<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>question Re: [KERBEROS] Failed to kinit as the KDC administrator user, admin/admin@HADOOP.COM in Support Questions</title>
    <link>https://community.cloudera.com/t5/Support-Questions/KERBEROS-Failed-to-kinit-as-the-KDC-administrator-user-admin/m-p/388792#M246781</link>
    <description>&lt;P&gt;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/20288"&gt;@Shelton&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;&lt;STRONG&gt;/etc/host&lt;/STRONG&gt;&lt;/P&gt;&lt;LI-SPOILER&gt;root@master1:~# hostname -f&lt;BR /&gt;master1.hadoop.com&lt;/LI-SPOILER&gt;&lt;P&gt;&lt;SPAN&gt;/etc/hosts&lt;/SPAN&gt;&lt;/P&gt;&lt;LI-SPOILER&gt;&lt;P&gt;&lt;BR /&gt;127.0.0.1 localhost&lt;BR /&gt;192.168.122.10 master1.hadoop.com&lt;BR /&gt;192.168.122.11 slave1.hadoop.com&lt;BR /&gt;192.168.122.12 slave2.hadoop.com&lt;BR /&gt;# The following lines are desirable for IPv6 capable hosts&lt;BR /&gt;::1 ip6-localhost ip6-loopback&lt;BR /&gt;fe00::0 ip6-localnet&lt;BR /&gt;ff00::0 ip6-mcastprefix&lt;BR /&gt;ff02::1 ip6-allnodes&lt;BR /&gt;ff02::2 ip6-allrouters&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;/LI-SPOILER&gt;&lt;P&gt;&lt;SPAN&gt;/etc/krb5.conf&lt;/SPAN&gt;&lt;/P&gt;&lt;LI-SPOILER&gt;&lt;P&gt;[libdefaults]&lt;BR /&gt;renew_lifetime = 7d&lt;BR /&gt;forwardable = true&lt;BR /&gt;default_realm = HADOOP.COM&lt;BR /&gt;ticket_lifetime = 24h&lt;BR /&gt;dns_lookup_realm = false&lt;BR /&gt;dns_lookup_kdc = false&lt;BR /&gt;default_ccache_name = /tmp/krb5cc_%{uid}&lt;BR /&gt;#default_tgs_enctypes = aes des3-cbc-sha1 rc4 des-cbc-md5&lt;BR /&gt;#default_tkt_enctypes = aes des3-cbc-sha1 rc4 des-cbc-md5&lt;/P&gt;&lt;P&gt;[logging]&lt;BR /&gt;default = FILE:/var/log/krb5kdc.log&lt;BR /&gt;admin_server = FILE:/var/log/kadmind.log&lt;BR /&gt;kdc = FILE:/var/log/krb5kdc.log&lt;/P&gt;&lt;P&gt;[realms]&lt;BR /&gt;HADOOP.COM = {&lt;BR /&gt;admin_server = master1.hadoop.com&lt;BR /&gt;kdc = master1.hadoop.com&lt;BR /&gt;}&lt;/P&gt;&lt;/LI-SPOILER&gt;&lt;P&gt;kadm5.acl&lt;/P&gt;&lt;LI-SPOILER&gt;*/admin@HADOOP.COM *&lt;/LI-SPOILER&gt;&lt;P&gt;event create ticket show error&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;root@master1:~# systemctl restart krb5-kdc
root@master1:~# systemctl restart krb5-admin-server
root@master1:~# kinit -kt /etc/security/keytabs/hdfs.keytab hdfs/master1.hadoop.com@HADOOP.COM
kinit: Client 'hdfs/master1.hadoop.com@HADOOP.COM' not found in Kerberos database while getting initial credentials&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 05 Jun 2024 08:07:39 GMT</pubDate>
    <dc:creator>rizalt</dc:creator>
    <dc:date>2024-06-05T08:07:39Z</dc:date>
    <item>
      <title>[KERBEROS] Failed to kinit as the KDC administrator user, admin/admin@HADOOP.COM</title>
      <link>https://community.cloudera.com/t5/Support-Questions/KERBEROS-Failed-to-kinit-as-the-KDC-administrator-user-admin/m-p/388748#M246757</link>
      <description>&lt;P&gt;Hallo,&lt;/P&gt;&lt;P&gt;When to enable Kerberos via ambari, &lt;SPAN&gt;I am facing the following window popup at the time of Testing client after client installation saying&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="rizalt_0-1717483147659.png" style="width: 400px;"&gt;&lt;img src="https://community.cloudera.com/t5/image/serverpage/image-id/40875i1B715F1C4EFD5678/image-size/medium?v=v2&amp;amp;px=400" role="button" title="rizalt_0-1717483147659.png" alt="rizalt_0-1717483147659.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;in my log ambari-server listed below&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;2024-06-04 06:27:43,380  WARN [agent-report-processor-2] ActionManager:162 - The task 76 is not in progress, ignoring update
2024-06-04 06:27:43,861  INFO [ambari-client-thread-6248] AmbariManagementControllerImpl:4086 - Received action execution request, clusterName=hadoop, request=isCommand :true, action :null, command :KERBEROS_SERVICE_CHECK, inputs :{HAS_RESOURCE_FILTERS=true}, resourceFilters: [RequestResourceFilter{serviceName='KERBEROS', componentName='null', hostNames=[]}], exclusive: false, clusterName :hadoop
2024-06-04 06:27:44,149  WARN [ambari-client-thread-6248] KDCKerberosOperationHandler:329 - Failed to kinit as the KDC administrator user, admin/admin@HADOOP.COM:
	ExitCode: 1
	STDOUT: 
	STDERR: kinit: Server not found in Kerberos database while getting initial credentials

2024-06-04 06:27:44,151 ERROR [ambari-client-thread-6248] KerberosHelperImpl:2507 - Cannot validate credentials: org.apache.ambari.server.serveraction.kerberos.KerberosAdminAuthenticationException: Invalid KDC administrator credentials.
The KDC administrator credentials must be set as a persisted or temporary credential resource.This may be done by issuing a POST (or PUT for updating) to the /api/v1/clusters/:clusterName/credentials/kdc.admin.credential API entry point with the following payload:
{
  "Credential" : {
    "principal" : "(PRINCIPAL)", "key" : "(PASSWORD)", "type" : "(persisted|temporary)"}
  }
}
2024-06-04 06:27:44,152 ERROR [ambari-client-thread-6248] CreateHandler:80 - Bad request received: Invalid KDC administrator credentials.
The KDC administrator credentials must be set as a persisted or temporary credential resource.This may be done by issuing a POST (or PUT for updating) to the /api/v1/clusters/:clusterName/credentials/kdc.admin.credential API entry point with the following payload:
{
  "Credential" : {
    "principal" : "(PRINCIPAL)", "key" : "(PASSWORD)", "type" : "(persisted|temporary)"}
  }
}
2024-06-04 06:27:44,578  WARN [agent-report-processor-1] ActionManager:162 - The task 75 is not in progress, ignoring update&lt;/LI-CODE&gt;&lt;P&gt;can anyone help me, please..&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 04 Jun 2024 06:42:19 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/KERBEROS-Failed-to-kinit-as-the-KDC-administrator-user-admin/m-p/388748#M246757</guid>
      <dc:creator>rizalt</dc:creator>
      <dc:date>2024-06-04T06:42:19Z</dc:date>
    </item>
    <item>
      <title>Re: [KERBEROS] Failed to kinit as the KDC administrator user, admin/admin@HADOOP.COM</title>
      <link>https://community.cloudera.com/t5/Support-Questions/KERBEROS-Failed-to-kinit-as-the-KDC-administrator-user-admin/m-p/388787#M246777</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/109307"&gt;@rizalt&lt;/a&gt;&amp;nbsp;, Have you tried logging in with "kinit admin/admin@HADOOP.COM" from one of your cluster nodes or ambari server to see if krb5.conf is fine and can find this user/principal in the KDC server with the given password?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 05 Jun 2024 06:57:48 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/KERBEROS-Failed-to-kinit-as-the-KDC-administrator-user-admin/m-p/388787#M246777</guid>
      <dc:creator>Majeti</dc:creator>
      <dc:date>2024-06-05T06:57:48Z</dc:date>
    </item>
    <item>
      <title>Re: [KERBEROS] Failed to kinit as the KDC administrator user, admin/admin@HADOOP.COM</title>
      <link>https://community.cloudera.com/t5/Support-Questions/KERBEROS-Failed-to-kinit-as-the-KDC-administrator-user-admin/m-p/388788#M246778</link>
      <description>&lt;P&gt;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/77242"&gt;@Majed&lt;/a&gt;&amp;nbsp; im my cluster master1,slave1 &amp;amp; slave2 kinit logged in fine without errors, listed below&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;root@master1:~# kinit admin/admin@HADOOP.COM
Password for admin/admin@HADOOP.COM:
root@master1:~# klist
Ticket cache: FILE:/tmp/krb5cc_0
Default principal: admin/admin@HADOOP.COM

Valid starting       Expires              Service principal
06/05/2024 07:17:16  06/05/2024 17:17:16  krbtgt/HADOOP.COM@HADOOP.COM
        renew until 06/05/2024 07:17:16
root@master1:~#
&lt;/LI-CODE&gt;&lt;LI-CODE lang="markup"&gt;root@slave1:~# kinit admin/admin@HADOOP.COM
Password for admin/admin@HADOOP.COM:
root@slave1:~# klist
Ticket cache: FILE:/tmp/krb5cc_0
Default principal: admin/admin@HADOOP.COM

Valid starting       Expires              Service principal
06/05/2024 07:19:26  06/05/2024 17:19:26  krbtgt/HADOOP.COM@HADOOP.COM
        renew until 06/05/2024 07:19:26
root@slave1:~#&lt;/LI-CODE&gt;&lt;LI-CODE lang="markup"&gt;root@slave2:~# kinit admin/admin@HADOOP.COM
Password for admin/admin@HADOOP.COM:
root@slave2:~# klist
Ticket cache: FILE:/tmp/krb5cc_0
Default principal: admin/admin@HADOOP.COM

Valid starting       Expires              Service principal
06/05/2024 07:20:19  06/05/2024 17:20:19  krbtgt/HADOOP.COM@HADOOP.COM
        renew until 06/05/2024 07:20:19
root@slave2:~#&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 05 Jun 2024 07:23:49 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/KERBEROS-Failed-to-kinit-as-the-KDC-administrator-user-admin/m-p/388788#M246778</guid>
      <dc:creator>rizalt</dc:creator>
      <dc:date>2024-06-05T07:23:49Z</dc:date>
    </item>
    <item>
      <title>Re: [KERBEROS] Failed to kinit as the KDC administrator user, admin/admin@HADOOP.COM</title>
      <link>https://community.cloudera.com/t5/Support-Questions/KERBEROS-Failed-to-kinit-as-the-KDC-administrator-user-admin/m-p/388790#M246780</link>
      <description>&lt;P&gt;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/109307"&gt;@rizalt&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;There are a couple of things to validate.&lt;BR /&gt;&lt;STRONG&gt;Step 1 Pre-requisites&lt;/STRONG&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Kerberos Server: Ensure you have a Kerberos Key Distribution Center (KDC) and an administrative server set up.&lt;/LI&gt;&lt;LI&gt;DNS: Proper DNS setup is required for both forward and reverse lookups.&lt;BR /&gt;NTP: Time synchronization across all nodes using Network Time Protocol (NTP).&lt;/LI&gt;&lt;LI&gt;HDP Cluster: A running Hortonworks Data Platform (HDP) cluster.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;STRONG&gt;Step 2:&lt;/STRONG&gt;&amp;nbsp; Check your &lt;STRONG&gt;/etc/host&lt;/STRONG&gt; file ensure your KDC host is assigned the domain HADOOP.COM to match your KDC credentials&lt;/P&gt;&lt;LI-SPOILER&gt;# hostname -f&lt;/LI-SPOILER&gt;&lt;P&gt;&lt;STRONG&gt;Step 3&lt;/STRONG&gt;: Once that matches then edit the Kerberos configuration file (/etc/krb5.conf) on all nodes to point to your KDC you can scramble the sensitive info and share&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-SPOILER&gt;&lt;P&gt;[libdefaults]&lt;BR /&gt;default_realm = HADOOP.COM&lt;BR /&gt;dns_lookup_realm = false&lt;BR /&gt;dns_lookup_kdc = false&lt;/P&gt;&lt;P&gt;[realms]&lt;BR /&gt;HADOOP.COM = {&lt;BR /&gt;kdc = kdc.hadoop.com&lt;BR /&gt;admin_server = admin.hadoop.com&lt;BR /&gt;}&lt;/P&gt;&lt;P&gt;[domain_realm]&lt;BR /&gt;.hadoop.com = HADOOP.COM&lt;BR /&gt;hadoop.com = HADOOP.COM&lt;/P&gt;&lt;/LI-SPOILER&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Step 4:&lt;/STRONG&gt; Locate your kadm5.acl file and ensure it looks like this&lt;/P&gt;&lt;LI-SPOILER&gt;*/admin@HADOOP.COM *&lt;/LI-SPOILER&gt;&lt;P&gt;&lt;STRONG&gt;Step 5:&lt;/STRONG&gt; Restart the KDC and admin servers as root or with sudo&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-SPOILER&gt;&lt;P&gt;# systemctl restart krb5kdc&lt;/P&gt;&lt;P&gt;# systemctl restart kadmin&lt;/P&gt;&lt;/LI-SPOILER&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;STRONG&gt;Step 6:&lt;/STRONG&gt; Check Kerberos Ticket: Ensure that the Kerberos ticket is obtained correctly.&lt;/P&gt;&lt;LI-SPOILER&gt;kinit -kt /etc/security/keytabs/hdfs.keytab hdfs/hostname@HADOOP.COM&lt;BR /&gt;klist&lt;/LI-SPOILER&gt;&lt;P&gt;If your setup is correct you will see an output like below&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-SPOILER&gt;&lt;P&gt;Ticket cache: FILE:/tmp/krb5cc_1000&lt;BR /&gt;Default principal: hdfs/hostname@HADOOP.COM&lt;/P&gt;&lt;P&gt;Valid starting Expires Service principal&lt;BR /&gt;06/05/2024 09:50:21 06/06/2024 09:50:21 krbtgt/HADOOP.COM@HADOOP.COM&lt;BR /&gt;renew until 06/05/2024 09:50:21&lt;BR /&gt;06/05/2024 09:50:22 06/06/2024 09:50:21 HTTP/hostname@HADOOP.COM&lt;BR /&gt;renew until 06/05/2024 09:50:21&lt;/P&gt;&lt;/LI-SPOILER&gt;&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Hope that helps&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 05 Jun 2024 07:51:54 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/KERBEROS-Failed-to-kinit-as-the-KDC-administrator-user-admin/m-p/388790#M246780</guid>
      <dc:creator>Shelton</dc:creator>
      <dc:date>2024-06-05T07:51:54Z</dc:date>
    </item>
    <item>
      <title>Re: [KERBEROS] Failed to kinit as the KDC administrator user, admin/admin@HADOOP.COM</title>
      <link>https://community.cloudera.com/t5/Support-Questions/KERBEROS-Failed-to-kinit-as-the-KDC-administrator-user-admin/m-p/388792#M246781</link>
      <description>&lt;P&gt;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/20288"&gt;@Shelton&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;&lt;STRONG&gt;/etc/host&lt;/STRONG&gt;&lt;/P&gt;&lt;LI-SPOILER&gt;root@master1:~# hostname -f&lt;BR /&gt;master1.hadoop.com&lt;/LI-SPOILER&gt;&lt;P&gt;&lt;SPAN&gt;/etc/hosts&lt;/SPAN&gt;&lt;/P&gt;&lt;LI-SPOILER&gt;&lt;P&gt;&lt;BR /&gt;127.0.0.1 localhost&lt;BR /&gt;192.168.122.10 master1.hadoop.com&lt;BR /&gt;192.168.122.11 slave1.hadoop.com&lt;BR /&gt;192.168.122.12 slave2.hadoop.com&lt;BR /&gt;# The following lines are desirable for IPv6 capable hosts&lt;BR /&gt;::1 ip6-localhost ip6-loopback&lt;BR /&gt;fe00::0 ip6-localnet&lt;BR /&gt;ff00::0 ip6-mcastprefix&lt;BR /&gt;ff02::1 ip6-allnodes&lt;BR /&gt;ff02::2 ip6-allrouters&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;/LI-SPOILER&gt;&lt;P&gt;&lt;SPAN&gt;/etc/krb5.conf&lt;/SPAN&gt;&lt;/P&gt;&lt;LI-SPOILER&gt;&lt;P&gt;[libdefaults]&lt;BR /&gt;renew_lifetime = 7d&lt;BR /&gt;forwardable = true&lt;BR /&gt;default_realm = HADOOP.COM&lt;BR /&gt;ticket_lifetime = 24h&lt;BR /&gt;dns_lookup_realm = false&lt;BR /&gt;dns_lookup_kdc = false&lt;BR /&gt;default_ccache_name = /tmp/krb5cc_%{uid}&lt;BR /&gt;#default_tgs_enctypes = aes des3-cbc-sha1 rc4 des-cbc-md5&lt;BR /&gt;#default_tkt_enctypes = aes des3-cbc-sha1 rc4 des-cbc-md5&lt;/P&gt;&lt;P&gt;[logging]&lt;BR /&gt;default = FILE:/var/log/krb5kdc.log&lt;BR /&gt;admin_server = FILE:/var/log/kadmind.log&lt;BR /&gt;kdc = FILE:/var/log/krb5kdc.log&lt;/P&gt;&lt;P&gt;[realms]&lt;BR /&gt;HADOOP.COM = {&lt;BR /&gt;admin_server = master1.hadoop.com&lt;BR /&gt;kdc = master1.hadoop.com&lt;BR /&gt;}&lt;/P&gt;&lt;/LI-SPOILER&gt;&lt;P&gt;kadm5.acl&lt;/P&gt;&lt;LI-SPOILER&gt;*/admin@HADOOP.COM *&lt;/LI-SPOILER&gt;&lt;P&gt;event create ticket show error&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;root@master1:~# systemctl restart krb5-kdc
root@master1:~# systemctl restart krb5-admin-server
root@master1:~# kinit -kt /etc/security/keytabs/hdfs.keytab hdfs/master1.hadoop.com@HADOOP.COM
kinit: Client 'hdfs/master1.hadoop.com@HADOOP.COM' not found in Kerberos database while getting initial credentials&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 05 Jun 2024 08:07:39 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/KERBEROS-Failed-to-kinit-as-the-KDC-administrator-user-admin/m-p/388792#M246781</guid>
      <dc:creator>rizalt</dc:creator>
      <dc:date>2024-06-05T08:07:39Z</dc:date>
    </item>
    <item>
      <title>Re: [KERBEROS] Failed to kinit as the KDC administrator user, admin/admin@HADOOP.COM</title>
      <link>https://community.cloudera.com/t5/Support-Questions/KERBEROS-Failed-to-kinit-as-the-KDC-administrator-user-admin/m-p/388802#M246788</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/109307"&gt;@rizalt&lt;/a&gt;&amp;nbsp;, You want to verify if the principal exists in the KDC admin database ?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;kadmin:&lt;/STRONG&gt; listprincs hdfs*&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 05 Jun 2024 11:33:59 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/KERBEROS-Failed-to-kinit-as-the-KDC-administrator-user-admin/m-p/388802#M246788</guid>
      <dc:creator>Majeti</dc:creator>
      <dc:date>2024-06-05T11:33:59Z</dc:date>
    </item>
    <item>
      <title>Re: [KERBEROS] Failed to kinit as the KDC administrator user, admin/admin@HADOOP.COM</title>
      <link>https://community.cloudera.com/t5/Support-Questions/KERBEROS-Failed-to-kinit-as-the-KDC-administrator-user-admin/m-p/388830#M246795</link>
      <description>&lt;P&gt;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/32680"&gt;@Majeti&lt;/a&gt;&amp;nbsp;. my issue is&amp;nbsp; when Ambari tests Kerberos client always shows a dialog box like this&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="rizalt_1-1717633792307.png" style="width: 400px;"&gt;&lt;img src="https://community.cloudera.com/t5/image/serverpage/image-id/40887iA8574999E2D917BF/image-size/medium?v=v2&amp;amp;px=400" role="button" title="rizalt_1-1717633792307.png" alt="rizalt_1-1717633792307.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;My previous settings were like this&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="rizalt_0-1717633749850.png" style="width: 400px;"&gt;&lt;img src="https://community.cloudera.com/t5/image/serverpage/image-id/40886iFAED246087D86ADA/image-size/medium?v=v2&amp;amp;px=400" role="button" title="rizalt_0-1717633749850.png" alt="rizalt_0-1717633749850.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;I have the principal admin/admin@HADOOP.COM and the password is correct,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;root@master1:~# kadmin -p admin/admin
Authenticating as principal admin/admin with password.
Password for admin/admin@HADOOP.COM:
kadmin:  listprincs
HTTP/master1.hadoop.com@HADOOP.COM
K/M@HADOOP.COM
admin/admin@HADOOP.COM
admin/master1.hadoop.com@HADOOP.COM
hdfs/master1.hadoop.com@HADOOP.COM
kadmin/admin@HADOOP.COM
kadmin/changepw@HADOOP.COM
krbtgt/HADOOP.COM@HADOOP.COM&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any suggestions for this issue?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 06 Jun 2024 00:39:08 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/KERBEROS-Failed-to-kinit-as-the-KDC-administrator-user-admin/m-p/388830#M246795</guid>
      <dc:creator>rizalt</dc:creator>
      <dc:date>2024-06-06T00:39:08Z</dc:date>
    </item>
    <item>
      <title>Re: [KERBEROS] Failed to kinit as the KDC administrator user, admin/admin@HADOOP.COM</title>
      <link>https://community.cloudera.com/t5/Support-Questions/KERBEROS-Failed-to-kinit-as-the-KDC-administrator-user-admin/m-p/388840#M246797</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/109307"&gt;@rizalt&lt;/a&gt; , I am not sure if you are hitting this known issue &lt;A href="https://docs.cloudera.com/runtime/7.1.2/release-notes/topics/rt-known-issues-ambari.html" target="_blank"&gt;https://docs.cloudera.com/runtime/7.1.2/release-notes/topics/rt-known-issues-ambari.html&lt;/A&gt; . You can try the workaround mentioned here for now.&lt;/P&gt;</description>
      <pubDate>Thu, 06 Jun 2024 07:20:30 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/KERBEROS-Failed-to-kinit-as-the-KDC-administrator-user-admin/m-p/388840#M246797</guid>
      <dc:creator>Majeti</dc:creator>
      <dc:date>2024-06-06T07:20:30Z</dc:date>
    </item>
    <item>
      <title>Re: [KERBEROS] Failed to kinit as the KDC administrator user, admin/admin@HADOOP.COM</title>
      <link>https://community.cloudera.com/t5/Support-Questions/KERBEROS-Failed-to-kinit-as-the-KDC-administrator-user-admin/m-p/388873#M246807</link>
      <description>&lt;P&gt;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/109307"&gt;@rizalt&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;Make a backup of your krb5.conf and modify it like below&lt;/P&gt;&lt;LI-SPOILER&gt;&lt;P&gt;# Configuration snippets may be placed in this directory as well&lt;BR /&gt;includedir /etc/krb5.conf.d/&lt;/P&gt;&lt;P&gt;[logging]&lt;BR /&gt;default = FILE:/var/log/krb5libs.log&lt;BR /&gt;kdc = FILE:/var/log/krb5kdc.log&lt;BR /&gt;admin_server = FILE:/var/log/kadmind.log&lt;/P&gt;&lt;P&gt;[libdefaults]&lt;BR /&gt;dns_lookup_realm = false&lt;BR /&gt;ticket_lifetime = 24h&lt;BR /&gt;renew_lifetime = 7d&lt;BR /&gt;forwardable = true&lt;BR /&gt;ticket_lifetime = 24h&lt;BR /&gt;dns_lookup_realm = false&lt;BR /&gt;dns_lookup_kdc = false&lt;BR /&gt;default_ccache_name = /tmp/krb5cc_%{uid}&lt;BR /&gt;#default_tgs_enctypes = aes des3-cbc-sha1 rc4 des-cbc-md5&lt;BR /&gt;#default_tkt_enctypes = aes des3-cbc-sha1 rc4 des-cbc-md5&lt;/P&gt;&lt;P&gt;[realms]&lt;BR /&gt;HADOOP.COM = {&lt;BR /&gt;admin_server = master1.hadoop.com&lt;BR /&gt;kdc = master1.hadoop.com&lt;BR /&gt;}&lt;/P&gt;&lt;P&gt;[domain_realm]&lt;BR /&gt;.master1.hadoop.com = HADOOP.COM&lt;BR /&gt;master1.hadoop.com = HADOOP.COM&lt;/P&gt;&lt;/LI-SPOILER&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Then restart the KDC and retry&amp;nbsp; &amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 06 Jun 2024 12:41:34 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/KERBEROS-Failed-to-kinit-as-the-KDC-administrator-user-admin/m-p/388873#M246807</guid>
      <dc:creator>Shelton</dc:creator>
      <dc:date>2024-06-06T12:41:34Z</dc:date>
    </item>
    <item>
      <title>Re: [KERBEROS] Failed to kinit as the KDC administrator user, admin/admin@HADOOP.COM</title>
      <link>https://community.cloudera.com/t5/Support-Questions/KERBEROS-Failed-to-kinit-as-the-KDC-administrator-user-admin/m-p/388888#M246812</link>
      <description>&lt;P&gt;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/109307"&gt;@rizalt&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;Did you see the same entry in the krb5.conf that I suggested you add?&lt;/P&gt;&lt;PRE&gt;&lt;EM&gt;[domain_realm]
&amp;nbsp; .hadoop.com = HADOOP.COM
&amp;nbsp; hadoop.com = HADOOP.COM&lt;/EM&gt;&lt;/PRE&gt;&lt;P&gt;In the Kerberos setup UI you should also include&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;HADOOP.COM , . HADOOP.COM&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;Check a solution I offered&lt;BR /&gt;&lt;A href="https://community.cloudera.com/t5/Support-Questions/Error-while-enabling-kerberos-on-ambari/m-p/240324" target="_self"&gt;&lt;SPAN&gt;Error while enabling Kerberos on ambari&lt;/SPAN&gt;&lt;/A&gt;&lt;BR /&gt;Hope that helps&lt;/P&gt;</description>
      <pubDate>Thu, 06 Jun 2024 19:12:23 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/KERBEROS-Failed-to-kinit-as-the-KDC-administrator-user-admin/m-p/388888#M246812</guid>
      <dc:creator>Shelton</dc:creator>
      <dc:date>2024-06-06T19:12:23Z</dc:date>
    </item>
    <item>
      <title>Re: [KERBEROS] Failed to kinit as the KDC administrator user, admin/admin@HADOOP.COM</title>
      <link>https://community.cloudera.com/t5/Support-Questions/KERBEROS-Failed-to-kinit-as-the-KDC-administrator-user-admin/m-p/388897#M246813</link>
      <description>&lt;P&gt;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/20288"&gt;@Shelton&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm following your step, but show an error like below&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;root@master1:~# sudo systemctl restart krb5-kdc
Job for krb5-kdc.service failed because the control process exited with error code.
See "systemctl status krb5-kdc.service" and "journalctl -xeu krb5-kdc.service" for details.
root@master1:~# systemctl status krb5-kdc.service
× krb5-kdc.service - Kerberos 5 Key Distribution Center
     Loaded: loaded (/lib/systemd/system/krb5-kdc.service; enabled; vendor preset: enabled)
     Active: failed (Result: exit-code) since Fri 2024-06-07 00:33:16 UTC; 5min ago
    Process: 13894 ExecStart=/usr/sbin/krb5kdc -P /var/run/krb5-kdc.pid $DAEMON_ARGS (code=exited, status=1/FAILURE)
        CPU: 92ms

Jun 07 00:33:16 master1.hadoop.com systemd[1]: Starting Kerberos 5 Key Distribution Center...
Jun 07 00:33:16 master1.hadoop.com krb5kdc[13894]: Couldn't open log file /var/log/krb5kdc.log: Read-only file system
Jun 07 00:33:16 master1.hadoop.com krb5kdc[13894]: krb5kdc: Configuration file does not specify default realm, attempt&amp;gt;
Jun 07 00:33:16 master1.hadoop.com krb5kdc[13894]: Configuration file does not specify default realm - while attemptin&amp;gt;
Jun 07 00:33:16 master1.hadoop.com systemd[1]: krb5-kdc.service: Control process exited, code=exited, status=1/FAILURE
Jun 07 00:33:16 master1.hadoop.com systemd[1]: krb5-kdc.service: Failed with result 'exit-code'.
Jun 07 00:33:16 master1.hadoop.com systemd[1]: Failed to start Kerberos 5 Key Distribution Center.&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 07 Jun 2024 00:39:05 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/KERBEROS-Failed-to-kinit-as-the-KDC-administrator-user-admin/m-p/388897#M246813</guid>
      <dc:creator>rizalt</dc:creator>
      <dc:date>2024-06-07T00:39:05Z</dc:date>
    </item>
    <item>
      <title>Re: [KERBEROS] Failed to kinit as the KDC administrator user, admin/admin@HADOOP.COM</title>
      <link>https://community.cloudera.com/t5/Support-Questions/KERBEROS-Failed-to-kinit-as-the-KDC-administrator-user-admin/m-p/388906#M246814</link>
      <description>&lt;P&gt;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/20288"&gt;@Shelton&lt;/a&gt;&amp;nbsp;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/32680"&gt;@Majeti&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I found in the kdf.conf for "admin_keytab" path /etc/krb5kdc/kadm5.keytab not found, where i can create kadm5.keyab? please see below&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="rizalt_0-1717731855188.png" style="width: 400px;"&gt;&lt;img src="https://community.cloudera.com/t5/image/serverpage/image-id/40910iD4F9A136F618B5D9/image-size/medium?v=v2&amp;amp;px=400" role="button" title="rizalt_0-1717731855188.png" alt="rizalt_0-1717731855188.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;any suggestions?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 07 Jun 2024 03:44:59 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/KERBEROS-Failed-to-kinit-as-the-KDC-administrator-user-admin/m-p/388906#M246814</guid>
      <dc:creator>rizalt</dc:creator>
      <dc:date>2024-06-07T03:44:59Z</dc:date>
    </item>
    <item>
      <title>Re: [KERBEROS] Failed to kinit as the KDC administrator user, admin/admin@HADOOP.COM</title>
      <link>https://community.cloudera.com/t5/Support-Questions/KERBEROS-Failed-to-kinit-as-the-KDC-administrator-user-admin/m-p/388926#M246822</link>
      <description>&lt;P&gt;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/109307"&gt;@rizalt&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;&lt;EM&gt;Can you share the OS ,OS version and HDP version you are trying to Kerberize? I don't have a dump of HDP binaries though. I would like to reproduce and share the steps.?&lt;BR /&gt;&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;I suggest starting afresh so delete/destroy the current KDC as the root user or sudo the following steps are specific to&amp;nbsp; ubuntu&amp;nbsp; re-adapt for appropriate OS&lt;/EM&gt;&lt;/P&gt;&lt;PRE&gt;&lt;EM&gt;# sudo &amp;nbsp;kdb5_util -r HADOOP.COM destroy&lt;/EM&gt;&lt;/PRE&gt;&lt;P&gt;&lt;EM&gt;Accept with a "Yes"&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Now create a new Kerberos database&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;Complete remove Kerberos&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;&lt;PRE&gt;&lt;EM&gt;$ sudo apt purge -y krb5-kdc krb5-admin-server krb5-config krb5-locales krb5-user krb5.conf&amp;nbsp;
$ sudo rm -rf /var/lib/krb5kdc&lt;/EM&gt;&lt;/PRE&gt;&lt;P&gt;&lt;EM&gt;Do a refresh installation&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;First, get the FQDN of your kdc server for this example&lt;/EM&gt;&lt;/P&gt;&lt;PRE&gt;&lt;EM&gt;# hostanme -f&amp;nbsp;
test.hadoop.com&lt;/EM&gt;&lt;/PRE&gt;&lt;P&gt;&lt;EM&gt;Use the above output for a later set up&lt;/EM&gt;&lt;/P&gt;&lt;PRE&gt;&lt;EM&gt;# apt install krb5-kdc krb5-admin-server krb5-config&lt;/EM&gt;&lt;/PRE&gt;&lt;P&gt;&lt;EM&gt;Proceed as follow&lt;/EM&gt;&lt;/P&gt;&lt;PRE&gt;&lt;EM&gt;At the prompt for the Kerberos Realm = HADOOP.COM
Kerberos server hostname = test.hadoop.com
Administrative server for Kerberos REALM = test.hadoop.com&lt;/EM&gt;&lt;/PRE&gt;&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;Configuring krb5 Admin Server&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;&lt;PRE&gt;&lt;EM&gt;# krb5_newrealm&lt;/EM&gt;&lt;/PRE&gt;&lt;P&gt;&lt;EM&gt;Open /etc/krb5kdc/kadm5.acl it should contain a line like this&lt;/EM&gt;&lt;/P&gt;&lt;PRE&gt;&lt;EM&gt;*/admin@HADOOP.COM *&lt;/EM&gt;&lt;/PRE&gt;&lt;P&gt;&lt;EM&gt;The kdc.conf should be adjusted to look like this&lt;/EM&gt;&lt;/P&gt;&lt;PRE&gt;&lt;EM&gt;[kdcdefaults]
&amp;nbsp;kdc_ports = 88
&amp;nbsp;kdc_tcp_ports = 88

[realms]
&amp;nbsp;HADOOP.COM = {
&amp;nbsp; #master_key_type = aes256-cts
&amp;nbsp; acl_file = /var/kerberos/krb5kdc/kadm5.acl
&amp;nbsp; dict_file = /usr/share/dict/words
&amp;nbsp; admin_keytab = /var/kerberos/krb5kdc/kadm5.keytab
&amp;nbsp; supported_enctypes = aes256-cts:normal aes128-cts:normal des3-hmac-sha1:normal arcfour-hmac:normal camellia256-cts:normal camellia128-cts:normal des-hmac-sha1:normal des-cbc-md5:normal des-cbc-crc:normal
}&lt;/EM&gt;&lt;/PRE&gt;&lt;P&gt;&lt;EM&gt;&amp;nbsp;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;The krb5.conf should look like this if you are on a multi-node cluster this is the fines you will copy to all other hosts, notice the entry under domain_realm?&lt;/EM&gt;&lt;/P&gt;&lt;PRE&gt;&lt;EM&gt;[libdefaults]
&amp;nbsp; renew_lifetime = 7d
&amp;nbsp; forwardable = true
&amp;nbsp; default_realm = HADOOP.COM
&amp;nbsp; ticket_lifetime = 24h
&amp;nbsp; dns_lookup_realm = false
&amp;nbsp; dns_lookup_kdc = false
&amp;nbsp; default_ccache_name = /tmp/krb5cc_%{uid}
&amp;nbsp; #default_tgs_enctypes = aes des3-cbc-sha1 rc4 des-cbc-md5
&amp;nbsp; #default_tkt_enctypes = aes des3-cbc-sha1 rc4 des-cbc-md5

[domain_realm]
&amp;nbsp; .hadoop.com = HADOOP.COM
&amp;nbsp; hadoop.com = HADOOP.COM

[logging]
&amp;nbsp; default = FILE:/var/log/krb5kdc.log
&amp;nbsp; admin_server = FILE:/var/log/kadmind.log
&amp;nbsp; kdc = FILE:/var/log/krb5kdc.log

[realms]
&amp;nbsp; HADOOP.COM = {
&amp;nbsp; &amp;nbsp; admin_server = test.hadoop.com
&amp;nbsp; &amp;nbsp; kdc = test.hadoop.com
&amp;nbsp; }&lt;/EM&gt;&lt;/PRE&gt;&lt;P&gt;&lt;EM&gt;&amp;nbsp;&lt;/EM&gt;&lt;EM&gt;Restart the Kerberos kdc daemons and kerberos admin servers:&lt;/EM&gt;&lt;/P&gt;&lt;PRE&gt;&lt;EM&gt;# for script in /etc/init.d/krb5*; do $script restart; done&lt;/EM&gt;&lt;/PRE&gt;&lt;P&gt;&lt;EM&gt;&amp;nbsp;&lt;/EM&gt;&lt;EM&gt;Don't manually create any principle like the "ambari_hdfs-050819@HADOOP.COM"&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Go to the ambari kerberos wizard for the domain notice the . (dot)&lt;/EM&gt;&lt;EM&gt;&amp;nbsp;&lt;/EM&gt;&lt;/P&gt;&lt;PRE&gt;&lt;EM&gt;kdc host = test.hadoop.com
Real Name = HADOOP.COM
Domains = .hadoop.com ,hadoop.com
-----
kadmin host = test.hadoop.com
Admin principal = admin/admin@HADOOP.COM
Admin &amp;nbsp;password = password set during the creation of kdc database&lt;/EM&gt;&lt;/PRE&gt;&lt;P&gt;&lt;EM&gt;Now from here just accept the default the keytabs should generate successfully.&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 07 Jun 2024 11:38:09 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/KERBEROS-Failed-to-kinit-as-the-KDC-administrator-user-admin/m-p/388926#M246822</guid>
      <dc:creator>Shelton</dc:creator>
      <dc:date>2024-06-07T11:38:09Z</dc:date>
    </item>
    <item>
      <title>Re: [KERBEROS] Failed to kinit as the KDC administrator user, admin/admin@HADOOP.COM</title>
      <link>https://community.cloudera.com/t5/Support-Questions/KERBEROS-Failed-to-kinit-as-the-KDC-administrator-user-admin/m-p/388937#M246829</link>
      <description>&lt;P&gt;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/20288"&gt;@Shelton&lt;/a&gt;&amp;nbsp; &amp;nbsp;I'm using Ubuntu 22.04 &amp;amp; using ODP (&lt;A href="https://clemlabs.s3.eu-west-3.amazonaws.com/ubuntu22/odp-release/1.2.2.0-46/ODP" target="_blank"&gt;https://clemlabs.s3.eu-west-3.amazonaws.com/ubuntu22/odp-release/1.2.2.0-46/ODP&lt;/A&gt;)&lt;/P&gt;</description>
      <pubDate>Fri, 07 Jun 2024 23:13:22 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/KERBEROS-Failed-to-kinit-as-the-KDC-administrator-user-admin/m-p/388937#M246829</guid>
      <dc:creator>rizalt</dc:creator>
      <dc:date>2024-06-07T23:13:22Z</dc:date>
    </item>
  </channel>
</rss>

