<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>question Kinit not working after migrating principals from one KDC to other one in Support Questions</title>
    <link>https://community.cloudera.com/t5/Support-Questions/Kinit-not-working-after-migrating-principals-from-one-KDC-to/m-p/337085#M232493</link>
    <description>&lt;P&gt;Hi Team,&lt;/P&gt;&lt;P&gt;I have recently migrated Kerberos principals using the below command from one KDC to another KDC, post-migration kinit is not working and it is throwing some error whereas the same identity is working in the original KDC. Can you please help us in identifying the error? Did I make any mistakes while migrating the principles?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Command Used -&amp;nbsp;kdb5_util dump -verbose dumpfile&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;and logged in to other KDC and executed the restore&amp;nbsp;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;kdb5_util &lt;/SPAN&gt;&lt;SPAN class="s2"&gt;&lt;STRONG&gt;restore&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;SPAN class="s1"&gt; -verbose /tmp/dumpfile&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;Error:&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;KRB5_TRACE=/dev/stdout kinit testuser&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;[8962] 1645765308.654184: Getting initial credentials for testuser@EXAMPLE.COM&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;[8962] 1645765308.654186: Sending unauthenticated request&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;[8962] 1645765308.654187: Sending request (181 bytes) to EXAMPLE.COM&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;[8962] 1645765308.654188: Resolving hostname stg-hdplucykrb101.phonepe.nb6&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;[8962] 1645765308.654189: Sending initial UDP request to dgram 10.57.55.228:88&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;[8962] 1645765308.654190: Received answer (163 bytes) from dgram 10.57.55.228:88&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;[8962] 1645765308.654188: Resolving hostname kdc.example.com&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;[8962] 1645765308.654191: Sending DNS URI query for _kerberos.EXAMPLE.COM.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;[8962] 1645765308.654192: No URI records found&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;[8962] 1645765308.654193: Sending DNS SRV query for _kerberos-master._udp.EXAMPLE.COM.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;[8962] 1645765308.654194: Sending DNS SRV query for _kerberos-master._tcp.EXAMPLE.COM.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;[8962] 1645765308.654195: No SRV records found&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;[8962] 1645765308.654196: Response was not from master KDC&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;[8962] 1645765308.654197: Received error from KDC: -1765328353/Decrypt integrity check failed&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;[8962] 1645765308.654198: Retrying AS request with master KDC&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;[8962] 1645765308.654199: Getting initial credentials for testuser@EXAMPLE.COM&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;[8962] 1645765308.654201: Sending unauthenticated request&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;[8962] 1645765308.654202: Sending request (181 bytes) to EXAMPLE.COM (master)&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;[8962] 1645765308.654203: Sending DNS URI query for _kerberos.EXAMPLE.COM.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;[8962] 1645765308.654204: No URI records found&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;[8962] 1645765308.654205: Sending DNS SRV query for _kerberos-master._udp.EXAMPLE.COM.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;[8962] 1645765308.654206: Sending DNS SRV query for _kerberos-master._tcp.EXAMPLE.COM.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;[8962] 1645765308.654207: No SRV records found&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;kinit: Password incorrect while getting initial credentials&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 25 Feb 2022 05:18:07 GMT</pubDate>
    <dc:creator>saivenkatg55</dc:creator>
    <dc:date>2022-02-25T05:18:07Z</dc:date>
    <item>
      <title>Kinit not working after migrating principals from one KDC to other one</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Kinit-not-working-after-migrating-principals-from-one-KDC-to/m-p/337085#M232493</link>
      <description>&lt;P&gt;Hi Team,&lt;/P&gt;&lt;P&gt;I have recently migrated Kerberos principals using the below command from one KDC to another KDC, post-migration kinit is not working and it is throwing some error whereas the same identity is working in the original KDC. Can you please help us in identifying the error? Did I make any mistakes while migrating the principles?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Command Used -&amp;nbsp;kdb5_util dump -verbose dumpfile&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;and logged in to other KDC and executed the restore&amp;nbsp;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;kdb5_util &lt;/SPAN&gt;&lt;SPAN class="s2"&gt;&lt;STRONG&gt;restore&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;SPAN class="s1"&gt; -verbose /tmp/dumpfile&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;Error:&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;KRB5_TRACE=/dev/stdout kinit testuser&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;[8962] 1645765308.654184: Getting initial credentials for testuser@EXAMPLE.COM&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;[8962] 1645765308.654186: Sending unauthenticated request&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;[8962] 1645765308.654187: Sending request (181 bytes) to EXAMPLE.COM&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;[8962] 1645765308.654188: Resolving hostname stg-hdplucykrb101.phonepe.nb6&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;[8962] 1645765308.654189: Sending initial UDP request to dgram 10.57.55.228:88&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;[8962] 1645765308.654190: Received answer (163 bytes) from dgram 10.57.55.228:88&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;[8962] 1645765308.654188: Resolving hostname kdc.example.com&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;[8962] 1645765308.654191: Sending DNS URI query for _kerberos.EXAMPLE.COM.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;[8962] 1645765308.654192: No URI records found&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;[8962] 1645765308.654193: Sending DNS SRV query for _kerberos-master._udp.EXAMPLE.COM.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;[8962] 1645765308.654194: Sending DNS SRV query for _kerberos-master._tcp.EXAMPLE.COM.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;[8962] 1645765308.654195: No SRV records found&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;[8962] 1645765308.654196: Response was not from master KDC&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;[8962] 1645765308.654197: Received error from KDC: -1765328353/Decrypt integrity check failed&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;[8962] 1645765308.654198: Retrying AS request with master KDC&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;[8962] 1645765308.654199: Getting initial credentials for testuser@EXAMPLE.COM&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;[8962] 1645765308.654201: Sending unauthenticated request&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;[8962] 1645765308.654202: Sending request (181 bytes) to EXAMPLE.COM (master)&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;[8962] 1645765308.654203: Sending DNS URI query for _kerberos.EXAMPLE.COM.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;[8962] 1645765308.654204: No URI records found&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;[8962] 1645765308.654205: Sending DNS SRV query for _kerberos-master._udp.EXAMPLE.COM.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;[8962] 1645765308.654206: Sending DNS SRV query for _kerberos-master._tcp.EXAMPLE.COM.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;[8962] 1645765308.654207: No SRV records found&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;kinit: Password incorrect while getting initial credentials&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 25 Feb 2022 05:18:07 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Kinit-not-working-after-migrating-principals-from-one-KDC-to/m-p/337085#M232493</guid>
      <dc:creator>saivenkatg55</dc:creator>
      <dc:date>2022-02-25T05:18:07Z</dc:date>
    </item>
    <item>
      <title>Re: Kinit not working after migrating principals from one KDC to other one</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Kinit-not-working-after-migrating-principals-from-one-KDC-to/m-p/337561#M232626</link>
      <description>&lt;OL&gt;&lt;LI&gt;Stop CDH Services and Stop Cloudera Manager Management Services.&lt;/LI&gt;&lt;LI&gt;Import the new kerberos account. You will need an admin account on the KDC for this:&lt;OL&gt;&lt;LI&gt;CM UI -&amp;gt; Administration -&amp;gt; Security -&amp;gt; Kerberos credentials -&amp;gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;"Import Kerberos Account Manager Credentials"&lt;/STRONG&gt;&lt;/LI&gt;&lt;LI&gt;Enter username and password&lt;/LI&gt;&lt;LI&gt;Click Import button&lt;/LI&gt;&lt;/OL&gt;&lt;/LI&gt;&lt;LI&gt;Re-generate missing principals if the previous step was successful&lt;OL&gt;&lt;LI&gt;CM UI -&amp;gt; Administration -&amp;gt; Security -&amp;gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;"Kerberos credentials"&lt;/STRONG&gt;&lt;/LI&gt;&lt;LI&gt;Click the button&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;"Generate Missing Credentials"&lt;/STRONG&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;/LI&gt;&lt;LI&gt;Wait until credentials have been generated&lt;/LI&gt;&lt;LI&gt;Start Cloudera Manager Management Services&lt;/LI&gt;&lt;LI&gt;Start CDH Services&lt;/LI&gt;&lt;/OL&gt;</description>
      <pubDate>Thu, 03 Mar 2022 06:11:36 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Kinit-not-working-after-migrating-principals-from-one-KDC-to/m-p/337561#M232626</guid>
      <dc:creator>GangWar</dc:creator>
      <dc:date>2022-03-03T06:11:36Z</dc:date>
    </item>
  </channel>
</rss>

