<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>question Re: Services failing to restart after kerberizing cluster  - HDP2.3 in Archives of Support Questions (Read Only)</title>
    <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Services-failing-to-restart-after-kerberizing-cluster-HDP2-3/m-p/98649#M11984</link>
    <description>&lt;P&gt;@Robert Levas&lt;/P&gt;&lt;P&gt;The following is the output&lt;/P&gt;&lt;P&gt;[root@hashmap keytabs]# klist -kte /etc/security/keytabs/spnego.service.keytab Keytab name: FILE:/etc/security/keytabs/spnego.service.keytab KVNO Timestamp Principal ---- ----------------- -------------------------------------------------------- 3 12/11/15 23:25:47 HTTP/hashmap.domain.com@HADOOP.COM (arcfour-hmac) 3 12/11/15 23:25:47 HTTP/hashmap.domain.com@HADOOP.COM (des-cbc-md5) 3 12/11/15 23:25:47 HTTP/hashmap.domain.com@HADOOP.COM (aes256-cts-hmac-sha1-96) 3 12/11/15 23:25:47 HTTP/hashmap.domain.com@HADOOP.COM (aes128-cts-hmac-sha1-96) 3 12/11/15 23:25:47 HTTP/hashmap.domain.com@HADOOP.COM (des3-cbc-sha1) [root@hashmap keytabs]# klist -kte /etc/security/keytabs/dn.service.keytab Keytab name: FILE:/etc/security/keytabs/dn.service.keytab KVNO Timestamp Principal ---- ----------------- -------------------------------------------------------- 3 12/11/15 23:25:47 dn/hashmap.domain.com@HADOOP.COM (arcfour-hmac) 3 12/11/15 23:25:47 dn/hashmap.domain.com@HADOOP.COM (des-cbc-md5) 3 12/11/15 23:25:47 dn/hashmap.domain.com@HADOOP.COM (aes256-cts-hmac-sha1-96) 3 12/11/15 23:25:47 dn/hashmap.domain.com@HADOOP.COM (aes128-cts-hmac-sha1-96) 3 12/11/15 23:25:47 dn/hashmap.domain.com@HADOOP.COM (des3-cbc-sha1) [root@hashmap keytabs]# &lt;/P&gt;</description>
    <pubDate>Sat, 12 Dec 2015 02:34:42 GMT</pubDate>
    <dc:creator>prijan_kurup</dc:creator>
    <dc:date>2015-12-12T02:34:42Z</dc:date>
    <item>
      <title>Services failing to restart after kerberizing cluster  - HDP2.3</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Services-failing-to-restart-after-kerberizing-cluster-HDP2-3/m-p/98643#M11978</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;Getting the following error in the hdfs log files "hadoop-hdfs-datanode-hashmap.domain.com.log" &lt;/P&gt;&lt;P&gt;Error&lt;/P&gt;&lt;PRE&gt;javax.security.sasl.SaslException: GSS initiate failed [Caused by GSSException: No valid credentials provided (Mechanism level: Fail to create credential. (63) - No service creds)]
        at com.sun.security.sasl.gsskerb.GssKrb5Client.evaluateChallenge(GssKrb5Client.java:211)
        at org.apache.hadoop.security.SaslRpcClient.saslConnect(SaslRpcClient.java:413)
        at org.apache.hadoop.ipc.Client$Connection.setupSaslConnection(Client.java:558)
        at org.apache.hadoop.ipc.Client$Connection.access$1800(Client.java:373)
        at org.apache.hadoop.ipc.Client$Connection$2.run(Client.java:727)
        at org.apache.hadoop.ipc.Client$Connection$2.run(Client.java:723)
        at java.security.AccessController.doPrivileged(Native Method)
        at javax.security.auth.Subject.doAs(Subject.java:422)
        at org.apache.hadoop.security.UserGroupInformation.doAs(UserGroupInformation.java:1657)
        at org.apache.hadoop.ipc.Client$Connection.setupIOstreams(Client.java:722)
        at org.apache.hadoop.ipc.Client$Connection.access$2800(Client.java:373)
        at org.apache.hadoop.ipc.Client.getConnection(Client.java:1493)
        at org.apache.hadoop.ipc.Client.call(Client.java:1397)
        at org.apache.hadoop.ipc.Client.call(Client.java:1358)
        at org.apache.hadoop.ipc.ProtobufRpcEngine$Invoker.invoke(ProtobufRpcEngine.java:229)
        at com.sun.proxy.$Proxy15.versionRequest(Unknown Source)
        at org.apache.hadoop.hdfs.protocolPB.DatanodeProtocolClientSideTranslatorPB.versionRequest(DatanodeProtocolClientSideTranslatorPB.java:272)
        at org.apache.hadoop.hdfs.server.datanode.BPServiceActor.retrieveNamespaceInfo(BPServiceActor.java:173)
        at org.apache.hadoop.hdfs.server.datanode.BPServiceActor.connectToNNAndHandshake(BPServiceActor.java:219)
        at org.apache.hadoop.hdfs.server.datanode.BPServiceActor.run(BPServiceActor.java:821)
        at java.lang.Thread.run(Thread.java:745)
Caused by: GSSException: No valid credentials provided (Mechanism level: Fail to create credential. (63) - No service crews)&lt;/PRE&gt;&lt;P&gt;Need help  / pointers to fix the issue.&lt;/P&gt;</description>
      <pubDate>Fri, 16 Sep 2022 09:52:36 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Services-failing-to-restart-after-kerberizing-cluster-HDP2-3/m-p/98643#M11978</guid>
      <dc:creator>prijan_kurup</dc:creator>
      <dc:date>2022-09-16T09:52:36Z</dc:date>
    </item>
    <item>
      <title>Re: Services failing to restart after kerberizing cluster  - HDP2.3</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Services-failing-to-restart-after-kerberizing-cluster-HDP2-3/m-p/98644#M11979</link>
      <description>&lt;P&gt;What KDC are you using? MIT? AD?&lt;/P&gt;&lt;P&gt;Whats your JDK version?&lt;/P&gt;&lt;P&gt;There could be multiple reasons for that, here are some pointers:&lt;/P&gt;&lt;P&gt;1)Validate the generated keytabs, this will tell you right away if there is something wrong with your keytab files or not.&lt;/P&gt;&lt;PRE&gt;kinit -kt /&amp;lt;path to keytabs&amp;gt;/&amp;lt;keytab file&amp;gt; &amp;lt;principal&amp;gt;&lt;/PRE&gt;&lt;P&gt;Check if a valid ticket was created via&lt;/P&gt;&lt;PRE&gt;klist&lt;/PRE&gt;&lt;P&gt;2) Validate JCE files: Are the JCE files available (&lt;EM&gt;/&amp;lt;jdk path&amp;gt;/jre/lib/security/....&lt;/EM&gt;)? Do you need the Unlimited Strength JCEs?&lt;/P&gt;&lt;P&gt;3) Check permissions of the generated keytab files. For example hdfs-headless keytab should belong to hdfs:hadoop with permissions set to 0400.&lt;/P&gt;&lt;P&gt;4) Validate the krb5.conf file (usually under &lt;EM&gt;/etc/krb5.conf&lt;/EM&gt;), make sure its available and sound.&lt;/P&gt;&lt;P&gt;What are the results of the above?&lt;/P&gt;&lt;P&gt;You might also want to read through this great guid=&amp;gt; &lt;A href="https://github.com/steveloughran/kerberos_and_hadoop"&gt;https://github.com/steveloughran/kerberos_and_hado...&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 11 Dec 2015 04:22:43 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Services-failing-to-restart-after-kerberizing-cluster-HDP2-3/m-p/98644#M11979</guid>
      <dc:creator>jstraub</dc:creator>
      <dc:date>2015-12-11T04:22:43Z</dc:date>
    </item>
    <item>
      <title>Re: Services failing to restart after kerberizing cluster  - HDP2.3</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Services-failing-to-restart-after-kerberizing-cluster-HDP2-3/m-p/98645#M11980</link>
      <description>&lt;P&gt;&lt;A rel="user" href="https://community.cloudera.com/users/875/prijankurup.html" nodeid="875"&gt;@Prijan Kurup&lt;/A&gt; Is it MIT KDC ? or MSFT KDC? Are you able to get ticket from kdc for services like hdfs?&lt;/P&gt;</description>
      <pubDate>Fri, 11 Dec 2015 04:24:52 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Services-failing-to-restart-after-kerberizing-cluster-HDP2-3/m-p/98645#M11980</guid>
      <dc:creator>nsabharwal</dc:creator>
      <dc:date>2015-12-11T04:24:52Z</dc:date>
    </item>
    <item>
      <title>Re: Services failing to restart after kerberizing cluster  - HDP2.3</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Services-failing-to-restart-after-kerberizing-cluster-HDP2-3/m-p/98646#M11981</link>
      <description>&lt;P&gt;Its MIT Kerberos in Centos&lt;/P&gt;</description>
      <pubDate>Fri, 11 Dec 2015 21:21:50 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Services-failing-to-restart-after-kerberizing-cluster-HDP2-3/m-p/98646#M11981</guid>
      <dc:creator>prijan_kurup</dc:creator>
      <dc:date>2015-12-11T21:21:50Z</dc:date>
    </item>
    <item>
      <title>Re: Services failing to restart after kerberizing cluster  - HDP2.3</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Services-failing-to-restart-after-kerberizing-cluster-HDP2-3/m-p/98647#M11982</link>
      <description>&lt;P&gt;Jonas&lt;/P&gt;&lt;P&gt;Its Cross Realm trust one way between AD and MIT kerberos in Centos. The JDK version is 1.8 and I have applied the JCE8 files . Let me validate the generated key tabs. Appreciate the suggestions.&lt;/P&gt;&lt;P&gt;Prijan&lt;/P&gt;</description>
      <pubDate>Fri, 11 Dec 2015 21:24:43 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Services-failing-to-restart-after-kerberizing-cluster-HDP2-3/m-p/98647#M11982</guid>
      <dc:creator>prijan_kurup</dc:creator>
      <dc:date>2015-12-11T21:24:43Z</dc:date>
    </item>
    <item>
      <title>Re: Services failing to restart after kerberizing cluster  - HDP2.3</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Services-failing-to-restart-after-kerberizing-cluster-HDP2-3/m-p/98648#M11983</link>
      <description>&lt;P&gt;On the host that is showing this error, can you klist the following keytab files:  &lt;/P&gt;&lt;UL&gt;&lt;LI&gt;/etc/security/keytabs/spnego.service.keytab&lt;/LI&gt;&lt;LI&gt; /etc/security/keytabs/dn.service.keytab
&lt;/LI&gt;&lt;/UL&gt;&lt;PRE&gt;[root@c6501 ~]# klist -kte /etc/security/keytabs/spnego.service.keytab
Keytab name: FILE:/etc/security/keytabs/spnego.service.keytab
KVNO Timestamp         Principal
---- ----------------- --------------------------------------------------------
   1 12/11/15 15:38:21 HTTP/c6501.ambari.apache.org@EXAMPLE.COM (des-cbc-md5)
   1 12/11/15 15:38:21 HTTP/c6501.ambari.apache.org@EXAMPLE.COM (aes256-cts-hmac-sha1-96)
   1 12/11/15 15:38:21 HTTP/c6501.ambari.apache.org@EXAMPLE.COM (des3-cbc-sha1)
   1 12/11/15 15:38:21 HTTP/c6501.ambari.apache.org@EXAMPLE.COM (arcfour-hmac)
   1 12/11/15 15:38:21 HTTP/c6501.ambari.apache.org@EXAMPLE.COM (aes128-cts-hmac-sha1-96)

[root@c6501 ~]# klist -kte /etc/security/keytabs/dn.service.keytab
Keytab name: FILE:/etc/security/keytabs/dn.service.keytab
KVNO Timestamp         Principal
---- ----------------- --------------------------------------------------------
   1 12/11/15 15:38:21 dn/c6501.ambari.apache.org@EXAMPLE.COM (des-cbc-md5)
   1 12/11/15 15:38:21 dn/c6501.ambari.apache.org@EXAMPLE.COM (aes256-cts-hmac-sha1-96)
   1 12/11/15 15:38:21 dn/c6501.ambari.apache.org@EXAMPLE.COM (des3-cbc-sha1)
   1 12/11/15 15:38:21 dn/c6501.ambari.apache.org@EXAMPLE.COM (arcfour-hmac)
   1 12/11/15 15:38:21 dn/c6501.ambari.apache.org@EXAMPLE.COM (aes128-cts-hmac-sha1-96)
&lt;/PRE&gt;&lt;P&gt;Notice that my examples have entries for &lt;STRONG&gt;aes256-cts-hmac-sha1-96&lt;/STRONG&gt;, do yours?  If not, then you will need to make sure that you have the Unlimited Key JCE policy jars (for your JVM) installed.  &lt;/P&gt;&lt;P&gt;If these look good, then from the host you having the issue with, can you attempt to kinit using them.  If you get no messages, all is good... else there is a disconnect between your keytab file and the password stored in the KDC.&lt;/P&gt;&lt;P&gt;Success case:&lt;/P&gt;&lt;PRE&gt;[root@c6501 ~]# kinit -kt /etc/security/keytabs/dn.service.keytab dn/c6501.ambari.apache.org@EXAMPLE.COM
[root@c6501 ~]#
&lt;/PRE&gt;&lt;P&gt;Failure case:&lt;/P&gt;&lt;PRE&gt;[root@c6501 ~]# kinit -kt /etc/security/keytabs/dn.service.keytab dn/c6501.ambari.apache.org@EXAMPLE.COM
kinit: Password incorrect while getting initial credentials
[root@c6501 ~]#
&lt;/PRE&gt;&lt;P&gt;If you get this failure, then try to regenerate the keytab files from the Ambari UI to see if that helps the issue.&lt;/P&gt;</description>
      <pubDate>Fri, 11 Dec 2015 23:49:24 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Services-failing-to-restart-after-kerberizing-cluster-HDP2-3/m-p/98648#M11983</guid>
      <dc:creator>rlevas</dc:creator>
      <dc:date>2015-12-11T23:49:24Z</dc:date>
    </item>
    <item>
      <title>Re: Services failing to restart after kerberizing cluster  - HDP2.3</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Services-failing-to-restart-after-kerberizing-cluster-HDP2-3/m-p/98649#M11984</link>
      <description>&lt;P&gt;@Robert Levas&lt;/P&gt;&lt;P&gt;The following is the output&lt;/P&gt;&lt;P&gt;[root@hashmap keytabs]# klist -kte /etc/security/keytabs/spnego.service.keytab Keytab name: FILE:/etc/security/keytabs/spnego.service.keytab KVNO Timestamp Principal ---- ----------------- -------------------------------------------------------- 3 12/11/15 23:25:47 HTTP/hashmap.domain.com@HADOOP.COM (arcfour-hmac) 3 12/11/15 23:25:47 HTTP/hashmap.domain.com@HADOOP.COM (des-cbc-md5) 3 12/11/15 23:25:47 HTTP/hashmap.domain.com@HADOOP.COM (aes256-cts-hmac-sha1-96) 3 12/11/15 23:25:47 HTTP/hashmap.domain.com@HADOOP.COM (aes128-cts-hmac-sha1-96) 3 12/11/15 23:25:47 HTTP/hashmap.domain.com@HADOOP.COM (des3-cbc-sha1) [root@hashmap keytabs]# klist -kte /etc/security/keytabs/dn.service.keytab Keytab name: FILE:/etc/security/keytabs/dn.service.keytab KVNO Timestamp Principal ---- ----------------- -------------------------------------------------------- 3 12/11/15 23:25:47 dn/hashmap.domain.com@HADOOP.COM (arcfour-hmac) 3 12/11/15 23:25:47 dn/hashmap.domain.com@HADOOP.COM (des-cbc-md5) 3 12/11/15 23:25:47 dn/hashmap.domain.com@HADOOP.COM (aes256-cts-hmac-sha1-96) 3 12/11/15 23:25:47 dn/hashmap.domain.com@HADOOP.COM (aes128-cts-hmac-sha1-96) 3 12/11/15 23:25:47 dn/hashmap.domain.com@HADOOP.COM (des3-cbc-sha1) [root@hashmap keytabs]# &lt;/P&gt;</description>
      <pubDate>Sat, 12 Dec 2015 02:34:42 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Services-failing-to-restart-after-kerberizing-cluster-HDP2-3/m-p/98649#M11984</guid>
      <dc:creator>prijan_kurup</dc:creator>
      <dc:date>2015-12-12T02:34:42Z</dc:date>
    </item>
    <item>
      <title>Re: Services failing to restart after kerberizing cluster  - HDP2.3</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Services-failing-to-restart-after-kerberizing-cluster-HDP2-3/m-p/98650#M11985</link>
      <description>&lt;P&gt;[root@hashmap keytabs]# kinit -kt /etc/security/keytabs/dn.service.keytab dn/hashmap.domain.com@HADOOP.COM
[root@hashmap keytabs]# klist
Ticket cache: FILE:/tmp/krb5cc_0
Default principal: dn/hashmap.domain.com@HADOOP.COM
Valid starting     Expires            Service principal
12/12/15 00:07:38  12/13/15 00:07:38  krbtgt/HADOOP.COM@HADOOP.COM
renew until 12/12/15 00:07:38&lt;/P&gt;</description>
      <pubDate>Sat, 12 Dec 2015 02:38:00 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Services-failing-to-restart-after-kerberizing-cluster-HDP2-3/m-p/98650#M11985</guid>
      <dc:creator>prijan_kurup</dc:creator>
      <dc:date>2015-12-12T02:38:00Z</dc:date>
    </item>
    <item>
      <title>Re: Services failing to restart after kerberizing cluster  - HDP2.3</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Services-failing-to-restart-after-kerberizing-cluster-HDP2-3/m-p/98651#M11986</link>
      <description>&lt;P&gt;HTTP/hashmap.domain.com@HADOOP.COM (arcfour-hmac) 
   3 12/11/15 23:25:47 HTTP/hashmap.domain.com@HADOOP.COM (des-cbc-md5) 
   3 12/11/15 23:25:47 HTTP/hashmap.domain.com@HADOOP.COM (aes256-cts-hmac-sha1-96) 
   3 12/11/15 23:25:47 HTTP/hashmap.domain.com@HADOOP.COM (aes128-cts-hmac-sha1-96) 
   3 12/11/15 23:25:47 HTTP/hashmap.domain.com@HADOOP.COM (des3-cbc-sha1) &lt;/P&gt;</description>
      <pubDate>Sat, 12 Dec 2015 02:41:11 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Services-failing-to-restart-after-kerberizing-cluster-HDP2-3/m-p/98651#M11986</guid>
      <dc:creator>prijan_kurup</dc:creator>
      <dc:date>2015-12-12T02:41:11Z</dc:date>
    </item>
    <item>
      <title>Re: Services failing to restart after kerberizing cluster  - HDP2.3</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Services-failing-to-restart-after-kerberizing-cluster-HDP2-3/m-p/98652#M11987</link>
      <description>&lt;P&gt;KVNO Timestamp         Principal
---- ----------------- --------------------------------------------------------
   3 12/11/15 23:25:47 dn/hashmap.domain.com@HADOOP.COM (arcfour-hmac) 
   3 12/11/15 23:25:47 dn/hashmap.domain.com@HADOOP.COM (des-cbc-md5) 
   3 12/11/15 23:25:47 dn/hashmap.domain.com@HADOOP.COM (aes256-cts-hmac-sha1-96) 
   3 12/11/15 23:25:47 dn/hashmap.domain.com@HADOOP.COM (aes128-cts-hmac-sha1-96) 
   3 12/11/15 23:25:47 dn/hashmap.domain.com@HADOOP.COM (des3-cbc-sha1)&lt;/P&gt;</description>
      <pubDate>Sat, 12 Dec 2015 02:41:54 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Services-failing-to-restart-after-kerberizing-cluster-HDP2-3/m-p/98652#M11987</guid>
      <dc:creator>prijan_kurup</dc:creator>
      <dc:date>2015-12-12T02:41:54Z</dc:date>
    </item>
    <item>
      <title>Re: Services failing to restart after kerberizing cluster  - HDP2.3</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Services-failing-to-restart-after-kerberizing-cluster-HDP2-3/m-p/98653#M11988</link>
      <description>&lt;P&gt;Was Kerberos enabled using Ambari's automation, or was this done manually?&lt;/P&gt;</description>
      <pubDate>Sat, 12 Dec 2015 03:46:52 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Services-failing-to-restart-after-kerberizing-cluster-HDP2-3/m-p/98653#M11988</guid>
      <dc:creator>rlevas</dc:creator>
      <dc:date>2015-12-12T03:46:52Z</dc:date>
    </item>
  </channel>
</rss>

