<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>question Re: Failed to regenerate kerberos keytabs in Support Questions</title>
    <link>https://community.cloudera.com/t5/Support-Questions/Failed-to-regenerate-kerberos-keytabs/m-p/321475#M228418</link>
    <description>&lt;P&gt;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/44519"&gt;@enirys&lt;/a&gt;&amp;nbsp;Free ipa with Ambari 2.6.x&amp;nbsp; is not supported, Free ipa is supported from Ambari 2.7.x onwards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sat, 24 Jul 2021 14:19:52 GMT</pubDate>
    <dc:creator>Scharan</dc:creator>
    <dc:date>2021-07-24T14:19:52Z</dc:date>
    <item>
      <title>Failed to regenerate kerberos keytabs</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Failed-to-regenerate-kerberos-keytabs/m-p/321442#M228401</link>
      <description>&lt;P&gt;From ambari webui (Admin -&amp;gt; Kerberos -&amp;gt; Regenerate Keytabs) when i try to regenerate keytabs it fails on &lt;STRONG&gt;Create Principals&lt;/STRONG&gt; step with the following error message&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;2021-07-22 17:39:06,690 - Failed to create principal, HTTP/cnode28.26f5de01-5e40-4d8a-98bd-a4353b7bf5e3.datalake@26F5DE01-5E40-4D8A-98BD-A4353B7BF5E3.DATALAKE - Failed to create service principal for HTTP/cnode28.26f5de01-5e40-4d8a-98bd-a4353b7bf5e3.datalake@26F5DE01-5E40-4D8A-98BD-A4353B7BF5E3.DATALAKE
STDOUT: 
STDERR: ipa: ERROR: service with name "HTTP/cnode28.26f5de01-5e40-4d8a-98bd-a4353b7bf5e3.datalake@26F5DE01-5E40-4D8A-98BD-A4353B7BF5E3.DATALAKE" already exists&lt;/LI-CODE&gt;&lt;P&gt;Bellow ambari kerberos config:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;authentication.kerberos.auth_to_local.rules=DEFAULT
authentication.kerberos.enabled=true
authentication.kerberos.spnego.keytab.file=/etc/security/keytabs/spnego.service.keytab
authentication.kerberos.spnego.principal=HTTP/enode6.26f5de01-5e40-4d8a-98bd-a4353b7bf5e3.datalake
authentication.kerberos.user.types=LDAP&lt;/LI-CODE&gt;&lt;P&gt;Thanks in advance for your help&lt;/P&gt;</description>
      <pubDate>Fri, 23 Jul 2021 13:26:50 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Failed-to-regenerate-kerberos-keytabs/m-p/321442#M228401</guid>
      <dc:creator>enirys</dc:creator>
      <dc:date>2021-07-23T13:26:50Z</dc:date>
    </item>
    <item>
      <title>Re: Failed to regenerate kerberos keytabs</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Failed-to-regenerate-kerberos-keytabs/m-p/321446#M228403</link>
      <description>&lt;P&gt;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/44519"&gt;@enirys&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Follow the below steps on ambari db&lt;/P&gt;&lt;P&gt;1. Take ambari DB backup&lt;/P&gt;&lt;P&gt;2. Execute the below mentioned SQL commands on ambari DB&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;# DELETE FROM ambari.kkp_mapping_service where kkp_id in (select kkp_id from ambari.kerberos_keytab_principal where principal_name = 'HTTP/cnode28.26f5de01-5e40-4d8a-98bd-a4353b7bf5e3.datalake@26F5DE01-5E40-4D8A-98BD-A4353B7BF5E3.DATALAKE');

# DELETE FROM kerberos_keytab_principal WHERE principal_name='HTTP/cnode28.26f5de01-5e40-4d8a-98bd-a4353b7bf5e3.datalake@26F5DE01-5E40-4D8A-98BD-A4353B7BF5E3.DATALAKE';

# DELETE FROM kerberos_principal WHERE principal_name='HTTP/cnode28.26f5de01-5e40-4d8a-98bd-a4353b7bf5e3.datalake@26F5DE01-5E40-4D8A-98BD-A4353B7BF5E3.DATALAKE';&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;3. After executing above command restart ambari server and regenerate the keytabs&lt;/P&gt;</description>
      <pubDate>Fri, 23 Jul 2021 14:09:56 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Failed-to-regenerate-kerberos-keytabs/m-p/321446#M228403</guid>
      <dc:creator>Scharan</dc:creator>
      <dc:date>2021-07-23T14:09:56Z</dc:date>
    </item>
    <item>
      <title>Re: Failed to regenerate kerberos keytabs</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Failed-to-regenerate-kerberos-keytabs/m-p/321458#M228408</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/35149"&gt;@Scharan&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thanks for your feedback, but i don't have kkp_mapping_service and kerberos_keytab_principal tables but only kerberos_principal and kerberos_principal_host&lt;/P&gt;</description>
      <pubDate>Fri, 23 Jul 2021 16:25:44 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Failed-to-regenerate-kerberos-keytabs/m-p/321458#M228408</guid>
      <dc:creator>enirys</dc:creator>
      <dc:date>2021-07-23T16:25:44Z</dc:date>
    </item>
    <item>
      <title>Re: Failed to regenerate kerberos keytabs</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Failed-to-regenerate-kerberos-keytabs/m-p/321472#M228416</link>
      <description>&lt;P&gt;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/44519"&gt;@enirys&lt;/a&gt;&amp;nbsp;In Ambari 2.7.x below tables should exists whether your cluster is kerberized or not&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can you check and confirm does below table exists in Ambari DB&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;kerberos_descriptor
kerberos_keytab
kerberos_keytab_principal
kerberos_principal
key_value_store
kkp_mapping_service&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 24 Jul 2021 06:08:52 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Failed-to-regenerate-kerberos-keytabs/m-p/321472#M228416</guid>
      <dc:creator>Scharan</dc:creator>
      <dc:date>2021-07-24T06:08:52Z</dc:date>
    </item>
    <item>
      <title>Re: Failed to regenerate kerberos keytabs</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Failed-to-regenerate-kerberos-keytabs/m-p/321474#M228417</link>
      <description>&lt;P&gt;hi &lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/35149"&gt;@Scharan&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My ambari version is &lt;STRONG&gt;2.6.2.2&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;i have only these tables&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;kerberos_descriptor
kerberos_principal
key_value_store&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;Other tables doesn't exists&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;kerberos_keytab
kerberos_keytab_principal
kkp_mapping_service&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 24 Jul 2021 13:14:35 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Failed-to-regenerate-kerberos-keytabs/m-p/321474#M228417</guid>
      <dc:creator>enirys</dc:creator>
      <dc:date>2021-07-24T13:14:35Z</dc:date>
    </item>
    <item>
      <title>Re: Failed to regenerate kerberos keytabs</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Failed-to-regenerate-kerberos-keytabs/m-p/321475#M228418</link>
      <description>&lt;P&gt;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/44519"&gt;@enirys&lt;/a&gt;&amp;nbsp;Free ipa with Ambari 2.6.x&amp;nbsp; is not supported, Free ipa is supported from Ambari 2.7.x onwards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 24 Jul 2021 14:19:52 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Failed-to-regenerate-kerberos-keytabs/m-p/321475#M228418</guid>
      <dc:creator>Scharan</dc:creator>
      <dc:date>2021-07-24T14:19:52Z</dc:date>
    </item>
    <item>
      <title>Re: Failed to regenerate kerberos keytabs</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Failed-to-regenerate-kerberos-keytabs/m-p/321553#M228441</link>
      <description>&lt;P&gt;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/35149"&gt;@Scharan&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I don't think the issue is related to ambari version, we have an integration cluster with similar configuration (Amabari 2.6.2.2 and freeipa) and keytab regeneration is working fine.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="enirys_0-1627289021462.png" style="width: 400px;"&gt;&lt;img src="https://community.cloudera.com/t5/image/serverpage/image-id/31964i3E81D852141346BB/image-size/medium?v=v2&amp;amp;px=400" role="button" title="enirys_0-1627289021462.png" alt="enirys_0-1627289021462.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 26 Jul 2021 08:45:39 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Failed-to-regenerate-kerberos-keytabs/m-p/321553#M228441</guid>
      <dc:creator>enirys</dc:creator>
      <dc:date>2021-07-26T08:45:39Z</dc:date>
    </item>
    <item>
      <title>Re: Failed to regenerate kerberos keytabs</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Failed-to-regenerate-kerberos-keytabs/m-p/321574#M228454</link>
      <description>&lt;P&gt;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/44519"&gt;@enirys&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can you once remove the problematic kerberos principal from FreeIPA and then try and regenerate the&amp;nbsp;kerberos keytabs&lt;/P&gt;&lt;PRE&gt;       ipa-rmkeytab [ &lt;STRONG&gt;-p&lt;/STRONG&gt; principal-name ] [ &lt;STRONG&gt;-k&lt;/STRONG&gt; keytab-file ] [ &lt;STRONG&gt;-r&lt;/STRONG&gt; realm ] [ &lt;STRONG&gt;-d&lt;/STRONG&gt; ]&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 26 Jul 2021 13:07:44 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Failed-to-regenerate-kerberos-keytabs/m-p/321574#M228454</guid>
      <dc:creator>jAnshula</dc:creator>
      <dc:date>2021-07-26T13:07:44Z</dc:date>
    </item>
  </channel>
</rss>

