<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>question Re: Ambari cluster with Kerberos - wrong principal expected in Archives of Support Questions (Read Only)</title>
    <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Ambari-cluster-with-Kerberos-wrong-principal-expected/m-p/121662#M34317</link>
    <description>&lt;P&gt;The hostname resolution works fine. However the issue is very likely in reverse lookups for IP addresses.&lt;/P&gt;</description>
    <pubDate>Mon, 11 Jul 2016 13:22:40 GMT</pubDate>
    <dc:creator>milan_sladky</dc:creator>
    <dc:date>2016-07-11T13:22:40Z</dc:date>
    <item>
      <title>Ambari cluster with Kerberos - wrong principal expected</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Ambari-cluster-with-Kerberos-wrong-principal-expected/m-p/121660#M34315</link>
      <description>&lt;P&gt;I have successfully enabled Kerberos for Ambari managed cluster. I have used the Wizard to generate the principals and everything. However the datanodes do not connect to namenodes. The reason is following:&lt;/P&gt;&lt;PRE&gt;2016-07-08 16:10:54,753 INFO ipc.Server (Server.java:doRead(891)) - Socket Reader #1 for port 8020: readAndProcess from client 172.30.52.137 threw exception [org.apache.hadoop.security.authorize.AuthorizationException: User dn/hadoop-poc2-02.int.na.prodxxx.com@HADOOPXXX.COM (auth:KERBEROS) is not authorized for protocol interface org.apache.hadoop.hdfs.server.protocol.DatanodeProtocol, expected client Kerberos principal is dn/172.30.52.137@HADOOPXXX.COM]&lt;/PRE&gt;&lt;P&gt;They expect principals containing IP address instead of hostnames... I have checked the keytabs and it is generated properly:&lt;/P&gt;&lt;PRE&gt;Keytab name: FILE:dn.service.keytab
KVNO Principal
---- --------------------------------------------------------------------------
1 dn/hadoop-poc2-02.int.na.prodxxx.com@HADOOPXXX.COM
1 dn/hadoop-poc2-02.int.na.prodxxx.com@HADOOPXXX.COM
1 dn/hadoop-poc2-02.int.na.prodxxx.com@HADOOPXXX.COM
1 dn/hadoop-poc2-02.int.na.prodxxx.com@HADOOPXXX.COM
1 dn/hadoop-poc2-02.int.na.prodxxx.com@HADOOPXXX.COM
&lt;/PRE&gt;&lt;P&gt;Any hints?&lt;/P&gt;</description>
      <pubDate>Sun, 10 Jul 2016 22:22:39 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Ambari-cluster-with-Kerberos-wrong-principal-expected/m-p/121660#M34315</guid>
      <dc:creator>milan_sladky</dc:creator>
      <dc:date>2016-07-10T22:22:39Z</dc:date>
    </item>
    <item>
      <title>Re: Ambari cluster with Kerberos - wrong principal expected</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Ambari-cluster-with-Kerberos-wrong-principal-expected/m-p/121661#M34316</link>
      <description>&lt;P&gt;@&lt;A href="https://community.hortonworks.com/users/10804/milansladky.html"&gt;Milan Sladky&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Are you sure that the hostname resolution is correct at your end? like `hostname -f`  or "/etc/hosts" file ...etc.&lt;/P&gt;&lt;P&gt;It looks suspect because the  Error indicates IPAddress "expected client Kerberos principal is dn/&lt;STRONG&gt;172.30.52.137&lt;/STRONG&gt;@HADOOPXXX.COM]"&lt;/P&gt;&lt;P&gt;Where as your keytabs looks more valid with the hostname "dn/&lt;STRONG&gt;hadoop-poc2-02.int.na.prodxxx.com&lt;/STRONG&gt;@HADOOPXXX.COM" &lt;/P&gt;</description>
      <pubDate>Sun, 10 Jul 2016 23:38:06 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Ambari-cluster-with-Kerberos-wrong-principal-expected/m-p/121661#M34316</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2016-07-10T23:38:06Z</dc:date>
    </item>
    <item>
      <title>Re: Ambari cluster with Kerberos - wrong principal expected</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Ambari-cluster-with-Kerberos-wrong-principal-expected/m-p/121662#M34317</link>
      <description>&lt;P&gt;The hostname resolution works fine. However the issue is very likely in reverse lookups for IP addresses.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Jul 2016 13:22:40 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Ambari-cluster-with-Kerberos-wrong-principal-expected/m-p/121662#M34317</guid>
      <dc:creator>milan_sladky</dc:creator>
      <dc:date>2016-07-11T13:22:40Z</dc:date>
    </item>
    <item>
      <title>Re: Ambari cluster with Kerberos - wrong principal expected</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Ambari-cluster-with-Kerberos-wrong-principal-expected/m-p/121663#M34318</link>
      <description>&lt;P&gt;So the issue was very likely caused by the fact that reverse lookup for IP address is performed. We do not have PTR records and /etc/hosts contains info about current host only. I have added records for all hosts of the cluster to /etc/hosts and it works now.&lt;/P&gt;&lt;P&gt;Please note that I have dfs.namenode.datanode.registration.&lt;STRONG&gt;ip-hostname-check &lt;/STRONG&gt;set to &lt;STRONG&gt;false &lt;/STRONG&gt;in custom hdfs-site.xml.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Jul 2016 13:29:04 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Ambari-cluster-with-Kerberos-wrong-principal-expected/m-p/121663#M34318</guid>
      <dc:creator>milan_sladky</dc:creator>
      <dc:date>2016-07-11T13:29:04Z</dc:date>
    </item>
  </channel>
</rss>

