<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>question URGENT: Enabling AD KDC on CDP 7.1.7 in Support Questions</title>
    <link>https://community.cloudera.com/t5/Support-Questions/URGENT-Enabling-AD-KDC-on-CDP-7-1-7/m-p/361577#M238629</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am in process of setting up a CDP 7.1.7 cluster.&lt;/P&gt;&lt;P&gt;At the moment, CM 7.6.1 is installed and integrated to AD on LDAPS protocol (Had to select authentication type as LDAP for the integration to work even though we have AD being used).&lt;/P&gt;&lt;P&gt;Next step is I have added few basic services i.e. HDFS, YARN and Zookeeper and now I am enabling Kerberos.&lt;/P&gt;&lt;P&gt;At the step of Generating credentials it fails with attached screenshot.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="snm1523_0-1673995944778.png" style="width: 400px;"&gt;&lt;img src="https://community.cloudera.com/t5/image/serverpage/image-id/36628iEFB41E92C347C8AF/image-size/medium?v=v2&amp;amp;px=400" role="button" title="snm1523_0-1673995944778.png" alt="snm1523_0-1673995944778.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;However, in the same window I noticed that CM is trying to connect to AD on LDAP protocol on port 389. Ideally it should be connecting via LDAPS on 636 as we have TLS also configured and enabled. Not sure if this is even relevant.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;From where does CM gets the LDAP URL? I tried to understand&amp;nbsp;&lt;STRONG&gt;gen_credentials_ad.sh&lt;/STRONG&gt; script at /opt/cloudera/cm/bin, however, did not completely interpret.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please help as this is bit urgent.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;snm1523&lt;/P&gt;</description>
    <pubDate>Tue, 17 Jan 2023 22:58:08 GMT</pubDate>
    <dc:creator>snm1523</dc:creator>
    <dc:date>2023-01-17T22:58:08Z</dc:date>
    <item>
      <title>URGENT: Enabling AD KDC on CDP 7.1.7</title>
      <link>https://community.cloudera.com/t5/Support-Questions/URGENT-Enabling-AD-KDC-on-CDP-7-1-7/m-p/361577#M238629</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am in process of setting up a CDP 7.1.7 cluster.&lt;/P&gt;&lt;P&gt;At the moment, CM 7.6.1 is installed and integrated to AD on LDAPS protocol (Had to select authentication type as LDAP for the integration to work even though we have AD being used).&lt;/P&gt;&lt;P&gt;Next step is I have added few basic services i.e. HDFS, YARN and Zookeeper and now I am enabling Kerberos.&lt;/P&gt;&lt;P&gt;At the step of Generating credentials it fails with attached screenshot.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="snm1523_0-1673995944778.png" style="width: 400px;"&gt;&lt;img src="https://community.cloudera.com/t5/image/serverpage/image-id/36628iEFB41E92C347C8AF/image-size/medium?v=v2&amp;amp;px=400" role="button" title="snm1523_0-1673995944778.png" alt="snm1523_0-1673995944778.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;However, in the same window I noticed that CM is trying to connect to AD on LDAP protocol on port 389. Ideally it should be connecting via LDAPS on 636 as we have TLS also configured and enabled. Not sure if this is even relevant.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;From where does CM gets the LDAP URL? I tried to understand&amp;nbsp;&lt;STRONG&gt;gen_credentials_ad.sh&lt;/STRONG&gt; script at /opt/cloudera/cm/bin, however, did not completely interpret.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please help as this is bit urgent.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;snm1523&lt;/P&gt;</description>
      <pubDate>Tue, 17 Jan 2023 22:58:08 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/URGENT-Enabling-AD-KDC-on-CDP-7-1-7/m-p/361577#M238629</guid>
      <dc:creator>snm1523</dc:creator>
      <dc:date>2023-01-17T22:58:08Z</dc:date>
    </item>
    <item>
      <title>Re: URGENT: Enabling AD KDC on CDP 7.1.7</title>
      <link>https://community.cloudera.com/t5/Support-Questions/URGENT-Enabling-AD-KDC-on-CDP-7-1-7/m-p/361735#M238649</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/12773"&gt;@snm1523&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;The exit code 50 refers to the LDAP error code, which translates to '&lt;STRONG&gt;insufficientAccessRights&lt;/STRONG&gt;'. Cloudera Manager Server must have the correct Kerberos principal configured. Specifically, Cloudera Manager Server must have a Kerberos principal that has privileges to create other accounts in Active Directory.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Make sure that the&amp;nbsp;Cloudera Manager Server account&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;does&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;have the ability to create/delete accounts in Active Directory and that it&amp;nbsp;&lt;STRONG&gt;does&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt;belong to a Global group.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Ref:&amp;nbsp;&lt;A href="https://docs.cloudera.com/cdp-private-cloud-base/7.1.6/security-kerberos-authentication/topics/cm-security-kerberos-enabling-step3-cm-principal.html" target="_blank"&gt;https://docs.cloudera.com/cdp-private-cloud-base/7.1.6/security-kerberos-authentication/topics/cm-security-kerberos-enabling-step3-cm-principal.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="p1"&gt;Hope this helps,&lt;/P&gt;&lt;P class="p1"&gt;Tarun&lt;/P&gt;&lt;P class="p1"&gt;&lt;STRONG&gt;&lt;I&gt;Was your question answered? Make sure to mark the answer as the accepted solution.&lt;/I&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;STRONG&gt;&lt;I&gt;If you find a reply useful, say thanks by clicking on the thumbs-up button.&lt;/I&gt;&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 19 Jan 2023 04:14:23 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/URGENT-Enabling-AD-KDC-on-CDP-7-1-7/m-p/361735#M238649</guid>
      <dc:creator>tj2007</dc:creator>
      <dc:date>2023-01-19T04:14:23Z</dc:date>
    </item>
    <item>
      <title>Re: URGENT: Enabling AD KDC on CDP 7.1.7</title>
      <link>https://community.cloudera.com/t5/Support-Questions/URGENT-Enabling-AD-KDC-on-CDP-7-1-7/m-p/361746#M238651</link>
      <description>&lt;P&gt;Thank you for the response &lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/99744"&gt;@tj2007&lt;/a&gt;. We have ensured that the required permissions are assigned to the account that is provided to Cloudera to create principals.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;we further tweaked some settings and also after a quick modification to gen_credentials_ad.sh script (post discussion with Cloudera support) got through with error. However, now getting below error:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="514532AC-0CAA-4AEF-9B6B-EBB51A0C8DCD.jpeg" style="width: 1112px;"&gt;&lt;img src="https://community.cloudera.com/t5/image/serverpage/image-id/36635iC7074B9A4B6D76C3/image-size/medium?v=v2&amp;amp;px=400" role="button" title="514532AC-0CAA-4AEF-9B6B-EBB51A0C8DCD.jpeg" alt="514532AC-0CAA-4AEF-9B6B-EBB51A0C8DCD.jpeg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;We have scheduled a call later today with Cloudera once again to discuss this. However, if you may be able to suggest something would be helpful.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Thanks&lt;/P&gt;&lt;P&gt;snm1523&lt;/P&gt;</description>
      <pubDate>Thu, 19 Jan 2023 07:15:33 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/URGENT-Enabling-AD-KDC-on-CDP-7-1-7/m-p/361746#M238651</guid>
      <dc:creator>snm1523</dc:creator>
      <dc:date>2023-01-19T07:15:33Z</dc:date>
    </item>
    <item>
      <title>Re: URGENT: Enabling AD KDC on CDP 7.1.7</title>
      <link>https://community.cloudera.com/t5/Support-Questions/URGENT-Enabling-AD-KDC-on-CDP-7-1-7/m-p/363388#M238968</link>
      <description>&lt;P&gt;Was able to get this fixed. We ultimately identified there were some permissions for child objects not given yet. We got on a call with AD team and asked for a screen share to validate the permissions and then found it is not assigned yet.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Wed, 08 Feb 2023 11:22:58 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/URGENT-Enabling-AD-KDC-on-CDP-7-1-7/m-p/363388#M238968</guid>
      <dc:creator>snm1523</dc:creator>
      <dc:date>2023-02-08T11:22:58Z</dc:date>
    </item>
  </channel>
</rss>

