<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>question Can not invoke hdfs command after invoking webhdfs operation in secure cluster in Archives of Support Questions (Read Only)</title>
    <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Can-not-invoke-hdfs-command-after-invoking-webhdfs-operation/m-p/153176#M20516</link>
    <description>&lt;P&gt;Here's what I did in my secure cluster:&lt;/P&gt;&lt;P&gt;1. Invokding webhdfs command: "curl -s -i --negotiate -u:anyUser http://sandbox.hortonworks.com:50070/webhdfs/v1/?op=LISTSTATUS"   (this works)&lt;/P&gt;&lt;P&gt;2. Invoking hdfs command: "hadoop fs -ls /" &lt;/P&gt;&lt;P&gt;But get the following error. (I need to kdestroy and kinti again to renew the ticket to make it work). This is weird, how can I make the webhdfs command not affect the hdfs command ?&lt;/P&gt;&lt;P&gt;16/02/23 03:38:41 WARN ipc.Client: Exception encountered while connecting to the server : javax.security.sasl.SaslException: GSS initiate failed [Caused by GSSException: No valid credentials provided (Mechanism level: Failed to find any Kerberos tgt)]
ls: Failed on local exception: java.io.IOException: javax.security.sasl.SaslException: GSS initiate failed [Caused by GSSException: No valid credentials provided (Mechanism level: Failed to find any Kerberos tgt)]; Host Details : local host is: "sandbox.hortonworks.com/10.0.2.15"; destination host is: "sandbox.hortonworks.com":8020;&lt;/P&gt;&lt;P&gt;The only difference after step 1 in klist is that I have 2 extra HTTP principal, but I still have my principal jeff@EXAMPLE.COM&lt;/P&gt;&lt;P&gt;Default principal: jeff@EXAMPLE.COM
Valid starting     Expires            Service principal
02/23/16 03:20:05  02/24/16 03:20:05  krbtgt/EXAMPLE.COM@EXAMPLE.COM
renew until 02/23/16 03:20:05
02/23/16 03:20:10  02/24/16 03:20:05  HTTP/sandbox.hortonworks.com@
renew until 02/23/16 03:20:05
02/23/16 03:20:10  02/24/16 03:20:05  HTTP/sandbox.hortonworks.com@EXAMPLE.COM
renew until 02/23/16 03:20:05&lt;/P&gt;</description>
    <pubDate>Tue, 23 Feb 2016 11:42:17 GMT</pubDate>
    <dc:creator>jzhang</dc:creator>
    <dc:date>2016-02-23T11:42:17Z</dc:date>
    <item>
      <title>Can not invoke hdfs command after invoking webhdfs operation in secure cluster</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Can-not-invoke-hdfs-command-after-invoking-webhdfs-operation/m-p/153176#M20516</link>
      <description>&lt;P&gt;Here's what I did in my secure cluster:&lt;/P&gt;&lt;P&gt;1. Invokding webhdfs command: "curl -s -i --negotiate -u:anyUser http://sandbox.hortonworks.com:50070/webhdfs/v1/?op=LISTSTATUS"   (this works)&lt;/P&gt;&lt;P&gt;2. Invoking hdfs command: "hadoop fs -ls /" &lt;/P&gt;&lt;P&gt;But get the following error. (I need to kdestroy and kinti again to renew the ticket to make it work). This is weird, how can I make the webhdfs command not affect the hdfs command ?&lt;/P&gt;&lt;P&gt;16/02/23 03:38:41 WARN ipc.Client: Exception encountered while connecting to the server : javax.security.sasl.SaslException: GSS initiate failed [Caused by GSSException: No valid credentials provided (Mechanism level: Failed to find any Kerberos tgt)]
ls: Failed on local exception: java.io.IOException: javax.security.sasl.SaslException: GSS initiate failed [Caused by GSSException: No valid credentials provided (Mechanism level: Failed to find any Kerberos tgt)]; Host Details : local host is: "sandbox.hortonworks.com/10.0.2.15"; destination host is: "sandbox.hortonworks.com":8020;&lt;/P&gt;&lt;P&gt;The only difference after step 1 in klist is that I have 2 extra HTTP principal, but I still have my principal jeff@EXAMPLE.COM&lt;/P&gt;&lt;P&gt;Default principal: jeff@EXAMPLE.COM
Valid starting     Expires            Service principal
02/23/16 03:20:05  02/24/16 03:20:05  krbtgt/EXAMPLE.COM@EXAMPLE.COM
renew until 02/23/16 03:20:05
02/23/16 03:20:10  02/24/16 03:20:05  HTTP/sandbox.hortonworks.com@
renew until 02/23/16 03:20:05
02/23/16 03:20:10  02/24/16 03:20:05  HTTP/sandbox.hortonworks.com@EXAMPLE.COM
renew until 02/23/16 03:20:05&lt;/P&gt;</description>
      <pubDate>Tue, 23 Feb 2016 11:42:17 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Can-not-invoke-hdfs-command-after-invoking-webhdfs-operation/m-p/153176#M20516</guid>
      <dc:creator>jzhang</dc:creator>
      <dc:date>2016-02-23T11:42:17Z</dc:date>
    </item>
    <item>
      <title>Re: Can not invoke hdfs command after invoking webhdfs operation in secure cluster</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Can-not-invoke-hdfs-command-after-invoking-webhdfs-operation/m-p/153177#M20517</link>
      <description>&lt;A rel="user" href="https://community.cloudera.com/users/453/jzhang.html" nodeid="453"&gt;@jzhang&lt;/A&gt;&lt;P&gt;This is related to not having correct ticket from KDC. You can test by getting a ticket from hdfs keytab. kinit with hdfs headless and see if hdfs -ls works or not&lt;/P&gt;</description>
      <pubDate>Tue, 23 Feb 2016 14:06:25 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Can-not-invoke-hdfs-command-after-invoking-webhdfs-operation/m-p/153177#M20517</guid>
      <dc:creator>nsabharwal</dc:creator>
      <dc:date>2016-02-23T14:06:25Z</dc:date>
    </item>
    <item>
      <title>Re: Can not invoke hdfs command after invoking webhdfs operation in secure cluster</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Can-not-invoke-hdfs-command-after-invoking-webhdfs-operation/m-p/153178#M20518</link>
      <description>&lt;P&gt;Yeah, I see this should due to ticket issue. But I don't understand why the webhdfs command corrupt my ticket. If I only invoke step 2, everything is OK. &lt;/P&gt;</description>
      <pubDate>Tue, 23 Feb 2016 14:08:08 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Can-not-invoke-hdfs-command-after-invoking-webhdfs-operation/m-p/153178#M20518</guid>
      <dc:creator>jzhang</dc:creator>
      <dc:date>2016-02-23T14:08:08Z</dc:date>
    </item>
    <item>
      <title>Re: Can not invoke hdfs command after invoking webhdfs operation in secure cluster</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Can-not-invoke-hdfs-command-after-invoking-webhdfs-operation/m-p/153179#M20519</link>
      <description>&lt;P&gt;&lt;A rel="user" href="https://community.cloudera.com/users/453/jzhang.html" nodeid="453"&gt;@jzhang&lt;/A&gt;  You will be running curl from the client node and hdfs from edge or master node.&lt;/P&gt;</description>
      <pubDate>Tue, 23 Feb 2016 14:20:07 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Can-not-invoke-hdfs-command-after-invoking-webhdfs-operation/m-p/153179#M20519</guid>
      <dc:creator>nsabharwal</dc:creator>
      <dc:date>2016-02-23T14:20:07Z</dc:date>
    </item>
    <item>
      <title>Re: Can not invoke hdfs command after invoking webhdfs operation in secure cluster</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Can-not-invoke-hdfs-command-after-invoking-webhdfs-operation/m-p/153180#M20520</link>
      <description>&lt;P&gt;No, I am running this in the same node. Actually I did it in sandbox. Only one node. &lt;/P&gt;</description>
      <pubDate>Tue, 23 Feb 2016 14:29:07 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Can-not-invoke-hdfs-command-after-invoking-webhdfs-operation/m-p/153180#M20520</guid>
      <dc:creator>jzhang</dc:creator>
      <dc:date>2016-02-23T14:29:07Z</dc:date>
    </item>
    <item>
      <title>Re: Can not invoke hdfs command after invoking webhdfs operation in secure cluster</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Can-not-invoke-hdfs-command-after-invoking-webhdfs-operation/m-p/153181#M20521</link>
      <description>&lt;P&gt;&lt;A rel="user" href="https://community.cloudera.com/users/453/jzhang.html" nodeid="453"&gt;@jzhang&lt;/A&gt;  That's exactly my point that REST access will from the client so you should not worry about the kerberos ticket issue&lt;/P&gt;</description>
      <pubDate>Tue, 23 Feb 2016 17:47:06 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Can-not-invoke-hdfs-command-after-invoking-webhdfs-operation/m-p/153181#M20521</guid>
      <dc:creator>nsabharwal</dc:creator>
      <dc:date>2016-02-23T17:47:06Z</dc:date>
    </item>
    <item>
      <title>Re: Can not invoke hdfs command after invoking webhdfs operation in secure cluster</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Can-not-invoke-hdfs-command-after-invoking-webhdfs-operation/m-p/153182#M20522</link>
      <description>&lt;P&gt;No, actually step 1 is spnego which require ticket, &lt;A href="https://hadoop.apache.org/docs/stable/hadoop-auth/Examples.html"&gt;https://hadoop.apache.org/docs/stable/hadoop-auth/Examples.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;What I don't understand is that before step 1, I can invoke hdfs command, but after step 1, I can not run step 1, seems my ticket is corrupted. &lt;/P&gt;</description>
      <pubDate>Wed, 24 Feb 2016 17:54:44 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Can-not-invoke-hdfs-command-after-invoking-webhdfs-operation/m-p/153182#M20522</guid>
      <dc:creator>jzhang</dc:creator>
      <dc:date>2016-02-24T17:54:44Z</dc:date>
    </item>
    <item>
      <title>Re: Can not invoke hdfs command after invoking webhdfs operation in secure cluster</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Can-not-invoke-hdfs-command-after-invoking-webhdfs-operation/m-p/153183#M20523</link>
      <description>&lt;P&gt;Well, this is "interesting". &lt;/P&gt;&lt;P&gt;I think it's that specific realmless principal, "HTTP/sandbox.hortonworks.com@"; you don't have a TGT ticket for that empty realm, so fail. I've heard of this before&lt;/P&gt;&lt;P&gt;&lt;A href="https://steveloughran.gitbooks.io/kerberos_and_hadoop/content/sections/terrors.html"&gt;https://steveloughran.gitbooks.io/kerberos_and_hadoop/content/sections/terrors.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Follow the instructions there; if it makes it go away, then it's a sign that the krb5 in the sandbox needs fixing&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;If you use kdestroy to delete the HTTP/sandbox.hortonworks.com@ ticket, what does that do?&lt;/LI&gt;&lt;LI&gt;download Kdiag and give it a run before and after the curl call: &lt;A href="https://github.com/steveloughran/kdiag"&gt;https://github.com/steveloughran/kdiag&lt;/A&gt; . `export HADOOP_JAAS_DEBUG=true` for extra info; grab stdout and stderr  into a single file, and attach.&lt;/LI&gt;&lt;LI&gt;what does your /etc/krb5.conf say? Mine explicitly set dns_lookup_realm = false and dns_lookup_kdc = false&lt;/LI&gt;&lt;LI&gt;set the env vars and JVM properties covered in troubleshooting, see what's being negotiated. &lt;A href="https://github.com/apache/hadoop/blob/trunk/hadoop-common-project/hadoop-common/src/site/markdown/SecureMode.md"&gt;https://github.com/apache/hadoop/blob/trunk/hadoop-common-project/hadoop-common/src/site/markdown/SecureMode.md&lt;/A&gt;&lt;/LI&gt;&lt;/OL&gt;</description>
      <pubDate>Thu, 03 Mar 2016 19:44:17 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Can-not-invoke-hdfs-command-after-invoking-webhdfs-operation/m-p/153183#M20523</guid>
      <dc:creator>stevel</dc:creator>
      <dc:date>2016-03-03T19:44:17Z</dc:date>
    </item>
    <item>
      <title>Re: Can not invoke hdfs command after invoking webhdfs operation in secure cluster</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Can-not-invoke-hdfs-command-after-invoking-webhdfs-operation/m-p/153184#M20524</link>
      <description>&lt;P&gt;Not sure how to destroy this specify ticket, kdestroy will delete all the tickets. And I didn't add this ticket explicitly it is added after I invoke the the first curl command&lt;/P&gt;&lt;P&gt;my dns_lookup_realm = false and dns_lookup_kdc = false&lt;/P&gt;&lt;P&gt;attach the output of Kdiag&lt;/P&gt;</description>
      <pubDate>Thu, 03 Mar 2016 21:27:59 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Can-not-invoke-hdfs-command-after-invoking-webhdfs-operation/m-p/153184#M20524</guid>
      <dc:creator>jzhang</dc:creator>
      <dc:date>2016-03-03T21:27:59Z</dc:date>
    </item>
    <item>
      <title>Re: Can not invoke hdfs command after invoking webhdfs operation in secure cluster</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Can-not-invoke-hdfs-command-after-invoking-webhdfs-operation/m-p/153185#M20525</link>
      <description>&lt;P&gt;&lt;EM&gt;The instruction on &lt;/EM&gt;&lt;A href="https://steveloughran.gitbooks.io/kerberos_and_hadoop/content/sections/terrors.html"&gt;https://steveloughran.gitbooks.io/kerberos_and_hadoop/content/sections/terrors.html&lt;/A&gt; can fix this issue&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Fix: add a &lt;CODE&gt;domain_realm&lt;/CODE&gt; in &lt;CODE&gt;/etc/krb5.conf&lt;/CODE&gt; mapping hostnames to realms&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;[domain_realm] &lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;    sandbox.hortonworks.com = EXAMPLE.COM
&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 03 Mar 2016 22:44:13 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Can-not-invoke-hdfs-command-after-invoking-webhdfs-operation/m-p/153185#M20525</guid>
      <dc:creator>jzhang</dc:creator>
      <dc:date>2016-03-03T22:44:13Z</dc:date>
    </item>
  </channel>
</rss>

