<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>question LDAPS connection failure while using Ambari Kerberos wizard in Archives of Support Questions (Read Only)</title>
    <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/LDAPS-connection-failure-while-using-Ambari-Kerberos-wizard/m-p/162670#M24765</link>
    <description>&lt;P&gt;We are having trouble using the Kerberos wizard in Ambari
when testing the connection to our AD domain controllers over LDAPS.  They sit behind a load-balancer which is
secured using a third-party trusted certificate.  Originally we thought that the certificate was
at issue as testing with an openssl client was producing a “self-signed”
warning.  This was corrected though when
we updated the underlying OS software and it presumably updated the root
certificate.&lt;/P&gt;&lt;P&gt;The errors we receive in the log are the following:&lt;/P&gt;&lt;PRE&gt;ERROR [ambari-kdc-verify] KdcConnection:380 - Authentication failed
ERROR [ambari-kdc-verify] KdcConnection:380 - Authentication failed
WARN [qtp-ambari-client-23]KdcServerConnectionVerification:167 - Failed to connect to the KDC server at &amp;lt;servername&amp;gt;:636 over TCP 
WARN [qtp-ambari-client-23] KdcServerConnectionVerification:197 - Timeout occurred while attempting to communicate with KDC server at &amp;lt;servername&amp;gt;:636 over UDP 
ERROR[qtp-ambari-client-23] KdcServerConnectionVerification:113 - Failed to connect to
the KDC at &amp;lt;servername&amp;gt;:636 using either TCP or UDP&lt;/PRE&gt;&lt;P&gt;We have tested the port on the load balancer using netcat/openssl
and ran a search using ldapsearch, they were all able to connect to that port
and ldapsearch returned results.  Using
the test option in the wizard also works when the connection is to a standard
domain controller over port 389.  We’ve
also been able to setup LDAPS authentication for the Ambari web console to the
same load balancer address which also works fine.&lt;/P&gt;&lt;P&gt;Any insights into what might be wrong or should we move forward
with manual creation/distribution of keytabs and principals?&lt;/P&gt;</description>
    <pubDate>Fri, 16 Sep 2022 10:12:53 GMT</pubDate>
    <dc:creator>alan9270</dc:creator>
    <dc:date>2022-09-16T10:12:53Z</dc:date>
    <item>
      <title>LDAPS connection failure while using Ambari Kerberos wizard</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/LDAPS-connection-failure-while-using-Ambari-Kerberos-wizard/m-p/162670#M24765</link>
      <description>&lt;P&gt;We are having trouble using the Kerberos wizard in Ambari
when testing the connection to our AD domain controllers over LDAPS.  They sit behind a load-balancer which is
secured using a third-party trusted certificate.  Originally we thought that the certificate was
at issue as testing with an openssl client was producing a “self-signed”
warning.  This was corrected though when
we updated the underlying OS software and it presumably updated the root
certificate.&lt;/P&gt;&lt;P&gt;The errors we receive in the log are the following:&lt;/P&gt;&lt;PRE&gt;ERROR [ambari-kdc-verify] KdcConnection:380 - Authentication failed
ERROR [ambari-kdc-verify] KdcConnection:380 - Authentication failed
WARN [qtp-ambari-client-23]KdcServerConnectionVerification:167 - Failed to connect to the KDC server at &amp;lt;servername&amp;gt;:636 over TCP 
WARN [qtp-ambari-client-23] KdcServerConnectionVerification:197 - Timeout occurred while attempting to communicate with KDC server at &amp;lt;servername&amp;gt;:636 over UDP 
ERROR[qtp-ambari-client-23] KdcServerConnectionVerification:113 - Failed to connect to
the KDC at &amp;lt;servername&amp;gt;:636 using either TCP or UDP&lt;/PRE&gt;&lt;P&gt;We have tested the port on the load balancer using netcat/openssl
and ran a search using ldapsearch, they were all able to connect to that port
and ldapsearch returned results.  Using
the test option in the wizard also works when the connection is to a standard
domain controller over port 389.  We’ve
also been able to setup LDAPS authentication for the Ambari web console to the
same load balancer address which also works fine.&lt;/P&gt;&lt;P&gt;Any insights into what might be wrong or should we move forward
with manual creation/distribution of keytabs and principals?&lt;/P&gt;</description>
      <pubDate>Fri, 16 Sep 2022 10:12:53 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/LDAPS-connection-failure-while-using-Ambari-Kerberos-wizard/m-p/162670#M24765</guid>
      <dc:creator>alan9270</dc:creator>
      <dc:date>2022-09-16T10:12:53Z</dc:date>
    </item>
    <item>
      <title>Re: LDAPS connection failure while using Ambari Kerberos wizard</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/LDAPS-connection-failure-while-using-Ambari-Kerberos-wizard/m-p/162671#M24766</link>
      <description>&lt;A rel="user" href="https://community.cloudera.com/users/4486/alan9270.html" nodeid="4486"&gt;@Alan Watt&lt;/A&gt;&lt;P&gt;The KDC verification process does not use the LDAP interface. It uses the KDC interface. So the port should be 88 not 636.  This means that that in the KDC host field you entered in the LDAP details rather than the KDC admin details, thus the failure. &lt;/P&gt;&lt;P&gt;Try setting the KDC host and KAdmin hosts to &amp;lt;servername&amp;gt;:88 and try again.&lt;/P&gt;</description>
      <pubDate>Fri, 08 Apr 2016 23:37:05 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/LDAPS-connection-failure-while-using-Ambari-Kerberos-wizard/m-p/162671#M24766</guid>
      <dc:creator>rlevas</dc:creator>
      <dc:date>2016-04-08T23:37:05Z</dc:date>
    </item>
    <item>
      <title>Re: LDAPS connection failure while using Ambari Kerberos wizard</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/LDAPS-connection-failure-while-using-Ambari-Kerberos-wizard/m-p/162672#M24767</link>
      <description>&lt;P&gt;Many thanks, I've changed the port and the connection test is passing.&lt;/P&gt;</description>
      <pubDate>Sat, 09 Apr 2016 00:38:59 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/LDAPS-connection-failure-while-using-Ambari-Kerberos-wizard/m-p/162672#M24767</guid>
      <dc:creator>alan9270</dc:creator>
      <dc:date>2016-04-09T00:38:59Z</dc:date>
    </item>
  </channel>
</rss>

