<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>question Problems with Enable Kerberos using the wizard in Support Questions</title>
    <link>https://community.cloudera.com/t5/Support-Questions/Problems-with-Enable-Kerberos-using-the-wizard/m-p/389451#M246987</link>
    <description>&lt;P&gt;When the wizard generates credentials, it reports Insufficient access (50) ldap error, like this:&lt;/P&gt;&lt;P&gt;/opt/cloudera/cm/bin/gen_credentials_ad.sh failed with exit code 50 and output of &amp;lt;&amp;lt;&lt;BR /&gt;+ export PATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/usr/kerberos/bin:/usr/kerberos/sbin:/usr/lib/mit/sbin:/usr/sbin:/usr/lib/mit/bin:/usr/bin&lt;BR /&gt;+ PATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/usr/kerberos/bin:/usr/kerberos/sbin:/usr/lib/mit/sbin:/usr/sbin:/usr/lib/mit/bin:/usr/bin&lt;BR /&gt;+ KEYTAB_OUT=/var/run/cloudera-scm-server/cmf3782202571582054951.keytab&lt;BR /&gt;+ PRINC=HTTP/cradle3302t.priv.cwru.edu@ADS.CASE.EDU&lt;BR /&gt;+ USER=PruWGPfsVZ&lt;BR /&gt;+ PASSWD=REDACTED&lt;BR /&gt;+ DELETE_ON_REGENERATE=true&lt;BR /&gt;+ SET_ENCRYPTION_TYPES=false&lt;BR /&gt;+ ENC_TYPES_MASK=4&lt;BR /&gt;+ USERACCOUNTCONTROL=66048&lt;BR /&gt;+ ACCOUNTEXPIRES=0&lt;BR /&gt;+ OBJECTCLASSES='objectClass: top&lt;BR /&gt;objectClass: person&lt;BR /&gt;objectClass: organizationalPerson&lt;BR /&gt;objectClass: user&lt;BR /&gt;'&lt;BR /&gt;+ EXTRA_ATTRIBUTES=&lt;BR /&gt;+ DIST_NAME='CN=PruWGPfsVZ,OU=cradle33,OU=Hadoop,OU=Research Computing,OU=Information Technology Services,OU=Delegated Departments,DC=ads,DC=case,DC=edu'&lt;BR /&gt;+ [[ -z ADS.CASE.EDU ]]&lt;BR /&gt;+ echo 'CMF_REALM is: ADS.CASE.EDU'&lt;BR /&gt;+ '[' -z /var/run/cloudera-scm-server/krb5125639301910663789.conf ']'&lt;BR /&gt;+ echo 'Using custom config path '\''/var/run/cloudera-scm-server/krb5125639301910663789.conf'\'', contents below:'&lt;BR /&gt;+ cat /var/run/cloudera-scm-server/krb5125639301910663789.conf&lt;BR /&gt;++ mktemp /tmp/cm_ldap.XXXXXXXX&lt;BR /&gt;+ LDAP_CONF=/tmp/cm_ldap.jOaAAbDw&lt;BR /&gt;+ echo 'TLS_REQCERT never'&lt;BR /&gt;+ echo 'sasl_secprops minssf=0,maxssf=0'&lt;BR /&gt;+ SIMPLE_PWD_STR=&lt;BR /&gt;+ LDAP_URL=&lt;BR /&gt;+ '[' REDACTED = '' ']'&lt;BR /&gt;+ SIMPLE_PWD_STR='-x -D rcci-hadoop-sa@ADS.CASE.EDU -w REDACTED'&lt;BR /&gt;+ LDAP_URL=ldaps://ads.case.edu:636&lt;BR /&gt;+ export LDAPCONF=/tmp/cm_ldap.jOaAAbDw&lt;BR /&gt;+ LDAPCONF=/tmp/cm_ldap.jOaAAbDw&lt;BR /&gt;++ ldapsearch -LLL -H ldaps://ads.case.edu:636 -b 'OU=cradle33,OU=Hadoop,OU=Research Computing,OU=Information Technology Services,OU=Delegated Departments,DC=ads,DC=case,DC=edu' -x -D rcci-hadoop-sa@ADS.CASE.EDU -w REDACTED userPrincipalName=HTTP/cradle3302t.priv.cwru.edu@ADS.CASE.EDU&lt;BR /&gt;+ PRINC_SEARCH=&lt;BR /&gt;++ echo ''&lt;BR /&gt;++ sed -n '1 {h; $ !d}; $ {x; s/\n //g; p}; /^ / {H; d}; /^ /! {x; s/\n //g; p}'&lt;BR /&gt;+ RESULTS_UNWRAPPED=&lt;BR /&gt;+ echo “”&lt;BR /&gt;+ set +e&lt;BR /&gt;+ echo&lt;BR /&gt;+ grep -q userPrincipalName&lt;BR /&gt;+ '[' 1 -eq 0 ']'&lt;BR /&gt;+ set -e&lt;BR /&gt;+ '[' false = true ']'&lt;BR /&gt;+ ldapmodify -H ldaps://ads.case.edu:636 -x -D rcci-hadoop-sa@ADS.CASE.EDU -w REDACTED&lt;BR /&gt;++ echo 'objectClass: top&lt;BR /&gt;objectClass: person&lt;BR /&gt;objectClass: organizationalPerson&lt;BR /&gt;objectClass: user&lt;BR /&gt;'&lt;BR /&gt;++ sed /str/d&lt;BR /&gt;++ echo HTTP/cradle3302t.priv.cwru.edu@ADS.CASE.EDU&lt;BR /&gt;++ sed -e 's/\@ADS.CASE.EDU//g'&lt;BR /&gt;++ echo -n '"REDACTED"'&lt;BR /&gt;++ iconv -f UTF8 -t UTF16LE&lt;BR /&gt;++ base64 -w 0&lt;BR /&gt;++ echo ''&lt;BR /&gt;ldap_add: Insufficient access (50)&lt;BR /&gt;additional info: 00000005: SecErr: DSID-03152E13, problem 4003 (INSUFF_ACCESS_RIGHTS), data 0&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&amp;gt;&amp;gt;&lt;/P&gt;&lt;P&gt;I know the service account has full access for sure.&lt;/P&gt;&lt;P&gt;Is anyone know the reason why it is failed in this way?&lt;/P&gt;</description>
    <pubDate>Thu, 20 Jun 2024 20:49:30 GMT</pubDate>
    <dc:creator>MaraWang</dc:creator>
    <dc:date>2024-06-20T20:49:30Z</dc:date>
    <item>
      <title>Problems with Enable Kerberos using the wizard</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Problems-with-Enable-Kerberos-using-the-wizard/m-p/389451#M246987</link>
      <description>&lt;P&gt;When the wizard generates credentials, it reports Insufficient access (50) ldap error, like this:&lt;/P&gt;&lt;P&gt;/opt/cloudera/cm/bin/gen_credentials_ad.sh failed with exit code 50 and output of &amp;lt;&amp;lt;&lt;BR /&gt;+ export PATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/usr/kerberos/bin:/usr/kerberos/sbin:/usr/lib/mit/sbin:/usr/sbin:/usr/lib/mit/bin:/usr/bin&lt;BR /&gt;+ PATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/usr/kerberos/bin:/usr/kerberos/sbin:/usr/lib/mit/sbin:/usr/sbin:/usr/lib/mit/bin:/usr/bin&lt;BR /&gt;+ KEYTAB_OUT=/var/run/cloudera-scm-server/cmf3782202571582054951.keytab&lt;BR /&gt;+ PRINC=HTTP/cradle3302t.priv.cwru.edu@ADS.CASE.EDU&lt;BR /&gt;+ USER=PruWGPfsVZ&lt;BR /&gt;+ PASSWD=REDACTED&lt;BR /&gt;+ DELETE_ON_REGENERATE=true&lt;BR /&gt;+ SET_ENCRYPTION_TYPES=false&lt;BR /&gt;+ ENC_TYPES_MASK=4&lt;BR /&gt;+ USERACCOUNTCONTROL=66048&lt;BR /&gt;+ ACCOUNTEXPIRES=0&lt;BR /&gt;+ OBJECTCLASSES='objectClass: top&lt;BR /&gt;objectClass: person&lt;BR /&gt;objectClass: organizationalPerson&lt;BR /&gt;objectClass: user&lt;BR /&gt;'&lt;BR /&gt;+ EXTRA_ATTRIBUTES=&lt;BR /&gt;+ DIST_NAME='CN=PruWGPfsVZ,OU=cradle33,OU=Hadoop,OU=Research Computing,OU=Information Technology Services,OU=Delegated Departments,DC=ads,DC=case,DC=edu'&lt;BR /&gt;+ [[ -z ADS.CASE.EDU ]]&lt;BR /&gt;+ echo 'CMF_REALM is: ADS.CASE.EDU'&lt;BR /&gt;+ '[' -z /var/run/cloudera-scm-server/krb5125639301910663789.conf ']'&lt;BR /&gt;+ echo 'Using custom config path '\''/var/run/cloudera-scm-server/krb5125639301910663789.conf'\'', contents below:'&lt;BR /&gt;+ cat /var/run/cloudera-scm-server/krb5125639301910663789.conf&lt;BR /&gt;++ mktemp /tmp/cm_ldap.XXXXXXXX&lt;BR /&gt;+ LDAP_CONF=/tmp/cm_ldap.jOaAAbDw&lt;BR /&gt;+ echo 'TLS_REQCERT never'&lt;BR /&gt;+ echo 'sasl_secprops minssf=0,maxssf=0'&lt;BR /&gt;+ SIMPLE_PWD_STR=&lt;BR /&gt;+ LDAP_URL=&lt;BR /&gt;+ '[' REDACTED = '' ']'&lt;BR /&gt;+ SIMPLE_PWD_STR='-x -D rcci-hadoop-sa@ADS.CASE.EDU -w REDACTED'&lt;BR /&gt;+ LDAP_URL=ldaps://ads.case.edu:636&lt;BR /&gt;+ export LDAPCONF=/tmp/cm_ldap.jOaAAbDw&lt;BR /&gt;+ LDAPCONF=/tmp/cm_ldap.jOaAAbDw&lt;BR /&gt;++ ldapsearch -LLL -H ldaps://ads.case.edu:636 -b 'OU=cradle33,OU=Hadoop,OU=Research Computing,OU=Information Technology Services,OU=Delegated Departments,DC=ads,DC=case,DC=edu' -x -D rcci-hadoop-sa@ADS.CASE.EDU -w REDACTED userPrincipalName=HTTP/cradle3302t.priv.cwru.edu@ADS.CASE.EDU&lt;BR /&gt;+ PRINC_SEARCH=&lt;BR /&gt;++ echo ''&lt;BR /&gt;++ sed -n '1 {h; $ !d}; $ {x; s/\n //g; p}; /^ / {H; d}; /^ /! {x; s/\n //g; p}'&lt;BR /&gt;+ RESULTS_UNWRAPPED=&lt;BR /&gt;+ echo “”&lt;BR /&gt;+ set +e&lt;BR /&gt;+ echo&lt;BR /&gt;+ grep -q userPrincipalName&lt;BR /&gt;+ '[' 1 -eq 0 ']'&lt;BR /&gt;+ set -e&lt;BR /&gt;+ '[' false = true ']'&lt;BR /&gt;+ ldapmodify -H ldaps://ads.case.edu:636 -x -D rcci-hadoop-sa@ADS.CASE.EDU -w REDACTED&lt;BR /&gt;++ echo 'objectClass: top&lt;BR /&gt;objectClass: person&lt;BR /&gt;objectClass: organizationalPerson&lt;BR /&gt;objectClass: user&lt;BR /&gt;'&lt;BR /&gt;++ sed /str/d&lt;BR /&gt;++ echo HTTP/cradle3302t.priv.cwru.edu@ADS.CASE.EDU&lt;BR /&gt;++ sed -e 's/\@ADS.CASE.EDU//g'&lt;BR /&gt;++ echo -n '"REDACTED"'&lt;BR /&gt;++ iconv -f UTF8 -t UTF16LE&lt;BR /&gt;++ base64 -w 0&lt;BR /&gt;++ echo ''&lt;BR /&gt;ldap_add: Insufficient access (50)&lt;BR /&gt;additional info: 00000005: SecErr: DSID-03152E13, problem 4003 (INSUFF_ACCESS_RIGHTS), data 0&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&amp;gt;&amp;gt;&lt;/P&gt;&lt;P&gt;I know the service account has full access for sure.&lt;/P&gt;&lt;P&gt;Is anyone know the reason why it is failed in this way?&lt;/P&gt;</description>
      <pubDate>Thu, 20 Jun 2024 20:49:30 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Problems-with-Enable-Kerberos-using-the-wizard/m-p/389451#M246987</guid>
      <dc:creator>MaraWang</dc:creator>
      <dc:date>2024-06-20T20:49:30Z</dc:date>
    </item>
    <item>
      <title>Re: Problems with Enable Kerberos using the wizard</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Problems-with-Enable-Kerberos-using-the-wizard/m-p/389456#M246990</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/110761"&gt;@MaraWang&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;please work with AD team to enusre the bind user have required rights (add, delete and modify) in order to do required actions in AD using the user. And you can refer the KB article below to have additional permission for all machine accounts ("objectclass=computer") associated with the cluster hosts. KB article : &lt;A href="https://my.cloudera.com/knowledge/Cloudera-Customer-Advisory-590-Microsoft-AD-November-2021?id=350255" target="_blank"&gt;https://my.cloudera.com/knowledge/Cloudera-Customer-Advisory-590-Microsoft-AD-November-2021?id=350255&lt;/A&gt; &lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Jun 2024 05:47:36 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Problems-with-Enable-Kerberos-using-the-wizard/m-p/389456#M246990</guid>
      <dc:creator>vamsi_redd</dc:creator>
      <dc:date>2024-06-21T05:47:36Z</dc:date>
    </item>
    <item>
      <title>Re: Problems with Enable Kerberos using the wizard</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Problems-with-Enable-Kerberos-using-the-wizard/m-p/389599#M247019</link>
      <description>&lt;P&gt;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/110761"&gt;@MaraWang&lt;/a&gt;,&amp;nbsp;Did the response assist in resolving your query? If it did, kindly mark the relevant reply as the solution, as it will aid others in locating the answer more easily in the future.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 26 Jun 2024 05:35:07 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Problems-with-Enable-Kerberos-using-the-wizard/m-p/389599#M247019</guid>
      <dc:creator>VidyaSargur</dc:creator>
      <dc:date>2024-06-26T05:35:07Z</dc:date>
    </item>
  </channel>
</rss>

