<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>question Eable Kerberos via Cloudera Manager wizard failed in Archives of Support Questions (Read Only)</title>
    <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Eable-Kerberos-via-Cloudera-Manager-wizard-failed/m-p/48099#M47389</link>
    <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Our test environment has RedHat 6.x, Kerberos instllation went well but getting the following error when enable Kerberos via CM wizard&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;All of our services were green before enable the kerberos but now all the services are down with following error&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;"Role is missing Kerberos keytab. Please run the Generate Missing Credentials command on the Kerberos Credentials tab of the Administration -&amp;gt; Security page"&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I tried to generate missing credentials in security page. but it is failed with below error message. Pls help me to understand how to proceed further...&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;/usr/share/cmf/bin/gen_credentials.sh failed with exit code 1 and output of &amp;lt;&amp;lt;&lt;BR /&gt;+ export PATH=/usr/kerberos/bin:/usr/kerberos/sbin:/usr/lib/mit/sbin:/usr/sbin:/usr/lib/mit/bin:/usr/bin:/sbin:/usr/sbin:/bin:/usr/bin&lt;BR /&gt;+ PATH=/usr/kerberos/bin:/usr/kerberos/sbin:/usr/lib/mit/sbin:/usr/sbin:/usr/lib/mit/bin:/usr/bin:/sbin:/usr/sbin:/bin:/usr/bin&lt;BR /&gt;+ CMF_REALM=AWS.COM&lt;BR /&gt;+ KEYTAB_OUT=/var/run/cloudera-scm-server/cmf4310122296840901236.keytab&lt;BR /&gt;+ PRINC=oozie/&amp;lt;hostname&amp;gt;@AWS.COM&lt;BR /&gt;+ MAX_RENEW_LIFE=432000&lt;BR /&gt;+ KADMIN='kadmin -k -t /var/run/cloudera-scm-server/cmf8961661390083798972.keytab -p root@AWS.COM -r AWS.COM'&lt;BR /&gt;+ RENEW_ARG=&lt;BR /&gt;+ '[' 432000 -gt 0 ']'&lt;BR /&gt;+ RENEW_ARG='-maxrenewlife "432000 sec"'&lt;BR /&gt;+ '[' -z /var/run/cloudera-scm-server/krb51519941863236958532.conf ']'&lt;BR /&gt;+ echo 'Using custom config path '\''/var/run/cloudera-scm-server/krb51519941863236958532.conf'\'', contents below:'&lt;BR /&gt;+ cat /var/run/cloudera-scm-server/krb51519941863236958532.conf&lt;BR /&gt;+ kadmin -k -t /var/run/cloudera-scm-server/cmf8961661390083798972.keytab -p root@AWS.COM -r AWS.COM -q 'addprinc -maxrenewlife "432000 sec" -randkey oozie/&amp;lt;hostname&amp;gt;@AWS.COM'&lt;BR /&gt;WARNING: no policy specified for oozie/&amp;lt;hostname&amp;gt;@AWS.COM; defaulting to no policy&lt;BR /&gt;add_principal: Operation requires ``add'' privilege while creating "oozie/&amp;lt;hostname&amp;gt;@AWS.COM".&lt;BR /&gt;+ '[' 432000 -gt 0 ']'&lt;BR /&gt;++ kadmin -k -t /var/run/cloudera-scm-server/cmf8961661390083798972.keytab -p root@AWS.COM -r AWS.COM -q 'getprinc -terse oozie/&amp;lt;hostname&amp;gt;@AWS.COM'&lt;BR /&gt;++ tail -1&lt;BR /&gt;++ cut -f 12&lt;BR /&gt;get_principal: Operation requires ``get'' privilege while retrieving "oozie/&amp;lt;hostname&amp;gt;@AWS.COM".&lt;BR /&gt;+ RENEW_LIFETIME='Authenticating as principal root@AWS.COM with keytab /var/run/cloudera-scm-server/cmf8961661390083798972.keytab.'&lt;BR /&gt;+ '[' Authenticating as principal root@AWS.COM with keytab /var/run/cloudera-scm-server/cmf8961661390083798972.keytab. -eq 0 ']'&lt;BR /&gt;/usr/share/cmf/bin/gen_credentials.sh: line 35: [: too many arguments&lt;BR /&gt;+ kadmin -k -t /var/run/cloudera-scm-server/cmf8961661390083798972.keytab -p root@AWS.COM -r AWS.COM -q 'xst -k /var/run/cloudera-scm-server/cmf4310122296840901236.keytab oozie/&amp;lt;hostname&amp;gt;@AWS.COM'&lt;BR /&gt;kadmin: Operation requires ``change-password'' privilege while changing oozie/&amp;lt;hostname&amp;gt;@AWS.COM's key&lt;BR /&gt;+ chmod 600 /var/run/cloudera-scm-server/cmf4310122296840901236.keytab&lt;BR /&gt;chmod: cannot access `/var/run/cloudera-scm-server/cmf4310122296840901236.keytab': No such file or directory&lt;BR /&gt;&lt;BR /&gt;&amp;gt;&amp;gt;&lt;/PRE&gt;&lt;P&gt;kadmin.local&lt;/P&gt;&lt;PRE&gt;kadmin.local:  listprincs
cloudera-scm/admin@AWS.COM
cloudera-scm/&amp;lt;Master_Domain&amp;gt;@AWS.COM
cloudera-scm/&amp;lt;hostname&amp;gt;@AWS.COM
host/&amp;lt;Clienthost1_name&amp;gt;@AWS.COM
host/&amp;lt;Clienthost2_name&amp;gt;@AWS.COM
kadmin/admin@AWS.COM
kadmin/changepw@AWS.COM
kadmin/&amp;lt;Master_hostname&amp;gt;@AWS.COM
krbtgt/AWS.COM@AWS.COM
kumar@AWS.COM
oozie/&amp;lt;Master_Domain&amp;gt;@AWS.COM
oozie/&amp;lt;Master_hostname&amp;gt;@AWS.COM
root/admin@AWS.COM
root@AWS.COM&lt;/PRE&gt;&lt;P&gt;Note: all the services are belongs to master host&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Kumar&lt;/P&gt;</description>
    <pubDate>Tue, 29 Nov 2016 05:22:05 GMT</pubDate>
    <dc:creator>saranvisa</dc:creator>
    <dc:date>2016-11-29T05:22:05Z</dc:date>
    <item>
      <title>Eable Kerberos via Cloudera Manager wizard failed</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Eable-Kerberos-via-Cloudera-Manager-wizard-failed/m-p/48099#M47389</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Our test environment has RedHat 6.x, Kerberos instllation went well but getting the following error when enable Kerberos via CM wizard&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;All of our services were green before enable the kerberos but now all the services are down with following error&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;"Role is missing Kerberos keytab. Please run the Generate Missing Credentials command on the Kerberos Credentials tab of the Administration -&amp;gt; Security page"&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I tried to generate missing credentials in security page. but it is failed with below error message. Pls help me to understand how to proceed further...&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;/usr/share/cmf/bin/gen_credentials.sh failed with exit code 1 and output of &amp;lt;&amp;lt;&lt;BR /&gt;+ export PATH=/usr/kerberos/bin:/usr/kerberos/sbin:/usr/lib/mit/sbin:/usr/sbin:/usr/lib/mit/bin:/usr/bin:/sbin:/usr/sbin:/bin:/usr/bin&lt;BR /&gt;+ PATH=/usr/kerberos/bin:/usr/kerberos/sbin:/usr/lib/mit/sbin:/usr/sbin:/usr/lib/mit/bin:/usr/bin:/sbin:/usr/sbin:/bin:/usr/bin&lt;BR /&gt;+ CMF_REALM=AWS.COM&lt;BR /&gt;+ KEYTAB_OUT=/var/run/cloudera-scm-server/cmf4310122296840901236.keytab&lt;BR /&gt;+ PRINC=oozie/&amp;lt;hostname&amp;gt;@AWS.COM&lt;BR /&gt;+ MAX_RENEW_LIFE=432000&lt;BR /&gt;+ KADMIN='kadmin -k -t /var/run/cloudera-scm-server/cmf8961661390083798972.keytab -p root@AWS.COM -r AWS.COM'&lt;BR /&gt;+ RENEW_ARG=&lt;BR /&gt;+ '[' 432000 -gt 0 ']'&lt;BR /&gt;+ RENEW_ARG='-maxrenewlife "432000 sec"'&lt;BR /&gt;+ '[' -z /var/run/cloudera-scm-server/krb51519941863236958532.conf ']'&lt;BR /&gt;+ echo 'Using custom config path '\''/var/run/cloudera-scm-server/krb51519941863236958532.conf'\'', contents below:'&lt;BR /&gt;+ cat /var/run/cloudera-scm-server/krb51519941863236958532.conf&lt;BR /&gt;+ kadmin -k -t /var/run/cloudera-scm-server/cmf8961661390083798972.keytab -p root@AWS.COM -r AWS.COM -q 'addprinc -maxrenewlife "432000 sec" -randkey oozie/&amp;lt;hostname&amp;gt;@AWS.COM'&lt;BR /&gt;WARNING: no policy specified for oozie/&amp;lt;hostname&amp;gt;@AWS.COM; defaulting to no policy&lt;BR /&gt;add_principal: Operation requires ``add'' privilege while creating "oozie/&amp;lt;hostname&amp;gt;@AWS.COM".&lt;BR /&gt;+ '[' 432000 -gt 0 ']'&lt;BR /&gt;++ kadmin -k -t /var/run/cloudera-scm-server/cmf8961661390083798972.keytab -p root@AWS.COM -r AWS.COM -q 'getprinc -terse oozie/&amp;lt;hostname&amp;gt;@AWS.COM'&lt;BR /&gt;++ tail -1&lt;BR /&gt;++ cut -f 12&lt;BR /&gt;get_principal: Operation requires ``get'' privilege while retrieving "oozie/&amp;lt;hostname&amp;gt;@AWS.COM".&lt;BR /&gt;+ RENEW_LIFETIME='Authenticating as principal root@AWS.COM with keytab /var/run/cloudera-scm-server/cmf8961661390083798972.keytab.'&lt;BR /&gt;+ '[' Authenticating as principal root@AWS.COM with keytab /var/run/cloudera-scm-server/cmf8961661390083798972.keytab. -eq 0 ']'&lt;BR /&gt;/usr/share/cmf/bin/gen_credentials.sh: line 35: [: too many arguments&lt;BR /&gt;+ kadmin -k -t /var/run/cloudera-scm-server/cmf8961661390083798972.keytab -p root@AWS.COM -r AWS.COM -q 'xst -k /var/run/cloudera-scm-server/cmf4310122296840901236.keytab oozie/&amp;lt;hostname&amp;gt;@AWS.COM'&lt;BR /&gt;kadmin: Operation requires ``change-password'' privilege while changing oozie/&amp;lt;hostname&amp;gt;@AWS.COM's key&lt;BR /&gt;+ chmod 600 /var/run/cloudera-scm-server/cmf4310122296840901236.keytab&lt;BR /&gt;chmod: cannot access `/var/run/cloudera-scm-server/cmf4310122296840901236.keytab': No such file or directory&lt;BR /&gt;&lt;BR /&gt;&amp;gt;&amp;gt;&lt;/PRE&gt;&lt;P&gt;kadmin.local&lt;/P&gt;&lt;PRE&gt;kadmin.local:  listprincs
cloudera-scm/admin@AWS.COM
cloudera-scm/&amp;lt;Master_Domain&amp;gt;@AWS.COM
cloudera-scm/&amp;lt;hostname&amp;gt;@AWS.COM
host/&amp;lt;Clienthost1_name&amp;gt;@AWS.COM
host/&amp;lt;Clienthost2_name&amp;gt;@AWS.COM
kadmin/admin@AWS.COM
kadmin/changepw@AWS.COM
kadmin/&amp;lt;Master_hostname&amp;gt;@AWS.COM
krbtgt/AWS.COM@AWS.COM
kumar@AWS.COM
oozie/&amp;lt;Master_Domain&amp;gt;@AWS.COM
oozie/&amp;lt;Master_hostname&amp;gt;@AWS.COM
root/admin@AWS.COM
root@AWS.COM&lt;/PRE&gt;&lt;P&gt;Note: all the services are belongs to master host&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Kumar&lt;/P&gt;</description>
      <pubDate>Tue, 29 Nov 2016 05:22:05 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Eable-Kerberos-via-Cloudera-Manager-wizard-failed/m-p/48099#M47389</guid>
      <dc:creator>saranvisa</dc:creator>
      <dc:date>2016-11-29T05:22:05Z</dc:date>
    </item>
    <item>
      <title>Re: Eable Kerberos via Cloudera Manager wizard failed</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Eable-Kerberos-via-Cloudera-Manager-wizard-failed/m-p/48100#M47390</link>
      <description>&lt;P&gt;Note: I don't find the keytab file in the below path. Is it causing the trouble?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;/var/run/cloudera-scm-server/cmf4310122296840901236.keytab&lt;/PRE&gt;</description>
      <pubDate>Tue, 29 Nov 2016 05:24:54 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Eable-Kerberos-via-Cloudera-Manager-wizard-failed/m-p/48100#M47390</guid>
      <dc:creator>saranvisa</dc:creator>
      <dc:date>2016-11-29T05:24:54Z</dc:date>
    </item>
    <item>
      <title>Re: Eable Kerberos via Cloudera Manager wizard failed</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Eable-Kerberos-via-Cloudera-Manager-wizard-failed/m-p/48529#M47391</link>
      <description>&lt;P&gt;Issue resolved...I made few mistakes and resolved one by one&lt;/P&gt;&lt;P&gt;1.&lt;BR /&gt;The below file is a temporary keytab which will be generated automatically everytime we try CM -&amp;gt; Administration -&amp;gt; Setting -&amp;gt; Import KDC Account Manager Credentials&lt;BR /&gt;This will be automatically removed after every attempt and will not be available for our manual reference. This is NOT an issue&lt;BR /&gt;/var/run/cloudera-scm-server/cmf4310122296840901236.keytab&lt;/P&gt;&lt;P&gt;2.&lt;BR /&gt;If you are planning to import KDC account using Wizard then no need to manually enter any service related principal&lt;BR /&gt;kadmin.local: listprincs&lt;BR /&gt;oozie/&amp;lt;Master_Domain&amp;gt;@AWS.COM&lt;BR /&gt;oozie/&amp;lt;Master_hostname&amp;gt;@AWS.COM&lt;/P&gt;&lt;P&gt;3.&lt;BR /&gt;# Cloudera Manager -&amp;gt; Administration -&amp;gt; Security -&amp;gt; Kerberos Credentials -&amp;gt; Configuration&lt;BR /&gt;a. Update REALM.COM&lt;BR /&gt;b. Update Host&lt;BR /&gt;c. Update Encryption Type&lt;/P&gt;&lt;P&gt;and few more corrections made and working fine&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Kumar&lt;/P&gt;</description>
      <pubDate>Wed, 14 Dec 2016 15:58:43 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Eable-Kerberos-via-Cloudera-Manager-wizard-failed/m-p/48529#M47391</guid>
      <dc:creator>saranvisa</dc:creator>
      <dc:date>2016-12-14T15:58:43Z</dc:date>
    </item>
    <item>
      <title>Re: Eable Kerberos via Cloudera Manager wizard failed</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Eable-Kerberos-via-Cloudera-Manager-wizard-failed/m-p/81099#M47392</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;this is maybe an old post but I'm struggling with the same problem and didn't wanted to open a new thread.&lt;/P&gt;&lt;P&gt;I'm working with CentOS 7.5 and added two new gateway hosts for StreamSets.&lt;/P&gt;&lt;P&gt;After I installed successfully StreamSets with the Parcel I created the principals for Kerberos with &lt;STRONG&gt;kadmin.local&lt;/STRONG&gt; for both hosts like this:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;add_principal sdc/hostname1.FQDN@MYCOMPANY.REALM&lt;/LI&gt;&lt;LI&gt;add_principal sdc/hostname2.FQDN@MYCOMPANY.REALM&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;After this step I wanted to create the missing Kerberos credentials over Cloudera Manager which fails.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm not sure with this line. Is this maybe the problem?&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;/usr/share/cmf/bin/gen_credentials.sh: line 35: [: too many arguments&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My full log file:&lt;/P&gt;&lt;PRE&gt;/usr/share/cmf/bin/gen_credentials.sh failed with exit code 1 and output of &amp;lt;&amp;lt;
+ export PATH=/usr/kerberos/bin:/usr/kerberos/sbin:/usr/lib/mit/sbin:/usr/sbin:/usr/lib/mit/bin:/usr/bin:/sbin:/usr/sbin:/bin:/usr/bin
+ PATH=/usr/kerberos/bin:/usr/kerberos/sbin:/usr/lib/mit/sbin:/usr/sbin:/usr/lib/mit/bin:/usr/bin:/sbin:/usr/sbin:/bin:/usr/bin
+ CMF_REALM=MYCOMPANY.REALM
+ KEYTAB_OUT=/var/run/cloudera-scm-server/cmf3411206514354101952.keytab
+ PRINC=sdc/hostname1.FQDN@MYCOMPANY.REALM
+ MAX_RENEW_LIFE=604800
+ KADMIN='kadmin -k -t /var/run/cloudera-scm-server/cmf5906055974897109624.keytab -p sdc/hostname2.FQDN@MYCOMPANY.REALM -r MYCOMPANY.REALM'
+ RENEW_ARG=
+ '[' 604800 -gt 0 ']'
+ RENEW_ARG='-maxrenewlife "604800 sec"'
+ '[' -z /var/run/cloudera-scm-server/krb57389542731171685362.conf ']'
+ echo 'Using custom config path '\''/var/run/cloudera-scm-server/krb57389542731171685362.conf'\'', contents below:'
+ cat /var/run/cloudera-scm-server/krb57389542731171685362.conf
+ kadmin -k -t /var/run/cloudera-scm-server/cmf5906055974897109624.keytab -p sdc/hostname2.FQDN@MYCOMPANY.REALM -r MYCOMPANY.REALM -q 'addprinc -maxrenewlife "604800 sec" -randkey sdc/hostname1.FQDN@MYCOMPANY.REALM'
WARNING: no policy specified for sdc/hostname1.FQDN@MYCOMPANY.REALM; defaulting to no policy
add_principal: Operation requires ``add'' privilege while creating "sdc/hostname1.FQDN@MYCOMPANY.REALM".
+ '[' 604800 -gt 0 ']'
++ kadmin -k -t /var/run/cloudera-scm-server/cmf5906055974897109624.keytab -p sdc/hostname2.FQDN@MYCOMPANY.REALM -r MYCOMPANY.REALM -q 'getprinc -terse sdc/hostname1.FQDN@MYCOMPANY.REALM'
++ tail -1
++ cut -f 12
get_principal: Operation requires ``get'' privilege while retrieving "sdc/hostname1.FQDN@MYCOMPANY.REALM".
+ RENEW_LIFETIME='Authenticating as principal sdc/hostname2.FQDN@MYCOMPANY.REALM with keytab /var/run/cloudera-scm-server/cmf5906055974897109624.keytab.'
+ '[' Authenticating as principal sdc/hostname2.FQDN@MYCOMPANY.REALM with keytab /var/run/cloudera-scm-server/cmf5906055974897109624.keytab. -eq 0 ']'
/usr/share/cmf/bin/gen_credentials.sh: line 35: [: too many arguments
+ kadmin -k -t /var/run/cloudera-scm-server/cmf5906055974897109624.keytab -p sdc/hostname2.FQDN@MYCOMPANY.REALM -r MYCOMPANY.REALM -q 'xst -k /var/run/cloudera-scm-server/cmf3411206514354101952.keytab sdc/hostname1.FQDN@MYCOMPANY.REALM'
kadmin: Operation requires ``change-password'' privilege while changing sdc/hostname1.FQDN@MYCOMPANY.REALM's key
+ chmod 600 /var/run/cloudera-scm-server/cmf3411206514354101952.keytab
chmod: cannot access ‘/var/run/cloudera-scm-server/cmf3411206514354101952.keytab’: No such file or directory

&amp;gt;&amp;gt;&lt;/PRE&gt;&lt;P&gt;Grateful for any help.&lt;/P&gt;</description>
      <pubDate>Sun, 14 Oct 2018 19:02:45 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Eable-Kerberos-via-Cloudera-Manager-wizard-failed/m-p/81099#M47392</guid>
      <dc:creator>Baris</dc:creator>
      <dc:date>2018-10-14T19:02:45Z</dc:date>
    </item>
    <item>
      <title>Re: Eable Kerberos via Cloudera Manager wizard failed</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Eable-Kerberos-via-Cloudera-Manager-wizard-failed/m-p/81117#M47393</link>
      <description>&lt;P&gt;EDIT:&lt;/P&gt;&lt;P&gt;I did a copy/paste mistake! Please ignore my full-log given in my post above.&lt;/P&gt;&lt;P&gt;Here is the correct Error-Log:&lt;/P&gt;&lt;PRE&gt;/usr/share/cmf/bin/gen_credentials.sh failed with exit code 1 and output of &amp;lt;&amp;lt;
+ export PATH=/usr/kerberos/bin:/usr/kerberos/sbin:/usr/lib/mit/sbin:/usr/sbin:/usr/lib/mit/bin:/usr/bin:/sbin:/usr/sbin:/bin:/usr/bin
+ PATH=/usr/kerberos/bin:/usr/kerberos/sbin:/usr/lib/mit/sbin:/usr/sbin:/usr/lib/mit/bin:/usr/bin:/sbin:/usr/sbin:/bin:/usr/bin
+ CMF_REALM=MYCOMPANY.REALM
+ KEYTAB_OUT=/var/run/cloudera-scm-server/cmf2548823212650177196.keytab
+ PRINC=sdc/hostname.FQDN@MYCOMPANY.REALM
+ MAX_RENEW_LIFE=604800
+ KADMIN='kadmin -k -t /var/run/cloudera-scm-server/cmf6838080336847771087.keytab -p admin/admin@MYCOMPANY.REALM -r MYCOMPANY.REALM'
+ RENEW_ARG=
+ '[' 604800 -gt 0 ']'
+ RENEW_ARG='-maxrenewlife "604800 sec"'
+ '[' -z /var/run/cloudera-scm-server/krb52847952611766397096.conf ']'
+ echo 'Using custom config path '\''/var/run/cloudera-scm-server/krb52847952611766397096.conf'\'', contents below:'
+ cat /var/run/cloudera-scm-server/krb52847952611766397096.conf
+ kadmin -k -t /var/run/cloudera-scm-server/cmf6838080336847771087.keytab -p admin/admin@MYCOMPANY.REALM -r MYCOMPANY.REALM -q 'addprinc -maxrenewlife "604800 sec" -randkey sdc/hostname.FQDN@MYCOMPANY.REALM'
WARNING: no policy specified for sdc/hostname.FQDN@MYCOMPANY.REALM; defaulting to no policy
add_principal: Operation requires ``add'' privilege while creating "sdc/hostname.FQDN@MYCOMPANY.REALM".
+ '[' 604800 -gt 0 ']'
++ kadmin -k -t /var/run/cloudera-scm-server/cmf6838080336847771087.keytab -p admin/admin@MYCOMPANY.REALM -r MYCOMPANY.REALM -q 'getprinc -terse sdc/hostname.FQDN@MYCOMPANY.REALM'
++ tail -1
++ cut -f 12
get_principal: Operation requires ``get'' privilege while retrieving "sdc/hostname.FQDN@MYCOMPANY.REALM".
+ RENEW_LIFETIME='Authenticating as principal admin/admin@MYCOMPANY.REALM with keytab /var/run/cloudera-scm-server/cmf6838080336847771087.keytab.'
+ '[' Authenticating as principal admin/admin@MYCOMPANY.REALM with keytab /var/run/cloudera-scm-server/cmf6838080336847771087.keytab. -eq 0 ']'
/usr/share/cmf/bin/gen_credentials.sh: line 35: [: too many arguments
+ kadmin -k -t /var/run/cloudera-scm-server/cmf6838080336847771087.keytab -p admin/admin@MYCOMPANY.REALM -r MYCOMPANY.REALM -q 'xst -k /var/run/cloudera-scm-server/cmf2548823212650177196.keytab sdc/hostname.FQDN@MYCOMPANY.REALM'
kadmin: Operation requires ``change-password'' privilege while changing sdc/hostname.FQDN@MYCOMPANY.REALM's key
+ chmod 600 /var/run/cloudera-scm-server/cmf2548823212650177196.keytab
chmod: cannot access ‘/var/run/cloudera-scm-server/cmf2548823212650177196.keytab’: No such file or directory

&amp;gt;&amp;gt;&lt;/PRE&gt;</description>
      <pubDate>Mon, 15 Oct 2018 15:59:38 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Eable-Kerberos-via-Cloudera-Manager-wizard-failed/m-p/81117#M47393</guid>
      <dc:creator>Baris</dc:creator>
      <dc:date>2018-10-15T15:59:38Z</dc:date>
    </item>
  </channel>
</rss>

