<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>question Re: Disabling Kerberos in Support Questions</title>
    <link>https://community.cloudera.com/t5/Support-Questions/Disabling-Kerberos/m-p/31911#M38084</link>
    <description>&lt;P&gt;Have the same problem, but after clean and reinstall cluster (using parcels). Error appears when oozie java action wrties to HDFS (runs from HUE). Earlier on this cluster was Kerberos, and I cleand all (I hope) directories from previous installation.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here is a detailed message:&lt;/P&gt;&lt;PRE&gt;Failing Oozie Launcher, Main class [org.apache.oozie.action.hadoop.JavaMain], main() threw exception, java.io.IOException:
Failed on local exception: java.io.IOException: Server asks us to fall back to SIMPLE auth, but this client is configured to only allow secure connections.; 
Host Details : local host is: "hadoop-05.xxx.xx/172.19.x.xxx"; destination host is: "hadoop-02.xxx.xx":8020; 
org.apache.oozie.action.hadoop.JavaMainException: java.io.IOException: Failed on local exception: java.io.IOException:
Server asks us to fall back to SIMPLE auth, but this client is configured to only allow secure connections.;
Host Details : local host is: "hadoop-05.xxx.xx/172.19.x.xxx"; destination host is: "hadoop-02.xxx.xx":8020;&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 16 Sep 2015 16:12:34 GMT</pubDate>
    <dc:creator>dna_29a</dc:creator>
    <dc:date>2015-09-16T16:12:34Z</dc:date>
    <item>
      <title>Disabling Kerberos</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Disabling-Kerberos/m-p/19654#M38073</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Hi all,&lt;/SPAN&gt;&lt;/P&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;We have a Kerberized cluster,but at the moment we would disable it.&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;How is it possible ?&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;I performed the following steps:&lt;/DIV&gt;&lt;DIV&gt;&lt;UL&gt;&lt;LI&gt;Zookeeper -&amp;gt; enableSecurity (Enable Kerberos Authentication)-&amp;gt; false&lt;/LI&gt;&lt;/UL&gt;&lt;UL&gt;&lt;LI&gt;HDFS -&amp;gt; hadoop.security.authentication -&amp;gt; Simple&lt;/LI&gt;&lt;LI&gt;HDFS -&amp;gt; hadoop.security.authorization -&amp;gt; false&lt;/LI&gt;&lt;LI&gt;HDFS -&amp;gt; dfs.datanode.address -&amp;gt; from 1004 (for Kerberos) to 50010 (default)&lt;/LI&gt;&lt;LI&gt;HDFS -&amp;gt; dfs.datanode.http.address &amp;nbsp;-&amp;gt; from 1006 (for Kerberos) to 50075 (default)&lt;/LI&gt;&lt;LI&gt;HDFS -&amp;gt; Data Directory Permissions -&amp;gt; from 700 to 755&lt;/LI&gt;&lt;/UL&gt;&lt;UL&gt;&lt;LI&gt;HBASE -&amp;gt; hbase.security.authentication -&amp;gt; Simple&lt;/LI&gt;&lt;LI&gt;HBASE -&amp;gt; hbase.security.authorization -&amp;gt; false&lt;/LI&gt;&lt;/UL&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;But when I start the cluster I have problems on Hue and Solr&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;Hue:&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;It seems that Kerberos is still configured for Hue&amp;nbsp;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; -&amp;gt;&amp;nbsp;The Kerberos Ticket Renewer is not running. How can i disable it?&amp;nbsp;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; -&amp;gt; &amp;nbsp;Impala e Oozie don't run from Hue&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;Solr: &amp;nbsp;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;Caused by: java.io.IOException: Failed on local exception: java.io.IOException: Server asks us to fall back to SIMPLE auth, but this client is configured to only allow secure connections.;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;I noticed that Hue and Solr run in secure mode. How can I disable them ?&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;Thanks&lt;/DIV&gt;&lt;DIV&gt;Alessio&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 16 Sep 2022 09:09:03 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Disabling-Kerberos/m-p/19654#M38073</guid>
      <dc:creator>Alessio</dc:creator>
      <dc:date>2022-09-16T09:09:03Z</dc:date>
    </item>
    <item>
      <title>Re: Disabling Kerberos</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Disabling-Kerberos/m-p/19712#M38074</link>
      <description>Just like other services. Pls look carefully ,you will find the botton. I have done this many times.</description>
      <pubDate>Fri, 03 Oct 2014 20:32:42 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Disabling-Kerberos/m-p/19712#M38074</guid>
      <dc:creator>iamfromsky</dc:creator>
      <dc:date>2014-10-03T20:32:42Z</dc:date>
    </item>
    <item>
      <title>Re: Disabling Kerberos</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Disabling-Kerberos/m-p/19714#M38075</link>
      <description>Don't forget redeploy client. It's important</description>
      <pubDate>Fri, 03 Oct 2014 20:33:36 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Disabling-Kerberos/m-p/19714#M38075</guid>
      <dc:creator>iamfromsky</dc:creator>
      <dc:date>2014-10-03T20:33:36Z</dc:date>
    </item>
    <item>
      <title>Re: Disabling Kerberos</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Disabling-Kerberos/m-p/19898#M38076</link>
      <description>&lt;P&gt;Hi,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I didn't find the button on CDH 5.1.2 but i removed the &lt;SPAN&gt;Kerberos Ticket Renewer and redeployed client.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I missed this for Solr&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;SOLR -&amp;gt; Solr Secure Authentication -&amp;gt; Simple&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 09 Oct 2014 08:46:16 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Disabling-Kerberos/m-p/19898#M38076</guid>
      <dc:creator>Alessio</dc:creator>
      <dc:date>2014-10-09T08:46:16Z</dc:date>
    </item>
    <item>
      <title>Re: Disabling Kerberos</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Disabling-Kerberos/m-p/19934#M38077</link>
      <description>&lt;P&gt;You would work your way back through the security guide discussion on enabling kerberos:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A target="_blank" href="http://www.cloudera.com/content/cloudera/en/documentation/cloudera-manager/v5-latest/Configuring-Hadoop-Security-with-Cloudera-Manager/cm5chs_enable_security_s8.html"&gt;http://www.cloudera.com/content/cloudera/en/documentation/cloudera-manager/v5-latest/Configuring-Hadoop-Security-with-Cloudera-Manager/cm5chs_enable_security_s8.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Note that if HBASE, or NN HA or JT HA was configured after enabling security, the cleanup can be difficult, the Znode paths within zookeeper might require manual removal of the ACL statements.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Todd&lt;/P&gt;</description>
      <pubDate>Thu, 09 Oct 2014 17:54:06 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Disabling-Kerberos/m-p/19934#M38077</guid>
      <dc:creator>Grizzly</dc:creator>
      <dc:date>2014-10-09T17:54:06Z</dc:date>
    </item>
    <item>
      <title>Re: Disabling Kerberos</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Disabling-Kerberos/m-p/20004#M38078</link>
      <description>&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I followed the instructions&amp;nbsp;in reverse order, present on the link.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When I disabled Kerberos, I had the two Namenodes (HA) both in stand-by state and I removed manually&amp;nbsp;&lt;SPAN&gt;entries in Zookeeper.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Now it works!!!&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thanks&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Alessio&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 10 Oct 2014 08:58:14 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Disabling-Kerberos/m-p/20004#M38078</guid>
      <dc:creator>Alessio</dc:creator>
      <dc:date>2014-10-10T08:58:14Z</dc:date>
    </item>
    <item>
      <title>Re: Disabling Kerberos</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Disabling-Kerberos/m-p/20488#M38079</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have another question about this.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;when you said :&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Note that if HBASE, or NN HA or JT HA was configured after enabling security, the cleanup can be difficult, the Znode paths within zookeeper might require manual removal of the ACL statements.&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;The same problem can be present for Yarn (HA).&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I tried to find the '&lt;/SPAN&gt;yarn.resourcemanager.zk-auth' in the yarn-site.xml (&lt;SPAN&gt;/var/run/cloudera-scm-agent/process&lt;/SPAN&gt;) in order to&amp;nbsp;auth with Zookeper and remove the ACL statement but is not present this parameter.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I searched it into all folders XXX-yarn-RESOURCEMANAGER (also in the most recent) but I cannot find it&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How can i solve this?&amp;nbsp;At the moment I have Yarn not in HA and when I try to enable the HA, both ResourceManagers stay in Stand-by&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Alessio&lt;/P&gt;</description>
      <pubDate>Mon, 20 Oct 2014 09:23:47 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Disabling-Kerberos/m-p/20488#M38079</guid>
      <dc:creator>Alessio</dc:creator>
      <dc:date>2014-10-20T09:23:47Z</dc:date>
    </item>
    <item>
      <title>Re: Disabling Kerberos</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Disabling-Kerberos/m-p/24950#M38080</link>
      <description>&lt;P&gt;Solved !!!&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Alessio&lt;/P&gt;</description>
      <pubDate>Mon, 23 Feb 2015 16:04:16 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Disabling-Kerberos/m-p/24950#M38080</guid>
      <dc:creator>Alessio</dc:creator>
      <dc:date>2015-02-23T16:04:16Z</dc:date>
    </item>
    <item>
      <title>Re: Disabling Kerberos</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Disabling-Kerberos/m-p/25684#M38081</link>
      <description>&lt;P&gt;How so? i have the same problem!&amp;nbsp;&amp;nbsp; Both my Yarn HA services went into standby.&lt;/P&gt;</description>
      <pubDate>Wed, 18 Mar 2015 14:47:48 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Disabling-Kerberos/m-p/25684#M38081</guid>
      <dc:creator>Bobby Perry</dc:creator>
      <dc:date>2015-03-18T14:47:48Z</dc:date>
    </item>
    <item>
      <title>Re: Disabling Kerberos</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Disabling-Kerberos/m-p/25686#M38082</link>
      <description>Looking for how you removed it from zk..</description>
      <pubDate>Wed, 18 Mar 2015 15:48:32 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Disabling-Kerberos/m-p/25686#M38082</guid>
      <dc:creator>Bobby Perry</dc:creator>
      <dc:date>2015-03-18T15:48:32Z</dc:date>
    </item>
    <item>
      <title>Re: Disabling Kerberos</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Disabling-Kerberos/m-p/26542#M38083</link>
      <description>&lt;P&gt;Hello Alessio,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am facing the same problem could you please outline the steps you did for Yarn and Zookeeper.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Deepak&lt;/P&gt;</description>
      <pubDate>Wed, 15 Apr 2015 21:46:25 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Disabling-Kerberos/m-p/26542#M38083</guid>
      <dc:creator>dmurthy</dc:creator>
      <dc:date>2015-04-15T21:46:25Z</dc:date>
    </item>
    <item>
      <title>Re: Disabling Kerberos</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Disabling-Kerberos/m-p/31911#M38084</link>
      <description>&lt;P&gt;Have the same problem, but after clean and reinstall cluster (using parcels). Error appears when oozie java action wrties to HDFS (runs from HUE). Earlier on this cluster was Kerberos, and I cleand all (I hope) directories from previous installation.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here is a detailed message:&lt;/P&gt;&lt;PRE&gt;Failing Oozie Launcher, Main class [org.apache.oozie.action.hadoop.JavaMain], main() threw exception, java.io.IOException:
Failed on local exception: java.io.IOException: Server asks us to fall back to SIMPLE auth, but this client is configured to only allow secure connections.; 
Host Details : local host is: "hadoop-05.xxx.xx/172.19.x.xxx"; destination host is: "hadoop-02.xxx.xx":8020; 
org.apache.oozie.action.hadoop.JavaMainException: java.io.IOException: Failed on local exception: java.io.IOException:
Server asks us to fall back to SIMPLE auth, but this client is configured to only allow secure connections.;
Host Details : local host is: "hadoop-05.xxx.xx/172.19.x.xxx"; destination host is: "hadoop-02.xxx.xx":8020;&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 16 Sep 2015 16:12:34 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Disabling-Kerberos/m-p/31911#M38084</guid>
      <dc:creator>dna_29a</dc:creator>
      <dc:date>2015-09-16T16:12:34Z</dc:date>
    </item>
    <item>
      <title>Re: Disabling Kerberos</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Disabling-Kerberos/m-p/37345#M38085</link>
      <description>I have a similar problem wanted to turn off Kerberos, so did everythin (turn auth to simple, data node ports etc etc).&lt;BR /&gt;Now the cluster does not use Kerberos, HDFS and Hive and Impala works fine, BUT THE OPTION FOR ENABLE KERBEROS IS STILL GREYED&lt;BR /&gt;Any thoughts?&lt;BR /&gt;T</description>
      <pubDate>Thu, 11 Feb 2016 21:55:01 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Disabling-Kerberos/m-p/37345#M38085</guid>
      <dc:creator>Tomas79</dc:creator>
      <dc:date>2016-02-11T21:55:01Z</dc:date>
    </item>
    <item>
      <title>Re: Disabling Kerberos</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Disabling-Kerberos/m-p/37540#M38086</link>
      <description>&lt;P&gt;The link provided is now broken. Is there an update to it?&lt;/P&gt;</description>
      <pubDate>Tue, 16 Feb 2016 22:41:52 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Disabling-Kerberos/m-p/37540#M38086</guid>
      <dc:creator>slmingol</dc:creator>
      <dc:date>2016-02-16T22:41:52Z</dc:date>
    </item>
    <item>
      <title>Re: Disabling Kerberos</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Disabling-Kerberos/m-p/37541#M38087</link>
      <description />
      <pubDate>Tue, 16 Feb 2016 22:45:05 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Disabling-Kerberos/m-p/37541#M38087</guid>
      <dc:creator>slmingol</dc:creator>
      <dc:date>2016-02-16T22:45:05Z</dc:date>
    </item>
    <item>
      <title>Re: Disabling Kerberos</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Disabling-Kerberos/m-p/37561#M38088</link>
      <description>&lt;P&gt;Try this one:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="http://www.cloudera.com/documentation/manager/5-1-x/Configuring-Hadoop-Security-with-Cloudera-Manager/cm5chs_enable_security_s8.html" target="_blank"&gt;http://www.cloudera.com/documentation/manager/5-1-x/Configuring-Hadoop-Security-with-Cloudera-Manager/cm5chs_enable_security_s8.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 17 Feb 2016 12:18:44 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Disabling-Kerberos/m-p/37561#M38088</guid>
      <dc:creator>cjervis</dc:creator>
      <dc:date>2016-02-17T12:18:44Z</dc:date>
    </item>
  </channel>
</rss>

