<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>question Re: Kerberos Authentication Failure : Catalog Server Unable to Connect to Statestore Port in Support Questions</title>
    <link>https://community.cloudera.com/t5/Support-Questions/Kerberos-Authentication-Failure-Catalog-Server-Unable-to/m-p/339080#M233024</link>
    <description>&lt;P&gt;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/96257"&gt;@pandu2022&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Have you updated the properties below for *&lt;STRONG&gt;all&lt;/STRONG&gt;* the Impala service roles (ID, catalog and statestore)?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;FONT face="courier new,courier"&gt;principal&lt;/FONT&gt;: When using a load-balancer this should be of the form &lt;FONT face="courier new,courier"&gt;impala_test/&amp;lt;LB_fqdn&amp;gt;@&amp;lt;REALM&amp;gt;&lt;/FONT&gt;. If not using a LB, this should be&amp;nbsp;&lt;FONT face="courier new,courier"&gt;impala_test/&amp;lt;host_fqdn&amp;gt;@&amp;lt;REALM&amp;gt;&lt;/FONT&gt;.&lt;/LI&gt;&lt;LI&gt;&lt;FONT face="courier new,courier"&gt;be_principal&lt;/FONT&gt;: This is only necessary when a LB is being used and should be of the form &lt;FONT face="courier new,courier"&gt;impala_test/&amp;lt;host_fqdn&amp;gt;@&amp;lt;REALM&amp;gt;&lt;/FONT&gt;.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;André&lt;/P&gt;&lt;P&gt;&lt;EM&gt;--&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;Was your question answered? Please take some time to click on "&lt;STRONG&gt;Accept as Solution&lt;/STRONG&gt;" below this post.&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;If you find a reply useful, say thanks by clicking on the thumbs up button.&lt;/EM&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 22 Mar 2022 06:43:12 GMT</pubDate>
    <dc:creator>araujo</dc:creator>
    <dc:date>2022-03-22T06:43:12Z</dc:date>
    <item>
      <title>Kerberos Authentication Failure : Catalog Server Unable to Connect to Statestore Port</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Kerberos-Authentication-Failure-Catalog-Server-Unable-to/m-p/337598#M232648</link>
      <description>&lt;P&gt;F0303 09:59:04.650674 32117 catalogd-main.cc:87] Couldn't open transport for &lt;STRONG&gt;hostname&lt;/STRONG&gt;:11423 (SASL(-1): generic failure: GSSAPI Error: Unspecified GSS failure. Minor code may provide more information (Server not found in Kerberos database))&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have used a customized service name for impala, can we do that? if not how can we achieve it?&lt;/P&gt;&lt;P&gt;principal - &lt;STRONG&gt;impala_&amp;lt;some text&amp;gt;@hostname@Domain&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 03 Mar 2022 10:55:24 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Kerberos-Authentication-Failure-Catalog-Server-Unable-to/m-p/337598#M232648</guid>
      <dc:creator>pandu2022</dc:creator>
      <dc:date>2022-03-03T10:55:24Z</dc:date>
    </item>
    <item>
      <title>Re: Kerberos Authentication Failure : Catalog Server Unable to Connect to Statestore Port</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Kerberos-Authentication-Failure-Catalog-Server-Unable-to/m-p/337656#M232659</link>
      <description>&lt;P&gt;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/96257"&gt;@pandu2022&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When using Kerberos and/or TLS, please make sure that the hostname is specified as a fully qualified name (e.g. hostname.acm.com), instead of a short name.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Are you using a fully qualified name? If not, could you please try again using one?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also, are you using a load balancer?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;André&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 03 Mar 2022 22:36:55 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Kerberos-Authentication-Failure-Catalog-Server-Unable-to/m-p/337656#M232659</guid>
      <dc:creator>araujo</dc:creator>
      <dc:date>2022-03-03T22:36:55Z</dc:date>
    </item>
    <item>
      <title>Re: Kerberos Authentication Failure : Catalog Server Unable to Connect to Statestore Port</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Kerberos-Authentication-Failure-Catalog-Server-Unable-to/m-p/338991#M232986</link>
      <description>&lt;P&gt;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/11191"&gt;@araujo&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;yes I'm using fully qualified domain name&lt;BR /&gt;when the principal is like &lt;STRONG&gt;impala&lt;/STRONG&gt;/&amp;lt;&lt;STRONG&gt;fqdn of host&lt;/STRONG&gt;&amp;gt;@domain catalog server is able to connect to statestore successfully. but when the principal service name is custom as &lt;STRONG&gt;impala_test&lt;/STRONG&gt;/&lt;STRONG&gt;&amp;lt;fqdn of host&amp;gt;&lt;/STRONG&gt;@domain, statestore error log is updating as below,&lt;BR /&gt;&lt;BR /&gt;I0321 08:30:30.615939 22113 statestore.cc:610] Creating new topic: ''catalog-update' on behalf of subscriber: 'catalog-server@&lt;STRONG&gt;&amp;lt;fqdn of catalog service host&amp;gt;&lt;/STRONG&gt;:11426&lt;BR /&gt;I0321 08:30:30.615953 22113 statestore.cc:618] Registering: catalog-server@&amp;lt;&lt;STRONG&gt;fqdn of catalog service host&amp;gt;&lt;/STRONG&gt;:11426&lt;BR /&gt;I0321 08:30:30.615984 22113 statestore.cc:641] Subscriber 'catalog-server@&lt;STRONG&gt;&amp;lt;fqdn of catalog service host&amp;gt;&lt;/STRONG&gt;:11426' registered (registration id: c54a83a37fd90f6b:9023e9873ba17d89)&lt;BR /&gt;E0321 08:30:30.632500 21923 authentication.cc:177] SASL message (Kerberos (internal)): GSSAPI Error: Unspecified GSS failure. Minor code may provide more information (Server not found in Kerberos database)&lt;BR /&gt;E0321 08:30:30.632500 21901 authentication.cc:177] SASL message (Kerberos (internal)): GSSAPI Error: Unspecified GSS failure. Minor code may provide more information (Server not found in Kerberos database)&lt;BR /&gt;I0321 08:30:30.632710 21901 thrift-client.cc:94] Unable to connect to &lt;STRONG&gt;&amp;lt;fqdn of catalog service host&amp;gt;&lt;/STRONG&gt;:11434&lt;BR /&gt;I0321 08:30:30.632715 21923 thrift-client.cc:94] Unable to connect to &lt;STRONG&gt;&amp;lt;fqdn of catalog service host&amp;gt;&lt;/STRONG&gt;:11434&lt;BR /&gt;I0321 08:30:30.632727 21923 statestore.cc:970] Unable to send heartbeat message to subscriber catalog-server@&amp;lt;&lt;STRONG&gt;fqdn of catalog service host&amp;gt;&lt;/STRONG&gt;:11426, received error: Couldn't open transport for &amp;lt;&lt;STRONG&gt;fqdn of catalog service host&amp;gt;&lt;/STRONG&gt;:11434 (SASL(-1): generic failure: GSSAPI Error: Unspecified GSS failure. Minor code may provide more information (Server not found in Kerberos database))&lt;BR /&gt;I0321 08:30:30.632732 21923 failure-detector.cc:91] 1 consecutive heartbeats failed for 'catalog-server@&amp;lt;&lt;STRONG&gt;fqdn of catalog service host&amp;gt;&lt;/STRONG&gt;:11426'. State is OK&lt;BR /&gt;I0321 08:30:30.632755 21901 statestore.cc:970] Unable to send topic update message to subscriber catalog-server@&amp;lt;&lt;STRONG&gt;fqdn of catalog service host&amp;gt;&lt;/STRONG&gt;:11426, received error: Couldn't open transport for &amp;lt;&lt;STRONG&gt;fqdn of catalog service host&amp;gt;&lt;/STRONG&gt;:11434 (SASL(-1): generic failure: GSSAPI Error: Unspecified GSS failure. Minor code may provide more information (Server not found in Kerberos database))&lt;BR /&gt;E0321 08:30:31.651836 21924 authentication.cc:177] SASL message (Kerberos (internal)): GSSAPI Error: Unspecified GSS failure. Minor code may provide more information (Server not found in Kerberos database)&lt;BR /&gt;I0321 08:30:31.651938 21924 thrift-client.cc:94] Unable to connect to &amp;lt;&lt;STRONG&gt;fqdn of catalog service host&amp;gt;&lt;/STRONG&gt;:11434&lt;BR /&gt;I0321 08:30:31.651949 21924 statestore.cc:970] Unable to send heartbeat message to subscriber catalog-server@&amp;lt;&lt;STRONG&gt;fqdn of catalog service host&amp;gt;&lt;/STRONG&gt;:11426, received error: Couldn't open transport for &amp;lt;&lt;STRONG&gt;fqdn of catalog service host&amp;gt;&lt;/STRONG&gt;:11434 (SASL(-1): generic failure: GSSAPI Error: Unspecified GSS failure. Minor code may provide more information (Server not found in Kerberos database))&lt;BR /&gt;I0321 08:30:31.651954 21924 failure-detector.cc:91] 2 consecutive heartbeats failed for 'catalog-server@&amp;lt;&lt;STRONG&gt;fqdn of catalog service host&amp;gt;&lt;/STRONG&gt;:11426'. State is OK&lt;BR /&gt;E0321 08:30:32.646282 21903 authentication.cc:177] SASL message (Kerberos (internal)): GSSAPI Error: Unspecified GSS failure. Minor code may provide more information (Server not found in Kerberos database)&lt;BR /&gt;I0321 08:30:32.646412 21903 thrift-client.cc:94] Unable to connect to &amp;lt;&lt;STRONG&gt;fqdn of catalog service host&amp;gt;&lt;/STRONG&gt;:11434&lt;BR /&gt;I0321 08:30:32.646428 21903 statestore.cc:970] Unable to send topic update message to subscriber catalog-server@&amp;lt;&lt;STRONG&gt;fqdn of catalog service host&amp;gt;&lt;/STRONG&gt;:11426, received error: Couldn't open transport for &amp;lt;&lt;STRONG&gt;fqdn of catalog service host&amp;gt;&lt;/STRONG&gt;:11434 (SASL(-1): generic failure: GSSAPI Error: Unspecified GSS failure. Minor code may provide more information (Server not found in Kerberos database))&lt;BR /&gt;E0321 08:30:32.681665 21923 authentication.cc:177] SASL message (Kerberos (internal)): GSSAPI Error: Unspecified GSS failure. Minor code may provide more information (Server not found in Kerberos database)&lt;BR /&gt;I0321 08:30:32.681779 21923 thrift-client.cc:94] Unable to connect to &amp;lt;&lt;STRONG&gt;fqdn of catalog service host&amp;gt;&lt;/STRONG&gt;:11434&lt;BR /&gt;I0321 08:30:32.681805 21923 statestore.cc:970] Unable to send heartbeat message to subscriber catalog-server@&amp;lt;&lt;STRONG&gt;fqdn of catalog service host&amp;gt;&lt;/STRONG&gt;:11426, received error: Couldn't open transport for &amp;lt;&lt;STRONG&gt;fqdn of catalog service host&amp;gt;&lt;/STRONG&gt;:11434 (SASL(-1): generic failure: GSSAPI Error: Unspecified GSS failure. Minor code may provide more information (Server not found in Kerberos database))&lt;BR /&gt;I0321 08:30:32.681810 21923 failure-detector.cc:91] 3 consecutive heartbeats failed for 'catalog-server@&amp;lt;&lt;STRONG&gt;fqdn of catalog service host&amp;gt;&lt;/STRONG&gt;:11426'. State is OK&lt;BR /&gt;E0321 08:30:33.697129 21926 authentication.cc:177] SASL message (Kerberos (internal)): GSSAPI Error: Unspecified GSS failure. Minor code may provide more information (Server not found in Kerberos database)&lt;BR /&gt;I0321 08:30:33.697227 21926 thrift-client.cc:94] Unable to connect to &amp;lt;&lt;STRONG&gt;fqdn of catalog service host&amp;gt;&lt;/STRONG&gt;:11434&lt;BR /&gt;I0321 08:30:33.697238 21926 statestore.cc:970] Unable to send heartbeat message to subscriber catalog-server@&amp;lt;&lt;STRONG&gt;fqdn of catalog service host&amp;gt;&lt;/STRONG&gt;:11426, received error: Couldn't open transport for &amp;lt;&lt;STRONG&gt;fqdn of catalog service host&amp;gt;&lt;/STRONG&gt;:11434 (SASL(-1): generic failure: GSSAPI Error: Unspecified GSS failure. Minor code may provide more information (Server not found in Kerberos database))&lt;BR /&gt;I0321 08:30:33.697243 21926 failure-detector.cc:91] 4 consecutive heartbeats failed for 'catalog-server@&amp;lt;&lt;STRONG&gt;fqdn of catalog service host&amp;gt;&lt;/STRONG&gt;:11426'.&lt;STRONG&gt; State is OK&lt;/STRONG&gt;&lt;BR /&gt;E0321 08:30:34.664945 21905 authentication.cc:177] SASL message (Kerberos (internal)): GSSAPI Error: Unspecified GSS failure. Minor code may provide more information (Server not found in Kerberos database)&lt;BR /&gt;I0321 08:30:34.665043 21905 thrift-client.cc:94] Unable to connect to &amp;lt;&lt;STRONG&gt;fqdn of catalog service host&amp;gt;&lt;/STRONG&gt;:11434&lt;BR /&gt;I0321 08:30:34.665056 21905 statestore.cc:970] Unable to send topic update message to subscriber catalog-server@&amp;lt;&lt;STRONG&gt;fqdn of catalog service host&amp;gt;&lt;/STRONG&gt;:11426, received error: Couldn't open transport for &amp;lt;&lt;STRONG&gt;fqdn of catalog service host&amp;gt;&lt;/STRONG&gt;:11434 (SASL(-1): generic failure: GSSAPI Error: Unspecified GSS failure. Minor code may provide more information (Server not found in Kerberos database))&lt;BR /&gt;E0321 08:30:34.713243 21927 authentication.cc:177] SASL message (Kerberos (internal)): GSSAPI Error: Unspecified GSS failure. Minor code may provide more information (Server not found in Kerberos database)&lt;BR /&gt;I0321 08:30:34.713331 21927 thrift-client.cc:94] Unable to connect to &amp;lt;&lt;STRONG&gt;fqdn of catalog service host&amp;gt;&lt;/STRONG&gt;:11434&lt;BR /&gt;I0321 08:30:34.713342 21927 statestore.cc:970] Unable to send heartbeat message to subscriber catalog-server@&amp;lt;&lt;STRONG&gt;fqdn of catalog service host&amp;gt;&lt;/STRONG&gt;:11426, received error: Couldn't open transport for &amp;lt;&lt;STRONG&gt;fqdn of catalog service host&amp;gt;&lt;/STRONG&gt;:11434 (SASL(-1): generic failure: GSSAPI Error: Unspecified GSS failure. Minor code may provide more information (Server not found in Kerberos database))&lt;BR /&gt;I0321 08:30:34.713347 21927 failure-detector.cc:91] 5 consecutive heartbeats failed for 'catalog-server@&amp;lt;&lt;STRONG&gt;fqdn of catalog service host&amp;gt;&lt;/STRONG&gt;:11426'. &lt;STRONG&gt;State is SUSPECTED&lt;/STRONG&gt;&lt;BR /&gt;E0321 08:30:35.725081 21928 authentication.cc:177] SASL message (Kerberos (internal)): GSSAPI Error: Unspecified GSS failure. Minor code may provide more information (Server not found in Kerberos database)&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 21 Mar 2022 08:49:35 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Kerberos-Authentication-Failure-Catalog-Server-Unable-to/m-p/338991#M232986</guid>
      <dc:creator>pandu2022</dc:creator>
      <dc:date>2022-03-21T08:49:35Z</dc:date>
    </item>
    <item>
      <title>Re: Kerberos Authentication Failure : Catalog Server Unable to Connect to Statestore Port</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Kerberos-Authentication-Failure-Catalog-Server-Unable-to/m-p/338993#M232987</link>
      <description>&lt;P&gt;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/11191"&gt;@araujo&lt;/a&gt;&amp;nbsp;yes im using a load balancer as well&lt;/P&gt;</description>
      <pubDate>Mon, 21 Mar 2022 09:07:17 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Kerberos-Authentication-Failure-Catalog-Server-Unable-to/m-p/338993#M232987</guid>
      <dc:creator>pandu2022</dc:creator>
      <dc:date>2022-03-21T09:07:17Z</dc:date>
    </item>
    <item>
      <title>Re: Kerberos Authentication Failure : Catalog Server Unable to Connect to Statestore Port</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Kerberos-Authentication-Failure-Catalog-Server-Unable-to/m-p/339059#M233009</link>
      <description>&lt;P&gt;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/96257"&gt;@pandu2022&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Where did you configure the customized service name for Impala?&lt;/P&gt;&lt;P&gt;Did you configure this since Impala was installed or was it initially using the default name and you later changed it?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;André&lt;/P&gt;</description>
      <pubDate>Mon, 21 Mar 2022 21:54:43 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Kerberos-Authentication-Failure-Catalog-Server-Unable-to/m-p/339059#M233009</guid>
      <dc:creator>araujo</dc:creator>
      <dc:date>2022-03-21T21:54:43Z</dc:date>
    </item>
    <item>
      <title>Re: Kerberos Authentication Failure : Catalog Server Unable to Connect to Statestore Port</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Kerberos-Authentication-Failure-Catalog-Server-Unable-to/m-p/339072#M233016</link>
      <description>&lt;P&gt;yes, initially i used a default service name as "&lt;STRONG&gt;impala&lt;/STRONG&gt;".but later for a requirement i needed to use customize the service name part in principal as "&lt;STRONG&gt;impala_test&lt;/STRONG&gt;".&amp;nbsp;&lt;BR /&gt;additionally, i tried including this customized service name in &lt;STRONG&gt;internal_principals_whitelist&lt;/STRONG&gt; parameter as well but no good.&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":sad_but_relieved_face:"&gt;😥&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/11191"&gt;@araujo&lt;/a&gt;&amp;nbsp;thank you very much for replying. kudos&lt;/P&gt;</description>
      <pubDate>Tue, 22 Mar 2022 03:29:38 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Kerberos-Authentication-Failure-Catalog-Server-Unable-to/m-p/339072#M233016</guid>
      <dc:creator>pandu2022</dc:creator>
      <dc:date>2022-03-22T03:29:38Z</dc:date>
    </item>
    <item>
      <title>Re: Kerberos Authentication Failure : Catalog Server Unable to Connect to Statestore Port</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Kerberos-Authentication-Failure-Catalog-Server-Unable-to/m-p/339073#M233017</link>
      <description>&lt;P&gt;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/11191"&gt;@araujo&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;i do not know where else to configure this customized service name for impala services.&lt;/P&gt;</description>
      <pubDate>Tue, 22 Mar 2022 03:32:36 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Kerberos-Authentication-Failure-Catalog-Server-Unable-to/m-p/339073#M233017</guid>
      <dc:creator>pandu2022</dc:creator>
      <dc:date>2022-03-22T03:32:36Z</dc:date>
    </item>
    <item>
      <title>Re: Kerberos Authentication Failure : Catalog Server Unable to Connect to Statestore Port</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Kerberos-Authentication-Failure-Catalog-Server-Unable-to/m-p/339074#M233018</link>
      <description>&lt;P&gt;Did you change this configuration in Cloudera Manager? Can you share screenshots of your configuration?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;André&lt;/P&gt;</description>
      <pubDate>Tue, 22 Mar 2022 03:52:19 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Kerberos-Authentication-Failure-Catalog-Server-Unable-to/m-p/339074#M233018</guid>
      <dc:creator>araujo</dc:creator>
      <dc:date>2022-03-22T03:52:19Z</dc:date>
    </item>
    <item>
      <title>Re: Kerberos Authentication Failure : Catalog Server Unable to Connect to Statestore Port</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Kerberos-Authentication-Failure-Catalog-Server-Unable-to/m-p/339076#M233020</link>
      <description>&lt;P&gt;We do not use Cloudera Manager to manage our impala cluster. It is a proprietary system. So I have limitations on sharing content here. Im sorry. We use start-up configs to start impala daemons to acquire expected behaviour .&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Thanks,&lt;BR /&gt;Panduka&lt;/P&gt;</description>
      <pubDate>Tue, 22 Mar 2022 05:57:09 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Kerberos-Authentication-Failure-Catalog-Server-Unable-to/m-p/339076#M233020</guid>
      <dc:creator>pandu2022</dc:creator>
      <dc:date>2022-03-22T05:57:09Z</dc:date>
    </item>
    <item>
      <title>Re: Kerberos Authentication Failure : Catalog Server Unable to Connect to Statestore Port</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Kerberos-Authentication-Failure-Catalog-Server-Unable-to/m-p/339078#M233022</link>
      <description>&lt;P&gt;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/96257"&gt;@pandu2022&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Understood. Just keep in mind that not knowing any details makes it more difficult to help.&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;What's your Kerberos KDC? (AD, MIT, FreeIPA, or other)&lt;/LI&gt;&lt;LI&gt;When you changed the Impala principal name, did you create the new principal in Kerberos? You need to make sure that all the principals "impala_test/&amp;lt;host&amp;gt;" exist in the KDC for all the hosts.&lt;/LI&gt;&lt;LI&gt;Did you regenerate the keytabs for all the &lt;STRONG&gt;Impala Daemons&lt;/STRONG&gt;, &lt;STRONG&gt;Catalog&lt;/STRONG&gt; and &lt;STRONG&gt;State Store&lt;/STRONG&gt; with the new principal name?&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;André&lt;/P&gt;&lt;P&gt;&lt;EM&gt;--&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;Was your question answered? Please take some time to click on "&lt;STRONG&gt;Accept as Solution&lt;/STRONG&gt;" below this post.&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;If you find a reply useful, say thanks by clicking on the thumbs up button.&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 22 Mar 2022 06:22:30 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Kerberos-Authentication-Failure-Catalog-Server-Unable-to/m-p/339078#M233022</guid>
      <dc:creator>araujo</dc:creator>
      <dc:date>2022-03-22T06:22:30Z</dc:date>
    </item>
    <item>
      <title>Re: Kerberos Authentication Failure : Catalog Server Unable to Connect to Statestore Port</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Kerberos-Authentication-Failure-Catalog-Server-Unable-to/m-p/339079#M233023</link>
      <description>&lt;P&gt;Hi &lt;SPAN&gt;André&lt;/SPAN&gt;,&lt;BR /&gt;Please find the in line comments,&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;What's your Kerberos KDC? (AD, MIT, FreeIPA, or other)&lt;BR /&gt;&lt;EM&gt;&lt;STRONG&gt;[AWS Managed AD]&lt;/STRONG&gt;&lt;/EM&gt;&lt;/LI&gt;&lt;LI&gt;When you changed the Impala principal name, did you create the new principal in Kerberos? You need to make sure that all the principals "impala_test/&amp;lt;host&amp;gt;" exist in the KDC for all the hosts.&lt;BR /&gt;&lt;EM&gt;&lt;STRONG&gt;[yes i created principals with customized service name]&lt;/STRONG&gt;&lt;/EM&gt;&lt;/LI&gt;&lt;LI&gt;Did you regenerate the keytabs for all the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Impala Daemons&lt;/STRONG&gt;,&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Catalog&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;and&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;State Store&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;with the new principal name?&lt;BR /&gt;&lt;EM&gt;&lt;STRONG&gt;[yes]&lt;/STRONG&gt;&lt;/EM&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;Thanks,&lt;BR /&gt;Panduka.&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 22 Mar 2022 06:27:43 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Kerberos-Authentication-Failure-Catalog-Server-Unable-to/m-p/339079#M233023</guid>
      <dc:creator>pandu2022</dc:creator>
      <dc:date>2022-03-22T06:27:43Z</dc:date>
    </item>
    <item>
      <title>Re: Kerberos Authentication Failure : Catalog Server Unable to Connect to Statestore Port</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Kerberos-Authentication-Failure-Catalog-Server-Unable-to/m-p/339080#M233024</link>
      <description>&lt;P&gt;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/96257"&gt;@pandu2022&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Have you updated the properties below for *&lt;STRONG&gt;all&lt;/STRONG&gt;* the Impala service roles (ID, catalog and statestore)?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;FONT face="courier new,courier"&gt;principal&lt;/FONT&gt;: When using a load-balancer this should be of the form &lt;FONT face="courier new,courier"&gt;impala_test/&amp;lt;LB_fqdn&amp;gt;@&amp;lt;REALM&amp;gt;&lt;/FONT&gt;. If not using a LB, this should be&amp;nbsp;&lt;FONT face="courier new,courier"&gt;impala_test/&amp;lt;host_fqdn&amp;gt;@&amp;lt;REALM&amp;gt;&lt;/FONT&gt;.&lt;/LI&gt;&lt;LI&gt;&lt;FONT face="courier new,courier"&gt;be_principal&lt;/FONT&gt;: This is only necessary when a LB is being used and should be of the form &lt;FONT face="courier new,courier"&gt;impala_test/&amp;lt;host_fqdn&amp;gt;@&amp;lt;REALM&amp;gt;&lt;/FONT&gt;.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;André&lt;/P&gt;&lt;P&gt;&lt;EM&gt;--&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;Was your question answered? Please take some time to click on "&lt;STRONG&gt;Accept as Solution&lt;/STRONG&gt;" below this post.&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;If you find a reply useful, say thanks by clicking on the thumbs up button.&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 22 Mar 2022 06:43:12 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Kerberos-Authentication-Failure-Catalog-Server-Unable-to/m-p/339080#M233024</guid>
      <dc:creator>araujo</dc:creator>
      <dc:date>2022-03-22T06:43:12Z</dc:date>
    </item>
    <item>
      <title>Re: Kerberos Authentication Failure : Catalog Server Unable to Connect to Statestore Port</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Kerberos-Authentication-Failure-Catalog-Server-Unable-to/m-p/339081#M233025</link>
      <description>&lt;P&gt;Hi,&lt;BR /&gt;everything works fine for "&lt;STRONG&gt;impala&lt;/STRONG&gt;" service name. but I will try and let you know. Thank you very much.&lt;BR /&gt;&lt;BR /&gt;Thanks,&lt;BR /&gt;Panduka.&lt;/P&gt;</description>
      <pubDate>Tue, 22 Mar 2022 06:47:03 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Kerberos-Authentication-Failure-Catalog-Server-Unable-to/m-p/339081#M233025</guid>
      <dc:creator>pandu2022</dc:creator>
      <dc:date>2022-03-22T06:47:03Z</dc:date>
    </item>
    <item>
      <title>Re: Kerberos Authentication Failure : Catalog Server Unable to Connect to Statestore Port</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Kerberos-Authentication-Failure-Catalog-Server-Unable-to/m-p/339133#M233052</link>
      <description>&lt;P&gt;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/96257"&gt;@pandu2022&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have feeling that your kerberos principle doesn't exist on the KDC server. On the statestore server can you try running "kinit&amp;nbsp;&lt;SPAN&gt;impala_test/&amp;lt;host_fqdn&amp;gt;@&amp;lt;REALM&amp;gt;". If you get prompt for password that indicate your principle is exist on KDC server. If you get error (not found in kerberos database) when you kinit, that indicate your principle doesn't exist on the KDC server.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;If the kinit works from catalog server, then most likely on statestore you are using different KDC server. In this case m&lt;/SPAN&gt;&lt;SPAN&gt;ay be you should check your /etc/krb5.conf to make sure there are match.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;rgds,&lt;/P&gt;&lt;P&gt;Ram.&lt;/P&gt;</description>
      <pubDate>Tue, 22 Mar 2022 17:34:40 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Kerberos-Authentication-Failure-Catalog-Server-Unable-to/m-p/339133#M233052</guid>
      <dc:creator>ram76</dc:creator>
      <dc:date>2022-03-22T17:34:40Z</dc:date>
    </item>
    <item>
      <title>Re: Kerberos Authentication Failure : Catalog Server Unable to Connect to Statestore Port</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Kerberos-Authentication-Failure-Catalog-Server-Unable-to/m-p/339328#M233072</link>
      <description>&lt;P&gt;Hi Ram,&lt;BR /&gt;kinit works fine in both of the servers as expected and no difference in krb5.conf files as well.&lt;BR /&gt;&lt;BR /&gt;Thanks,&lt;BR /&gt;Panduka.&lt;/P&gt;</description>
      <pubDate>Wed, 23 Mar 2022 10:31:35 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Kerberos-Authentication-Failure-Catalog-Server-Unable-to/m-p/339328#M233072</guid>
      <dc:creator>pandu2022</dc:creator>
      <dc:date>2022-03-23T10:31:35Z</dc:date>
    </item>
    <item>
      <title>Re: Kerberos Authentication Failure : Catalog Server Unable to Connect to Statestore Port</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Kerberos-Authentication-Failure-Catalog-Server-Unable-to/m-p/339362#M233073</link>
      <description>&lt;P&gt;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/11191"&gt;@araujo&lt;/a&gt;&amp;nbsp;/&amp;nbsp;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/71237"&gt;@ram76&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;should the backend host fqdn be accessible from the KDC server. I am using a custom fqdn for hosts which are accessible within the cluster but KDC can access only the LB fqdn.is this an issue? any comments?&lt;/P&gt;</description>
      <pubDate>Wed, 23 Mar 2022 10:37:52 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Kerberos-Authentication-Failure-Catalog-Server-Unable-to/m-p/339362#M233073</guid>
      <dc:creator>pandu2022</dc:creator>
      <dc:date>2022-03-23T10:37:52Z</dc:date>
    </item>
    <item>
      <title>Re: Kerberos Authentication Failure : Catalog Server Unable to Connect to Statestore Port</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Kerberos-Authentication-Failure-Catalog-Server-Unable-to/m-p/339624#M233141</link>
      <description>&lt;P&gt;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/96257"&gt;@pandu2022&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The KDC does not need to connect to Impala servers.&lt;/P&gt;&lt;P&gt;Do you happen to have multiple realms in your environment with cross-realm trust configured between them?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Could you please run the below commands and share the output?&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;kinit &amp;lt;your_user&amp;gt;
kvno impala/&amp;lt;host_fqdn&amp;gt;@&amp;lt;REALM&amp;gt;
kvno impala_test/&amp;lt;host_fqdn&amp;gt;@&amp;lt;REALM&amp;gt;&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;André&lt;/P&gt;&lt;P&gt;&lt;EM&gt;--&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;Was your question answered? Please take some time to click on "&lt;STRONG&gt;Accept as Solution&lt;/STRONG&gt;" below this post.&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;If you find a reply useful, say thanks by clicking on the thumbs up button.&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 25 Mar 2022 00:17:45 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Kerberos-Authentication-Failure-Catalog-Server-Unable-to/m-p/339624#M233141</guid>
      <dc:creator>araujo</dc:creator>
      <dc:date>2022-03-25T00:17:45Z</dc:date>
    </item>
    <item>
      <title>Re: Kerberos Authentication Failure : Catalog Server Unable to Connect to Statestore Port</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Kerberos-Authentication-Failure-Catalog-Server-Unable-to/m-p/339681#M233153</link>
      <description>&lt;P&gt;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/11191"&gt;@araujo&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;OMG!!&lt;/P&gt;&lt;P&gt;kinit &amp;lt;user&amp;gt; - works fine&lt;/P&gt;&lt;P&gt;kvno impala/&amp;lt;host fqdn&amp;gt; - works fine&lt;/P&gt;&lt;P&gt;but,&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;kvno impala_test/&amp;lt;host fqdn&amp;gt; - not working !!!&lt;/STRONG&gt;&lt;BR /&gt;kvno: Server not found in Kerberos database while getting credentials for impala_test/&amp;lt;host fqdn&amp;gt;@domain&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 25 Mar 2022 11:18:59 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Kerberos-Authentication-Failure-Catalog-Server-Unable-to/m-p/339681#M233153</guid>
      <dc:creator>pandu2022</dc:creator>
      <dc:date>2022-03-25T11:18:59Z</dc:date>
    </item>
    <item>
      <title>Re: Kerberos Authentication Failure : Catalog Server Unable to Connect to Statestore Port</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Kerberos-Authentication-Failure-Catalog-Server-Unable-to/m-p/339682#M233154</link>
      <description>&lt;P&gt;and additionally ,&lt;BR /&gt;what does this kvno command do?&lt;BR /&gt;when i kinit relavant keytab for impala_test/&amp;lt;host fqdn&amp;gt;@domain. it works fine. but kvno command does not.&lt;/P&gt;</description>
      <pubDate>Fri, 25 Mar 2022 11:20:38 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Kerberos-Authentication-Failure-Catalog-Server-Unable-to/m-p/339682#M233154</guid>
      <dc:creator>pandu2022</dc:creator>
      <dc:date>2022-03-25T11:20:38Z</dc:date>
    </item>
    <item>
      <title>Re: Kerberos Authentication Failure : Catalog Server Unable to Connect to Statestore Port</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Kerberos-Authentication-Failure-Catalog-Server-Unable-to/m-p/339701#M233157</link>
      <description>&lt;P&gt;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/96257"&gt;@pandu2022&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please check the servicePrincipalName (SPN) property of the AD user. It should be impala_test/&amp;lt;host&amp;gt;@realm.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;André&lt;/P&gt;</description>
      <pubDate>Fri, 25 Mar 2022 12:43:13 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Kerberos-Authentication-Failure-Catalog-Server-Unable-to/m-p/339701#M233157</guid>
      <dc:creator>araujo</dc:creator>
      <dc:date>2022-03-25T12:43:13Z</dc:date>
    </item>
  </channel>
</rss>

