at org.apache.ranger.plugin.util.PolicyRefresher.run(PolicyRefresher.java:206)
2021-07-01 10:03:35,987 WARN org.apache.ranger.admin.client.RangerAdminRESTClient: Error getting policies. secureMode=false, user=kms (auth:SIMPLE), response={"httpStatusCode":400,"statusCode":0}, serviceName=cm_kms
2021-07-01 10:03:35,987 DEBUG org.apache.ranger.admin.client.RangerAdminRESTClient: &amp;lt;== RangerAdminRESTClient.getServicePoliciesIfUpdated(-1, 1625097035937): null
2021-07-01 10:03:35,987 DEBUG org.apache.ranger.plugin.util.PolicyRefresher: PolicyRefresher(serviceName=cm_kms).run(): no update found. lastKnownVersion=-1
2021-07-01 10:03:35,987 DEBUG org.apache.ranger.perf.policyengine.init: [PERF] PolicyRefresher.loadPolicyFromPolicyAdmin(serviceName=cm_kms): 7
2021-07-01 10:03:35,987 DEBUG org.apache.ranger.plugin.util.PolicyRefresher: &amp;lt;== PolicyRefresher(serviceName=cm_kms).loadPolicyfromPolicyAdmin()&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Ranger KMS authenticatin type is kerberos, I tired to change it to simple and restarted both ranger and rangerkms, it did not help.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I don't know where the auth simple come from? Thanks.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;2021-07-01 10:03:35,987 WARN org.apache.ranger.admin.client.RangerAdminRESTClient: Error getting policies. secureMode=false, user=kms (auth:SIMPLE), response={"httpStatusCode":400,"statusCode":0}, serviceName=cm_kms&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 01 Jul 2021 02:10:30 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/CDP-7-1-6-Ranger-KMS-test-conection-failed-quot-User-ranger/m-p/319630#M227903</guid>
      <dc:creator>jakezhang</dc:creator>
      <dc:date>2021-07-01T02:10:30Z</dc:date>
    </item>
    <item>
      <title>Re: CDP 7.1.6  Ranger KMS test conection failed " User:ranger not allowed to do 'GET_KEYS' "</title>
      <link>https://community.cloudera.com/t5/Support-Questions/CDP-7-1-6-Ranger-KMS-test-conection-failed-quot-User-ranger/m-p/319961#M228056</link>
      <description>&lt;P&gt;I was seeing the same issue, thanks to &lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/31768"&gt;@jakezhang&lt;/a&gt;&amp;nbsp; for posting.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Changing the Ranger KMS: kerberos_princ_name from rangerkms to keyadmin allowed me to get this working. Thanks for the clues in the log file and to &lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/35149"&gt;@Scharan&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="rangerkms2.png" style="width: 999px;"&gt;&lt;img src="https://community.cloudera.com/t5/image/serverpage/image-id/31794i28CAA697EDBEA5BC/image-size/large?v=v2&amp;amp;px=999" role="button" title="rangerkms2.png" alt="rangerkms2.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="rangerkms3.png" style="width: 999px;"&gt;&lt;img src="https://community.cloudera.com/t5/image/serverpage/image-id/31795i695D037F4D5A0516/image-size/large?v=v2&amp;amp;px=999" role="button" title="rangerkms3.png" alt="rangerkms3.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="rangerkms1.png" style="width: 999px;"&gt;&lt;img src="https://community.cloudera.com/t5/image/serverpage/image-id/31796i51D820A7036631BF/image-size/large?v=v2&amp;amp;px=999" role="button" title="rangerkms1.png" alt="rangerkms1.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 06 Jul 2021 18:10:47 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/CDP-7-1-6-Ranger-KMS-test-conection-failed-quot-User-ranger/m-p/319961#M228056</guid>
      <dc:creator>russ_stevenson</dc:creator>
      <dc:date>2021-07-06T18:10:47Z</dc:date>
    </item>
  </channel>
</rss>

