<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>question Re: Zookeeper kerberos issue or quorum issue? in Archives of Support Questions (Read Only)</title>
    <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Zookeeper-kerberos-issue-or-quorum-issue/m-p/34703#M10944</link>
    <description>&lt;P&gt;Thanks Harsh,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So, to generalize, the mechanism level subcodes can always be taken as some failure in communicating with KDC, right?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I also see that despite this error, ZK does continue to function ... so is this error to be really treated seriously?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks again.&lt;/P&gt;</description>
    <pubDate>Thu, 03 Dec 2015 03:45:02 GMT</pubDate>
    <dc:creator>sumit.nigam</dc:creator>
    <dc:date>2015-12-03T03:45:02Z</dc:date>
    <item>
      <title>Zookeeper kerberos issue or quorum issue?</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Zookeeper-kerberos-issue-or-quorum-issue/m-p/34323#M10942</link>
      <description>&lt;P&gt;I use a kerberized cluster and once in a while I notice following error in my zookeeper client logs:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;15/11/15 15:46:53 ERROR client.ZooKeeperSaslClient: An error: (java.security.PrivilegedActionException: javax.security.sasl.SaslException: GSS initiate failed &lt;/SPAN&gt;&lt;SPAN class="error"&gt;[Caused by GSSException: No valid credentials provided (&lt;STRONG&gt;Mechanism level: Connection reset&lt;/STRONG&gt;)]&lt;/SPAN&gt;&lt;SPAN&gt;) occurred when evaluating Zookeeper Quorum Member's received SASL token. &lt;STRONG&gt;Zookeeper Client will go to AUTH_FAILED state&lt;/STRONG&gt;.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;SPAN&gt;15/11/15 15:46:53 ERROR zookeeper.&lt;STRONG&gt;ClientCnxn&lt;/STRONG&gt;: &lt;STRONG&gt;SASL authentication with Zookeeper Quorum member failed&lt;/STRONG&gt;: javax.security.sasl.SaslException: An error: (java.security.PrivilegedActionException: javax.security.sasl.SaslException: GSS initiate failed &lt;/SPAN&gt;&lt;SPAN class="error"&gt;[Caused by GSSException: No valid credentials provided (Mechanism level: Connection reset)]&lt;/SPAN&gt;&lt;SPAN&gt;) occurred when evaluating Zookeeper Quorum Member's received SASL token. Zookeeper Client will go to AUTH_FAILED state.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;So, I had following doubt with this:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;It is showing actual error to be connection reset. I am not sure&amp;nbsp;connection RST to what? Is it to Kerberos KDC? But the log further seems to indicate that connection&amp;nbsp;issue happened when connecting to ZK quorum member. So, in that case the RST flag is recd from ZK quorum member?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thanks,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Sumit&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 16 Sep 2022 09:50:00 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Zookeeper-kerberos-issue-or-quorum-issue/m-p/34323#M10942</guid>
      <dc:creator>sumit.nigam</dc:creator>
      <dc:date>2022-09-16T09:50:00Z</dc:date>
    </item>
    <item>
      <title>Re: Zookeeper kerberos issue or quorum issue?</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Zookeeper-kerberos-issue-or-quorum-issue/m-p/34684#M10943</link>
      <description>Yes, the Mechanism level: sub-codes usually pertain to operations within the context of a KDC or local Kerberos work. The connection reset being a network error is therefore alluding to the Client-&amp;gt;KDC connection being reset.&lt;BR /&gt;&lt;BR /&gt;The ZKs would auth to each other in secure mode, but the specific failure here is within just the auth layer (than the higher levels of ZK connectivity and responses).</description>
      <pubDate>Wed, 02 Dec 2015 18:41:08 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Zookeeper-kerberos-issue-or-quorum-issue/m-p/34684#M10943</guid>
      <dc:creator>Harsh J</dc:creator>
      <dc:date>2015-12-02T18:41:08Z</dc:date>
    </item>
    <item>
      <title>Re: Zookeeper kerberos issue or quorum issue?</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Zookeeper-kerberos-issue-or-quorum-issue/m-p/34703#M10944</link>
      <description>&lt;P&gt;Thanks Harsh,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So, to generalize, the mechanism level subcodes can always be taken as some failure in communicating with KDC, right?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I also see that despite this error, ZK does continue to function ... so is this error to be really treated seriously?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks again.&lt;/P&gt;</description>
      <pubDate>Thu, 03 Dec 2015 03:45:02 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Zookeeper-kerberos-issue-or-quorum-issue/m-p/34703#M10944</guid>
      <dc:creator>sumit.nigam</dc:creator>
      <dc:date>2015-12-03T03:45:02Z</dc:date>
    </item>
    <item>
      <title>Re: Zookeeper kerberos issue or quorum issue?</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Zookeeper-kerberos-issue-or-quorum-issue/m-p/34838#M10945</link>
      <description>&amp;gt; So, to generalize, the mechanism level subcodes can always be taken as some failure in communicating with KDC, right?&lt;BR /&gt;&lt;BR /&gt;Yes, it can be always taken as something wrong in the Kerberos layer (not necessarily only KDC, could also be things such as bad enctypes in keytab, etc., but always Kerberos mechanism related)&lt;BR /&gt;&lt;BR /&gt;&amp;gt; I also see that despite this error, ZK does continue to function ... so is this error to be really treated seriously?&lt;BR /&gt;&lt;BR /&gt;Did a retry of the auth perhaps succeed? Its not normal for it to repeat the errors.</description>
      <pubDate>Mon, 07 Dec 2015 05:23:24 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Zookeeper-kerberos-issue-or-quorum-issue/m-p/34838#M10945</guid>
      <dc:creator>Harsh J</dc:creator>
      <dc:date>2015-12-07T05:23:24Z</dc:date>
    </item>
  </channel>
</rss>

