<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>question Re: AD Kerberized cluster Hive connection string in Archives of Support Questions (Read Only)</title>
    <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/AD-Kerberized-cluster-Hive-connection-string/m-p/165545#M45336</link>
    <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;The Hive principal is not a headless principal , ie the hive principal is dedicated to the HiveServer2 Server . &lt;/P&gt;&lt;P&gt;So the Principal name always pooints to the Hiveserver2 , which in your case is &lt;/P&gt;&lt;P&gt;qwang-hdp2. So if you are able to login using&lt;/P&gt;&lt;PRE&gt;beeline -u "jdbc:hive2://qwang-hdp2:10000/default;principal=hive/qwang-hdp2@REALM.NAME"


Then you are good. &lt;/PRE&gt;</description>
    <pubDate>Tue, 08 Nov 2016 06:11:01 GMT</pubDate>
    <dc:creator>pbalasundaram</dc:creator>
    <dc:date>2016-11-08T06:11:01Z</dc:date>
    <item>
      <title>AD Kerberized cluster Hive connection string</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/AD-Kerberized-cluster-Hive-connection-string/m-p/165544#M45335</link>
      <description>&lt;P&gt;I have some question about the hive jdbc connection string for AD Kerberized cluster.&lt;/P&gt;&lt;P&gt;Hive server: qwang-hdp2&lt;/P&gt;&lt;P&gt;Hive clients: qwang-hdp0, qwang-hdp2, qwang-hdp4&lt;/P&gt;&lt;P&gt;I could connect using beeline using following conn string&lt;/P&gt;&lt;PRE&gt;beeline -u "jdbc:hive2://qwang-hdp2:10000/default;principal=hive/qwang-hdp2@REALM.NAME"
&lt;/PRE&gt;&lt;P&gt;But not this conn string&lt;/P&gt;&lt;PRE&gt;beeline -u "jdbc:hive2://qwang-hdp2:10000/default;principal=hive/qwang-hdp0@REALM.NAME"&lt;/PRE&gt;&lt;P&gt;The only difference is the hive principal, got the following error &lt;/P&gt;&lt;PRE&gt;Error: Could not open client transport with JDBC Uri: jdbc:hive2://qwang-hdp2:10000/default;principal=hive/qwang-hdp0@REALM.NAME: Peer indicated failure: GSS initiate failed (state=08S01,code=0)&lt;/PRE&gt;&lt;P&gt;Root is under hadoopadmin principal&lt;/P&gt;&lt;PRE&gt;[root@qwang-hdp0 ~]# klist
Ticket cache: FILE:/tmp/krb5cc_0
Default principal: hadoopadmin@REALM.NAME
&lt;/PRE&gt;&lt;P&gt;Also keytabs are available&lt;/P&gt;&lt;PRE&gt;[root@qwang-hdp0 ~]# klist -kt /etc/security/keytabs/hive.service.keytab
Keytab name: FILE:/etc/security/keytabs/hive.service.keytab
KVNO Timestamp           Principal
---- ------------------- ------------------------------------------------------
   0 11/02/2016 20:35:50 hive/qwang-hdp0@REALM.NAME
   0 11/02/2016 20:35:50 hive/qwang-hdp0@REALM.NAME
   0 11/02/2016 20:35:50 hive/qwang-hdp0@REALM.NAME
   0 11/02/2016 20:35:50 hive/qwang-hdp0@REALM.NAME
   0 11/02/2016 20:35:50 hive/qwang-hdp0@REALM.NAME

&lt;/PRE&gt;&lt;P&gt;Could you suggest any way to trouble shoot why this is happening?&lt;/P&gt;</description>
      <pubDate>Sat, 05 Nov 2016 00:16:01 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/AD-Kerberized-cluster-Hive-connection-string/m-p/165544#M45335</guid>
      <dc:creator>qiwang</dc:creator>
      <dc:date>2016-11-05T00:16:01Z</dc:date>
    </item>
    <item>
      <title>Re: AD Kerberized cluster Hive connection string</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/AD-Kerberized-cluster-Hive-connection-string/m-p/165545#M45336</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;The Hive principal is not a headless principal , ie the hive principal is dedicated to the HiveServer2 Server . &lt;/P&gt;&lt;P&gt;So the Principal name always pooints to the Hiveserver2 , which in your case is &lt;/P&gt;&lt;P&gt;qwang-hdp2. So if you are able to login using&lt;/P&gt;&lt;PRE&gt;beeline -u "jdbc:hive2://qwang-hdp2:10000/default;principal=hive/qwang-hdp2@REALM.NAME"


Then you are good. &lt;/PRE&gt;</description>
      <pubDate>Tue, 08 Nov 2016 06:11:01 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/AD-Kerberized-cluster-Hive-connection-string/m-p/165545#M45336</guid>
      <dc:creator>pbalasundaram</dc:creator>
      <dc:date>2016-11-08T06:11:01Z</dc:date>
    </item>
  </channel>
</rss>

