<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>question Re: Kafka console producer/consumer failing with AD users but works with local kafka realm. in Support Questions</title>
    <link>https://community.cloudera.com/t5/Support-Questions/Kafka-console-producer-consumer-failing-with-AD-users-but/m-p/92237#M45862</link>
    <description>&lt;P&gt;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/27216"&gt;@satz&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We were able to resolve this. We had the kerberos auth principles in default kafka group while all the broker were in a different config group. Adding the auth principles to the kafka config group has solved the issue.&lt;/P&gt;</description>
    <pubDate>Wed, 03 Jul 2019 15:34:50 GMT</pubDate>
    <dc:creator>RajeshBodolla</dc:creator>
    <dc:date>2019-07-03T15:34:50Z</dc:date>
    <item>
      <title>Kafka console producer/consumer failing with AD users but works with local kafka realm.</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Kafka-console-producer-consumer-failing-with-AD-users-but/m-p/91415#M45860</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have just built a new kafka cluster(&lt;SPAN&gt;3.1.0-1.3.1.0.p0.35&lt;/SPAN&gt;) and integrated it with kerberos. Kerberos is integrated with AD. We are able to produce and consume with kafka principle which is local but with AD users, it fails with below error on console.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;19/06/09 08:14:22 DEBUG authenticator.SaslClientAuthenticator: Set SASL client state to CLIENT_COMPLETE&lt;BR /&gt;19/06/09 08:14:22 DEBUG authenticator.SaslClientAuthenticator: Set SASL client state to COMPLETE&lt;BR /&gt;19/06/09 08:14:22 DEBUG clients.NetworkClient: [Producer clientId=console-producer] Initiating API versions fetch from node -1.&lt;BR /&gt;&lt;STRONG&gt;19/06/09 08:14:22 DEBUG network.Selector: [Producer clientId=console-producer] Connection with server2.kafka4.corp/180.20.92.23 disconnected&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;java.io.EOFException&lt;/STRONG&gt;&lt;BR /&gt;at org.apache.kafka.common.network.NetworkReceive.readFromReadableChannel(NetworkReceive.java:124)&lt;BR /&gt;at org.apache.kafka.common.network.NetworkReceive.readFrom(NetworkReceive.java:93)&lt;BR /&gt;at org.apache.kafka.common.network.KafkaChannel.receive(KafkaChannel.java:235)&lt;BR /&gt;at org.apache.kafka.common.network.KafkaChannel.read(KafkaChannel.java:196)&lt;BR /&gt;at org.apache.kafka.common.network.Selector.attemptRead(Selector.java:545)&lt;BR /&gt;at org.apache.kafka.common.network.Selector.pollSelectionKeys(Selector.java:483)&lt;BR /&gt;at org.apache.kafka.common.network.Selector.poll(Selector.java:412)&lt;BR /&gt;at org.apache.kafka.clients.NetworkClient.poll(NetworkClient.java:481)&lt;BR /&gt;at org.apache.kafka.clients.producer.internals.Sender.run(Sender.java:239)&lt;BR /&gt;at org.apache.kafka.clients.producer.internals.Sender.run(Sender.java:163)&lt;BR /&gt;at java.lang.Thread.run(Thread.java:748)&lt;BR /&gt;19/06/09 08:14:22 DEBUG clients.NetworkClient: [Producer clientId=console-producer] Node -1 disconnected.&lt;BR /&gt;19/06/09 08:14:22 INFO clients.NetworkClient: [Producer clientId=console-producer] API versions request failed via disconnect. Defaulting legacy API versions&lt;BR /&gt;19/06/09 08:14:22 DEBUG clients.NetworkClient: [Producer clientId=console-producer] Give up sending metadata request since no node is available&lt;BR /&gt;19/06/09 08:14:22 DEBUG clients.NetworkClient: [Producer clientId=console-producer] Give up sending metadata request since no node is available&lt;BR /&gt;^C19/06/09 08:14:22 INFO producer.KafkaProducer: [Producer clientId=console-producer] Closing the Kafka producer with timeoutMillis = 9223372036854775807 ms.&lt;BR /&gt;19/06/09 08:14:22 DEBUG internals.Sender: [Producer clientId=console-producer] Beginning shutdown of Kafka producer I/O thread, sending remaining records.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;==========================================&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The broker logs only have errors about the shortname for users.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Caused by: org.apache.kafka.common.security.kerberos.NoMatchingRule: No rules apply to RAJESH@KAFKA4.CORP, rules [DEFAULT]&lt;/P&gt;</description>
      <pubDate>Fri, 16 Sep 2022 14:26:19 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Kafka-console-producer-consumer-failing-with-AD-users-but/m-p/91415#M45860</guid>
      <dc:creator>RajeshBodolla</dc:creator>
      <dc:date>2022-09-16T14:26:19Z</dc:date>
    </item>
    <item>
      <title>Re: Kafka console producer/consumer failing with AD users but works with local kafka realm.</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Kafka-console-producer-consumer-failing-with-AD-users-but/m-p/92234#M45861</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/24123"&gt;@RajeshBodolla&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It seems like the actual exception is as below&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Caused by: org.apache.kafka.common.security.kerberos.NoMatchingRule: No rules apply to RAJESH@KAFKA4.CORP, rules [DEFAULT]&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Could you please share the complete stack? it seems it is somewhere not able to resolve the principal&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 03 Jul 2019 15:27:42 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Kafka-console-producer-consumer-failing-with-AD-users-but/m-p/92234#M45861</guid>
      <dc:creator>satz</dc:creator>
      <dc:date>2019-07-03T15:27:42Z</dc:date>
    </item>
    <item>
      <title>Re: Kafka console producer/consumer failing with AD users but works with local kafka realm.</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Kafka-console-producer-consumer-failing-with-AD-users-but/m-p/92237#M45862</link>
      <description>&lt;P&gt;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/27216"&gt;@satz&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We were able to resolve this. We had the kerberos auth principles in default kafka group while all the broker were in a different config group. Adding the auth principles to the kafka config group has solved the issue.&lt;/P&gt;</description>
      <pubDate>Wed, 03 Jul 2019 15:34:50 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Kafka-console-producer-consumer-failing-with-AD-users-but/m-p/92237#M45862</guid>
      <dc:creator>RajeshBodolla</dc:creator>
      <dc:date>2019-07-03T15:34:50Z</dc:date>
    </item>
  </channel>
</rss>

