<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>question Re: &amp;quot;Test Connection&amp;quot; for ranger kms repository fails in Archives of Support Questions (Read Only)</title>
    <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/quot-Test-Connection-quot-for-ranger-kms-repository-fails/m-p/151606#M24163</link>
    <description>&lt;P&gt;Hi Vipin,&lt;/P&gt;&lt;P&gt;In my case also, user name coming as only 'keyadmin" instead of &lt;A href="mailto:keyadmin@realm"&gt;keyadmin@realm&lt;/A&gt; but I am giving username as&lt;/P&gt;&lt;P&gt;&lt;A href="mailto:keyadmin@realm"&gt;keyadmin@realm&lt;/A&gt; in UI:-&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;UNAUTHENTICATED RemoteHost:127.0.0.1 Method:GET &lt;A href="http://hostname:9292/kms/v1/keys/names?doAs=keyadmin"&gt;URL:http://hostname:9292/kms/v1/keys/names?doAs=keyadmin&lt;/A&gt; ErrorMsg:'Authentication required'.&lt;/P&gt;&lt;P&gt;which property should I change for this?&lt;/P&gt;&lt;P&gt;please help.&lt;/P&gt;&lt;P&gt;Thanks in advance&lt;/P&gt;</description>
    <pubDate>Tue, 24 May 2016 03:21:54 GMT</pubDate>
    <dc:creator>trip_ankit87</dc:creator>
    <dc:date>2016-05-24T03:21:54Z</dc:date>
    <item>
      <title>"Test Connection" for ranger kms repository fails</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/quot-Test-Connection-quot-for-ranger-kms-repository-fails/m-p/151601#M24158</link>
      <description>&lt;P&gt;I followed the document for setting ranger kms on kerberized cluster. &lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.hortonworks.com/HDPDocuments/HDP2/HDP-2.3.2/bk_Ranger_KMS_Admin_Guide/content/ch03s02.html" target="_blank"&gt;https://docs.hortonworks.com/HDPDocuments/HDP2/HDP-2.3.2/bk_Ranger_KMS_Admin_Guide/content/ch03s02.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;While doing test connection to default repository of Ranger KMS it gives error as shown below -&lt;/P&gt;&lt;P&gt;Can you please help how to resolve this ?&lt;/P&gt;&lt;PRE&gt;2016-03-31 20:02:05,403 [timed-executor-pool-0] INFO  apache.ranger.services.kms.client.KMSClient (KMSClient.java:214) - getKeyList():response.getStatus()= 401 for URL &lt;A href="http://node1.example.com:9292/kms/v1/keys/names?user.name=keyadmin" target="_blank"&gt;http://node1.example.com:9292/kms/v1/keys/names?user.name=keyadmin&lt;/A&gt;, so returning null list
2016-03-31 20:02:05,408 [timed-executor-pool-0] ERROR apache.ranger.services.kms.client.KMSResourceMgr (KMSResourceMgr.java:43) - &amp;lt;== KMSResourceMgr.validateConfig Error: org.apache.ranger.plugin.client.HadoopException: &amp;lt;html&amp;gt;&amp;lt;head&amp;gt;&amp;lt;title&amp;gt;Apache Tomcat/7.0.55 - Error report&amp;lt;/title&amp;gt;&amp;lt;style&amp;gt;&amp;lt;!--H1 {font-family:Tahoma,Arial,sans-serif;color:white;background-color:#525D76;font-size:22px;} H2 {font-family:Tahoma,Arial,sans-serif;color:white;background-color:#525D76;font-size:16px;} H3 {font-family:Tahoma,Arial,sans-serif;color:white;background-color:#525D76;font-size:14px;} BODY {font-family:Tahoma,Arial,sans-serif;color:black;background-color:white;} B {font-family:Tahoma,Arial,sans-serif;color:white;background-color:#525D76;} P {font-family:Tahoma,Arial,sans-serif;background:white;color:black;font-size:12px;}A {color : black;}A.name {color : black;}HR {color : #525D76;}--&amp;gt;&amp;lt;/style&amp;gt; &amp;lt;/head&amp;gt;&amp;lt;body&amp;gt;&amp;lt;h1&amp;gt;HTTP Status 401 - Authentication required&amp;lt;/h1&amp;gt;&amp;lt;HR size="1" noshade="noshade"&amp;gt;&amp;lt;p&amp;gt;&amp;lt;b&amp;gt;type&amp;lt;/b&amp;gt; Status report&amp;lt;/p&amp;gt;&amp;lt;p&amp;gt;&amp;lt;b&amp;gt;message&amp;lt;/b&amp;gt; &amp;lt;u&amp;gt;Authentication required&amp;lt;/u&amp;gt;&amp;lt;/p&amp;gt;&amp;lt;p&amp;gt;&amp;lt;b&amp;gt;description&amp;lt;/b&amp;gt; &amp;lt;u&amp;gt;This request requires HTTP authentication.&amp;lt;/u&amp;gt;&amp;lt;/p&amp;gt;&amp;lt;HR size="1" noshade="noshade"&amp;gt;&amp;lt;h3&amp;gt;Apache Tomcat/7.0.55&amp;lt;/h3&amp;gt;&amp;lt;/body&amp;gt;&amp;lt;/html&amp;gt;&lt;/PRE&gt;</description>
      <pubDate>Thu, 31 Mar 2016 23:11:13 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/quot-Test-Connection-quot-for-ranger-kms-repository-fails/m-p/151601#M24158</guid>
      <dc:creator>sshimpi</dc:creator>
      <dc:date>2016-03-31T23:11:13Z</dc:date>
    </item>
    <item>
      <title>Re: "Test Connection" for ranger kms repository fails</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/quot-Test-Connection-quot-for-ranger-kms-repository-fails/m-p/151602#M24159</link>
      <description>&lt;P&gt;In Kerberized environments, repository config user should be a valid kerberos principal. Please create a valid principal like keyadmin@DOMAIN.COM with password and configure this in KMS repo - this needs to be done in ranger UI. Steps are listed &lt;A href="http://docs.hortonworks.com/HDPDocuments/HDP2/HDP-2.4.0/bk_Ranger_KMS_Admin_Guide/content/ch02s01s03.html"&gt;here&lt;/A&gt;. Although this is from latest documentation, these steps should work.&lt;/P&gt;&lt;P&gt;After repository is updated,  Ranger and KMS needs to be restarted.&lt;/P&gt;&lt;P&gt;Also make sure you have a link to core-site.xml under /etc/ranger/kms/conf as described &lt;A href="http://docs.hortonworks.com/HDPDocuments/HDP2/HDP-2.4.0/bk_Ranger_KMS_Admin_Guide/content/ch02s01s02.html"&gt;here&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 01 Apr 2016 00:51:23 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/quot-Test-Connection-quot-for-ranger-kms-repository-fails/m-p/151602#M24159</guid>
      <dc:creator>vperiasamy</dc:creator>
      <dc:date>2016-04-01T00:51:23Z</dc:date>
    </item>
    <item>
      <title>Re: "Test Connection" for ranger kms repository fails</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/quot-Test-Connection-quot-for-ranger-kms-repository-fails/m-p/151603#M24160</link>
      <description>&lt;P&gt;From the log, looks like you are still using the username as 'keyadmin' which won't work if you have setup Kerberos. The KMSClient code looks for keyadmin@REALM if kerberos is enabled. Please set that restart the Ranger and KMS services after the change.&lt;/P&gt;</description>
      <pubDate>Fri, 01 Apr 2016 02:59:51 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/quot-Test-Connection-quot-for-ranger-kms-repository-fails/m-p/151603#M24160</guid>
      <dc:creator>VR46</dc:creator>
      <dc:date>2016-04-01T02:59:51Z</dc:date>
    </item>
    <item>
      <title>Re: "Test Connection" for ranger kms repository fails</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/quot-Test-Connection-quot-for-ranger-kms-repository-fails/m-p/151604#M24161</link>
      <description>&lt;P&gt;Uhh just saw that &lt;A rel="user" href="https://community.cloudera.com/users/47/vperiasamy.html" nodeid="47"&gt;@vperiasamy &lt;/A&gt;had already replied. And that is pretty much correct. Cheers Vel !&lt;/P&gt;</description>
      <pubDate>Fri, 01 Apr 2016 03:01:03 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/quot-Test-Connection-quot-for-ranger-kms-repository-fails/m-p/151604#M24161</guid>
      <dc:creator>VR46</dc:creator>
      <dc:date>2016-04-01T03:01:03Z</dc:date>
    </item>
    <item>
      <title>Re: "Test Connection" for ranger kms repository fails</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/quot-Test-Connection-quot-for-ranger-kms-repository-fails/m-p/151605#M24162</link>
      <description>&lt;P&gt;&lt;A rel="user" href="https://community.cloudera.com/users/47/vperiasamy.html" nodeid="47"&gt;@vperiasamy&lt;/A&gt; the issue is resolved. I just took solution from &lt;A rel="user" href="https://community.cloudera.com/users/740/vrathor.html" nodeid="740"&gt;@Vipin Rathor&lt;/A&gt; before checking you comment &lt;span class="lia-unicode-emoji" title=":winking_face_with_tongue:"&gt;😜&lt;/span&gt;&lt;/P&gt;&lt;P&gt;But it helped. Thanks for reply.&lt;/P&gt;</description>
      <pubDate>Fri, 01 Apr 2016 18:30:12 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/quot-Test-Connection-quot-for-ranger-kms-repository-fails/m-p/151605#M24162</guid>
      <dc:creator>sshimpi</dc:creator>
      <dc:date>2016-04-01T18:30:12Z</dc:date>
    </item>
    <item>
      <title>Re: "Test Connection" for ranger kms repository fails</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/quot-Test-Connection-quot-for-ranger-kms-repository-fails/m-p/151606#M24163</link>
      <description>&lt;P&gt;Hi Vipin,&lt;/P&gt;&lt;P&gt;In my case also, user name coming as only 'keyadmin" instead of &lt;A href="mailto:keyadmin@realm"&gt;keyadmin@realm&lt;/A&gt; but I am giving username as&lt;/P&gt;&lt;P&gt;&lt;A href="mailto:keyadmin@realm"&gt;keyadmin@realm&lt;/A&gt; in UI:-&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;UNAUTHENTICATED RemoteHost:127.0.0.1 Method:GET &lt;A href="http://hostname:9292/kms/v1/keys/names?doAs=keyadmin"&gt;URL:http://hostname:9292/kms/v1/keys/names?doAs=keyadmin&lt;/A&gt; ErrorMsg:'Authentication required'.&lt;/P&gt;&lt;P&gt;which property should I change for this?&lt;/P&gt;&lt;P&gt;please help.&lt;/P&gt;&lt;P&gt;Thanks in advance&lt;/P&gt;</description>
      <pubDate>Tue, 24 May 2016 03:21:54 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/quot-Test-Connection-quot-for-ranger-kms-repository-fails/m-p/151606#M24163</guid>
      <dc:creator>trip_ankit87</dc:creator>
      <dc:date>2016-05-24T03:21:54Z</dc:date>
    </item>
    <item>
      <title>Re: "Test Connection" for ranger kms repository fails</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/quot-Test-Connection-quot-for-ranger-kms-repository-fails/m-p/151607#M24164</link>
      <description>&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hi Vipin,&lt;/P&gt;&lt;P&gt;In my case also, user name coming as only 'keyadmin" instead of &lt;A href="mailto:keyadmin@realm"&gt;keyadmin@realm&lt;/A&gt; but I am giving username as&lt;/P&gt;&lt;P&gt;&lt;A href="mailto:keyadmin@realm"&gt;keyadmin@realm&lt;/A&gt; in UI:-&lt;/P&gt;&lt;P&gt;UNAUTHENTICATED RemoteHost:127.0.0.1 Method:GET &lt;A href="http://hostname:9292/kms/v1/keys/names?doAs=keyadmin"&gt;URL:http://hostname:9292/kms/v1/keys/names?doAs=keyadmin&lt;/A&gt; ErrorMsg:'Authentication required'.&lt;/P&gt;&lt;P&gt;which property should I change for this?&lt;/P&gt;&lt;P&gt;please help.&lt;/P&gt;&lt;P&gt;Thanks in advance&lt;/P&gt;</description>
      <pubDate>Tue, 24 May 2016 05:58:34 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/quot-Test-Connection-quot-for-ranger-kms-repository-fails/m-p/151607#M24164</guid>
      <dc:creator>trip_ankit87</dc:creator>
      <dc:date>2016-05-24T05:58:34Z</dc:date>
    </item>
    <item>
      <title>Re: "Test Connection" for ranger kms repository fails</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/quot-Test-Connection-quot-for-ranger-kms-repository-fails/m-p/151608#M24165</link>
      <description>&lt;P&gt;&lt;A rel="user" href="https://community.cloudera.com/users/740/vrathor.html" nodeid="740"&gt;@Vipin Rathor&lt;/A&gt; &lt;/P&gt;&lt;P&gt;Hi Vipin,&lt;/P&gt;&lt;P&gt;I am having the same issue, the ranger logs show "returning null list"&lt;/P&gt;&lt;P&gt;I am able to login into Ranger as keyadmin / password (as created in AD), I can kinit as keyadmin&lt;/P&gt;&lt;P&gt;I am not seeing the user in Ranger user tab, however can see the user in usersync log&lt;/P&gt;&lt;P&gt;2016-08-19 03:38:10,633 [timed-executor-pool-0] DEBUG apache.ranger.services.kms.client.KMSClient (KMSClient.java:312) - Getting KmsClient for datasource: hubhdpdevcluster01_kms
2016-08-19 03:38:10,633 [timed-executor-pool-0] DEBUG apache.ranger.services.kms.client.KMSClient (KMSClient.java:313) - configMap: {password=*****, provider=kms://http@hadooplinux.xxx.com:9292/kms, username=keyadmin@HADOOPDOM.COM}
2016-08-19 03:38:10,633 [timed-executor-pool-0] DEBUG apache.ranger.services.kms.client.KMSClient (KMSClient.java:73) - Kms Client is build with url [kms://http@hadooplinux.xxx.com:9292/kms] user: [keyadmin@HADOOPDOM.COM]
2016-08-19 03:38:10,633 [timed-executor-pool-0] DEBUG apache.ranger.services.kms.client.KMSClient (KMSClient.java:144) - Getting Kms Key list for keyNameMatching :
2016-08-19 03:38:10,994 [timed-executor-pool-0] DEBUG apache.ranger.services.kms.client.KMSClient (KMSClient.java:181) - getKeyList():calling &lt;A href="http://hadooplinux.xxx.com:9292/kms/v1/keys/names?doAs=keyadmin"&gt;http://hadooplinux.xxx.com:9292/kms/v1/keys/names?doAs=keyadmin&lt;/A&gt;
2016-08-19 03:38:10,994 [timed-executor-pool-0] DEBUG apache.ranger.services.kms.client.KMSClient (KMSClient.java:185) - getKeyList():response.getStatus()= 401
2016-08-19 03:38:10,994 [timed-executor-pool-0] INFO  apache.ranger.services.kms.client.KMSClient (KMSClient.java:214) - getKeyList():response.getStatus()= 401 for URL &lt;A href="http://hadooplinux.xxx.com:9292/kms/v1/keys/names?doAs=keyadmin,"&gt;http://hadooplinux.xxx.com:9292/kms/v1/keys/names?doAs=keyadmin&lt;/A&gt; so returning null list
2016-08-19 03:38:10,995 [timed-executor-pool-0] ERROR apache.ranger.services.kms.client.KMSResourceMgr (KMSResourceMgr.java:43) - &amp;lt;== KMSResourceMgr.validateConfig Error: org.apache.ranger.plugin.client.HadoopException: &lt;/P&gt;&lt;P&gt;Is there some other settings for AD-KDC in Ranger KMS?&lt;/P&gt;&lt;P&gt;Ranger KMS was setup and the cluster was kerbersized later. Does it have to be setup after kerberzing?&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Avijeet&lt;/P&gt;</description>
      <pubDate>Fri, 19 Aug 2016 14:32:33 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/quot-Test-Connection-quot-for-ranger-kms-repository-fails/m-p/151608#M24165</guid>
      <dc:creator>avijeetd</dc:creator>
      <dc:date>2016-08-19T14:32:33Z</dc:date>
    </item>
    <item>
      <title>Re: "Test Connection" for ranger kms repository fails</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/quot-Test-Connection-quot-for-ranger-kms-repository-fails/m-p/277945#M24166</link>
      <description>&lt;P&gt;This links are not working now.&lt;/P&gt;</description>
      <pubDate>Fri, 20 Sep 2019 12:06:26 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/quot-Test-Connection-quot-for-ranger-kms-repository-fails/m-p/277945#M24166</guid>
      <dc:creator>arturbrandys</dc:creator>
      <dc:date>2019-09-20T12:06:26Z</dc:date>
    </item>
    <item>
      <title>Re: "Test Connection" for ranger kms repository fails</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/quot-Test-Connection-quot-for-ranger-kms-repository-fails/m-p/277948#M24167</link>
      <description>&lt;P&gt;&lt;SPAN&gt;I found the &lt;A href="https://docs.cloudera.com/HDPDocuments/HDP2/HDP-2.4.0/bk_Security_Guide/content/ch_ranger-kms-admin-guide.html" target="_blank" rel="noopener"&gt;Ranger KMS Admin Guide for HDP 2.4.0&lt;/A&gt;, hopefully this is what you are looking for.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 20 Sep 2019 13:28:31 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/quot-Test-Connection-quot-for-ranger-kms-repository-fails/m-p/277948#M24167</guid>
      <dc:creator>cjervis</dc:creator>
      <dc:date>2019-09-20T13:28:31Z</dc:date>
    </item>
  </channel>
</rss>

