<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>question Re: Kerberos:Error occured in generating credentials in Archives of Support Questions (Read Only)</title>
    <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Kerberos-Error-occured-in-generating-credentials/m-p/21407#M3613</link>
    <description>&lt;P&gt;the latest 5.2 version of cloudera is used&lt;/P&gt;</description>
    <pubDate>Tue, 11 Nov 2014 19:12:25 GMT</pubDate>
    <dc:creator>HDFS</dc:creator>
    <dc:date>2014-11-11T19:12:25Z</dc:date>
    <item>
      <title>Kerberos:Error occured in generating credentials</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Kerberos-Error-occured-in-generating-credentials/m-p/21405#M3611</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I was enabling kerberos from cloudera manager.&lt;/P&gt;&lt;P&gt;Everything worked fine but when it tried to do the step of "generating Credentials" it gave me an error.&lt;/P&gt;&lt;P&gt;Please find the error.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any suggestions?&lt;/P&gt;&lt;P&gt;Waiting for the reply&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;/usr/share/cmf/bin/gen_credentials.sh failed with exit code 1 and output of &amp;lt;&amp;lt;
+ export PATH=/usr/kerberos/bin:/usr/kerberos/sbin:/usr/lib/mit/sbin:/usr/sbin:/sbin:/usr/sbin:/bin:/usr/bin
+ PATH=/usr/kerberos/bin:/usr/kerberos/sbin:/usr/lib/mit/sbin:/usr/sbin:/sbin:/usr/sbin:/bin:/usr/bin
+ CMF_REALM=JNJ.COM
+ KEYTAB_OUT=/var/run/cloudera-scm-server/cmf7829892990940630057.keytab
+ PRINC=impala/itsusmpl00509.jnj.com@JNJ.COM
+ MAX_RENEW_LIFE=432000
+ KADMIN='kadmin -k -t /var/run/cloudera-scm-server/cmf4619059661181081787.keytab -p cloudera-scm/admin@JNJ.COM -r JNJ.COM'
+ RENEW_ARG=
+ '[' 432000 -gt 0 ']'
+ RENEW_ARG='-maxrenewlife "432000 sec"'
+ kadmin -k -t /var/run/cloudera-scm-server/cmf4619059661181081787.keytab -p cloudera-scm/admin@JNJ.COM -r JNJ.COM -q 'addprinc -maxrenewlife "432000 sec" -randkey impala/itsusmpl00509.jnj.com@JNJ.COM'
WARNING: no policy specified for impala/itsusmpl00509.jnj.com@JNJ.COM; defaulting to no policy
add_principal: Operation requires ``add'' privilege while creating "impala/itsusmpl00509.jnj.com@JNJ.COM".
+ '[' 432000 -gt 0 ']'
++ kadmin -k -t /var/run/cloudera-scm-server/cmf4619059661181081787.keytab -p cloudera-scm/admin@JNJ.COM -r JNJ.COM -q 'getprinc -terse impala/itsusmpl00509.jnj.com@JNJ.COM'
++ tail -1
++ cut -f 12
get_principal: Operation requires ``get'' privilege while retrieving "impala/itsusmpl00509.jnj.com@JNJ.COM".
+ RENEW_LIFETIME='Authenticating as principal cloudera-scm/admin@JNJ.COM with keytab /var/run/cloudera-scm-server/cmf4619059661181081787.keytab.'
+ '[' Authenticating as principal cloudera-scm/admin@JNJ.COM with keytab /var/run/cloudera-scm-server/cmf4619059661181081787.keytab. -eq 0 ']'
/usr/share/cmf/bin/gen_credentials.sh: line 28: [: too many arguments
+ kadmin -k -t /var/run/cloudera-scm-server/cmf4619059661181081787.keytab -p cloudera-scm/admin@JNJ.COM -r JNJ.COM -q 'xst -k /var/run/cloudera-scm-server/cmf7829892990940630057.keytab impala/itsusmpl00509.jnj.com@JNJ.COM'
kadmin: Operation requires ``change-password'' privilege while changing impala/itsusmpl00509.jnj.com@JNJ.COM's key
+ chmod 600 /var/run/cloudera-scm-server/cmf7829892990940630057.keytab
chmod: cannot access `/var/run/cloudera-scm-server/cmf7829892990940630057.keytab': No such file or directory&lt;/PRE&gt;</description>
      <pubDate>Fri, 16 Sep 2022 09:12:24 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Kerberos-Error-occured-in-generating-credentials/m-p/21405#M3611</guid>
      <dc:creator>HDFS</dc:creator>
      <dc:date>2022-09-16T09:12:24Z</dc:date>
    </item>
    <item>
      <title>Re: Kerberos:Error occured in generating credentials</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Kerberos-Error-occured-in-generating-credentials/m-p/21406#M3612</link>
      <description>&lt;P&gt;What version of Cloudera Manager are you using in the example&amp;nbsp;you provided?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 11 Nov 2014 19:09:52 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Kerberos-Error-occured-in-generating-credentials/m-p/21406#M3612</guid>
      <dc:creator>Grizzly</dc:creator>
      <dc:date>2014-11-11T19:09:52Z</dc:date>
    </item>
    <item>
      <title>Re: Kerberos:Error occured in generating credentials</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Kerberos-Error-occured-in-generating-credentials/m-p/21407#M3613</link>
      <description>&lt;P&gt;the latest 5.2 version of cloudera is used&lt;/P&gt;</description>
      <pubDate>Tue, 11 Nov 2014 19:12:25 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Kerberos-Error-occured-in-generating-credentials/m-p/21407#M3613</guid>
      <dc:creator>HDFS</dc:creator>
      <dc:date>2014-11-11T19:12:25Z</dc:date>
    </item>
    <item>
      <title>Re: Kerberos:Error occured in generating credentials</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Kerberos-Error-occured-in-generating-credentials/m-p/21408#M3614</link>
      <description>&lt;P&gt;What KDC is in use? &amp;nbsp;What OS and Release Version is the KDC running on?&lt;/P&gt;</description>
      <pubDate>Tue, 11 Nov 2014 19:15:45 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Kerberos-Error-occured-in-generating-credentials/m-p/21408#M3614</guid>
      <dc:creator>Grizzly</dc:creator>
      <dc:date>2014-11-11T19:15:45Z</dc:date>
    </item>
    <item>
      <title>Re: Kerberos:Error occured in generating credentials</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Kerberos-Error-occured-in-generating-credentials/m-p/21409#M3615</link>
      <description>&lt;P&gt;Also, what is in your KDC's kadm5.acl file?&lt;/P&gt;</description>
      <pubDate>Tue, 11 Nov 2014 19:18:10 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Kerberos-Error-occured-in-generating-credentials/m-p/21409#M3615</guid>
      <dc:creator>Grizzly</dc:creator>
      <dc:date>2014-11-11T19:18:10Z</dc:date>
    </item>
    <item>
      <title>Re: Kerberos:Error occured in generating credentials</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Kerberos-Error-occured-in-generating-credentials/m-p/21412#M3616</link>
      <description>&lt;P&gt;Its KDC 5 running on rhel 6.3&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;and my kadm5.acl file has&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;admin@JNJ.COM&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 11 Nov 2014 19:37:08 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Kerberos-Error-occured-in-generating-credentials/m-p/21412#M3616</guid>
      <dc:creator>HDFS</dc:creator>
      <dc:date>2014-11-11T19:37:08Z</dc:date>
    </item>
    <item>
      <title>Re: Kerberos:Error occured in generating credentials</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Kerberos-Error-occured-in-generating-credentials/m-p/21414#M3617</link>
      <description>&lt;P&gt;so realize the reason there was a */admin@REALM in the kadm5.acl file before you changed it... &amp;nbsp;that generic entry was in there so that any principal that has a name that ends with /admin is granted administrative rights over the KDC database.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Your cloudera manager principal is named&amp;nbsp;cloudera-scm/admin@JNJ.COM, but your acl file restricts admin to ONLY a user named "admin@JNJ.COM"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;From the script output you gave, none of the commands are working through kadmin becase the CM server user has no rights.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Either update the kadm5.acl file to include&amp;nbsp;&lt;SPAN&gt;*/admin@&lt;SPAN&gt;JNJ.COM, or explicitly set and entry for the CM server&amp;nbsp;&lt;SPAN&gt;scm-server/admin@&lt;/SPAN&gt;&lt;SPAN&gt;JNJ.COM. &amp;nbsp;At that point you should be able to configure cluster principals through CM in the KDC.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;SPAN&gt;&lt;SPAN&gt;Todd&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 11 Nov 2014 20:07:46 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Kerberos-Error-occured-in-generating-credentials/m-p/21414#M3617</guid>
      <dc:creator>Grizzly</dc:creator>
      <dc:date>2014-11-11T20:07:46Z</dc:date>
    </item>
    <item>
      <title>Re: Kerberos:Error occured in generating credentials</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Kerberos-Error-occured-in-generating-credentials/m-p/21415#M3618</link>
      <description>&lt;P&gt;My kadm5.acl is like this :-&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;*/admin@JNJ.COM*&lt;BR /&gt;~&lt;BR /&gt;~&lt;BR /&gt;~&lt;BR /&gt;~&lt;BR /&gt;~&lt;BR /&gt;~&lt;BR /&gt;~&lt;BR /&gt;~&lt;BR /&gt;~&lt;BR /&gt;~&lt;BR /&gt;~&lt;BR /&gt;~&lt;BR /&gt;~&lt;BR /&gt;~&lt;BR /&gt;~&lt;BR /&gt;~&lt;BR /&gt;~&lt;BR /&gt;~&lt;BR /&gt;~&lt;BR /&gt;~&lt;BR /&gt;~&lt;BR /&gt;~&lt;BR /&gt;"/var/kerberos/krb5kdc/kadm5.acl" 1L, 18C&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So you are suggesting is to add cloudera-scm/admin@JNJ.COM too right?&lt;/P&gt;</description>
      <pubDate>Tue, 11 Nov 2014 20:15:05 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Kerberos-Error-occured-in-generating-credentials/m-p/21415#M3618</guid>
      <dc:creator>HDFS</dc:creator>
      <dc:date>2014-11-11T20:15:05Z</dc:date>
    </item>
    <item>
      <title>Re: Kerberos:Error occured in generating credentials</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Kerberos-Error-occured-in-generating-credentials/m-p/21417#M3619</link>
      <description>&lt;P&gt;You should not have to specifically add the CM principal, the */admin should handle it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;From what you pasted,&amp;nbsp;I think you have a space missing between your COM and the "*" at the end of the first line; &amp;nbsp;Mine looks like this:&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;[12:34 root@secsme-1 ~] &amp;gt; cat kadm5.acl&lt;BR /&gt;*/admin@COE.CLOUDERA.COM *&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 11 Nov 2014 20:36:00 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Kerberos-Error-occured-in-generating-credentials/m-p/21417#M3619</guid>
      <dc:creator>Grizzly</dc:creator>
      <dc:date>2014-11-11T20:36:00Z</dc:date>
    </item>
    <item>
      <title>Re: Kerberos:Error occured in generating credentials</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Kerberos-Error-occured-in-generating-credentials/m-p/21537#M3620</link>
      <description>&lt;P&gt;I was able to reolve it.&lt;/P&gt;&lt;P&gt;The space should not be there between COM and * in kadm5.acl&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks !! &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 13 Nov 2014 17:40:42 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Kerberos-Error-occured-in-generating-credentials/m-p/21537#M3620</guid>
      <dc:creator>HDFS</dc:creator>
      <dc:date>2014-11-13T17:40:42Z</dc:date>
    </item>
    <item>
      <title>Re: Kerberos:Error occured in generating credentials</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Kerberos-Error-occured-in-generating-credentials/m-p/21538#M3621</link>
      <description>&lt;P&gt;Just FYI, it should have a space&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A target="_blank" href="http://web.mit.edu/kerberos/krb5-devel/doc/admin/conf_files/kadm5_acl.html"&gt;http://web.mit.edu/kerberos/krb5-devel/doc/admin/conf_files/kadm5_acl.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 13 Nov 2014 17:43:41 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Kerberos-Error-occured-in-generating-credentials/m-p/21538#M3621</guid>
      <dc:creator>Grizzly</dc:creator>
      <dc:date>2014-11-13T17:43:41Z</dc:date>
    </item>
    <item>
      <title>Re: Kerberos:Error occured in generating credentials</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Kerberos-Error-occured-in-generating-credentials/m-p/21546#M3622</link>
      <description>&lt;P&gt;Yes ,It was a typo error, I meant the space should be there. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;*/admin@My-Realm.COM *&lt;/P&gt;</description>
      <pubDate>Thu, 13 Nov 2014 19:58:25 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Kerberos-Error-occured-in-generating-credentials/m-p/21546#M3622</guid>
      <dc:creator>HDFS</dc:creator>
      <dc:date>2014-11-13T19:58:25Z</dc:date>
    </item>
  </channel>
</rss>

