<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>question Re: Can CDH5.3 Sentry work without Kerberos? in Archives of Support Questions (Read Only)</title>
    <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Can-CDH5-3-Sentry-work-without-Kerberos/m-p/24734#M4974</link>
    <description>&lt;P&gt;Thanks I'll give it a try.&lt;/P&gt;</description>
    <pubDate>Tue, 17 Feb 2015 00:45:21 GMT</pubDate>
    <dc:creator>ty.n</dc:creator>
    <dc:date>2015-02-17T00:45:21Z</dc:date>
    <item>
      <title>Can CDH5.3 Sentry work without Kerberos?</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Can-CDH5-3-Sentry-work-without-Kerberos/m-p/24729#M4970</link>
      <description>&lt;P&gt;I am trying to evaluate Sentry in the CDH5.3 virtual machine provided by Cloudera. &amp;nbsp;Unfortunately I am having a lot of problems getting it to even work and I throught I'd check that my assumption that I can even get it to work is correct.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In this (&amp;nbsp;&lt;A target="_blank" href="http://www.cloudera.com/content/cloudera/en/documentation/core/latest/topics/cm_sg_sentry_service.html)"&gt;http://www.cloudera.com/content/cloudera/en/documentation/core/latest/topics/cm_sg_sentry_service.html&lt;/A&gt;&amp;nbsp;)&amp;nbsp;documentation the prereqisites say:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;CDH 5.1.x (or later) managed by Cloudera Manager 5.1.x (or later). See the&amp;nbsp;&lt;A target="_blank" href="http://www.cloudera.com/content/cloudera/en/documentation/core/latest/topics/cm_ag_upgrading_cm.html#cmig_topic_9"&gt;Cloudera Manager Administration Guide&lt;/A&gt;&amp;nbsp;and&amp;nbsp;&lt;A target="_blank" href="http://www.cloudera.com/content/cloudera/en/documentation/core/latest/topics/installation.html"&gt;Cloudera Installation and Upgrade&lt;/A&gt;&amp;nbsp;for instructions.&lt;/LI&gt;&lt;LI&gt;HiveServer2 and the Hive Metastore running with strong authentication. For HiveServer2, strong authentication is either Kerberos or LDAP. For the Hive Metastore, only Kerberos is considered strong authentication (to override, see&amp;nbsp;&lt;A target="_blank" href="http://www.cloudera.com/content/cloudera/en/documentation/core/latest/topics/sg_sentry_service_config.html#concept_wjm_qxm_vq_unique_1"&gt;Securing the Hive Metastore&lt;/A&gt;).&lt;/LI&gt;&lt;LI&gt;Impala 1.4.0 (or later) running with strong authentication. With Impala, either Kerberos or LDAP can be configured to achieve strong authentication.&lt;/LI&gt;&lt;LI&gt;Implement Kerberos authentication on your cluster. For instructions, see&amp;nbsp;&lt;A target="_blank" href="http://www.cloudera.com/content/cloudera/en/documentation/core/latest/topics/cm_sg_intro_kerb.html#xd_583c10bfdbd326ba--6eed2fb8-14349d04bee--76dd"&gt;Enabling Kerberos Authentication Using the Wizard&lt;/A&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;I don't have kerberos or LDAP (since I'm in the virtual machine) so I override the HiveServer2/Hive Metastore requirement for strong authentication.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The last prerequisite says I need to implement Kerberos authentication. &amp;nbsp;Is this only if I want Impala to work; or will it stop Sentry from working entirely.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Ty&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 16 Sep 2022 09:21:44 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Can-CDH5-3-Sentry-work-without-Kerberos/m-p/24729#M4970</guid>
      <dc:creator>ty.n</dc:creator>
      <dc:date>2022-09-16T09:21:44Z</dc:date>
    </item>
    <item>
      <title>Re: Can CDH5.3 Sentry work without Kerberos?</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Can-CDH5-3-Sentry-work-without-Kerberos/m-p/24731#M4971</link>
      <description>&lt;P&gt;Sentry is a service for strong authorization over Hadoop cluster, so that the cluster needs to be strongly authenticated using Kerberos or LDAP before you integrate Sentry.&lt;/P&gt;</description>
      <pubDate>Tue, 17 Feb 2015 00:10:25 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Can-CDH5-3-Sentry-work-without-Kerberos/m-p/24731#M4971</guid>
      <dc:creator>dice</dc:creator>
      <dc:date>2015-02-17T00:10:25Z</dc:date>
    </item>
    <item>
      <title>Re: Can CDH5.3 Sentry work without Kerberos?</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Can-CDH5-3-Sentry-work-without-Kerberos/m-p/24732#M4972</link>
      <description>&lt;P&gt;Just to be 100% sure are you saying that it is not possible to implement Sentry with the virtual machine alone since it does not have any kerberos functionality inbuilt?&lt;/P&gt;</description>
      <pubDate>Tue, 17 Feb 2015 00:12:57 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Can-CDH5-3-Sentry-work-without-Kerberos/m-p/24732#M4972</guid>
      <dc:creator>ty.n</dc:creator>
      <dc:date>2015-02-17T00:12:57Z</dc:date>
    </item>
    <item>
      <title>Re: Can CDH5.3 Sentry work without Kerberos?</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Can-CDH5-3-Sentry-work-without-Kerberos/m-p/24733#M4973</link>
      <description>&lt;P&gt;Kerberos (KDC) is not included with the VM, but you can easily configure KDC server by yourself in the VM.&lt;/P&gt;&lt;P&gt;I usually run krb-bootstrap for this kinds of test purpose: &lt;A target="_blank" href="https://github.com/daisukebe/krb-bootstrap."&gt;https://github.com/daisukebe/krb-bootstrap.&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 17 Feb 2015 00:41:08 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Can-CDH5-3-Sentry-work-without-Kerberos/m-p/24733#M4973</guid>
      <dc:creator>dice</dc:creator>
      <dc:date>2015-02-17T00:41:08Z</dc:date>
    </item>
    <item>
      <title>Re: Can CDH5.3 Sentry work without Kerberos?</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Can-CDH5-3-Sentry-work-without-Kerberos/m-p/24734#M4974</link>
      <description>&lt;P&gt;Thanks I'll give it a try.&lt;/P&gt;</description>
      <pubDate>Tue, 17 Feb 2015 00:45:21 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Can-CDH5-3-Sentry-work-without-Kerberos/m-p/24734#M4974</guid>
      <dc:creator>ty.n</dc:creator>
      <dc:date>2015-02-17T00:45:21Z</dc:date>
    </item>
    <item>
      <title>Re: Can CDH5.3 Sentry work without Kerberos?</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Can-CDH5-3-Sentry-work-without-Kerberos/m-p/24735#M4975</link>
      <description>You're welcome!&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Tue, 17 Feb 2015 01:00:44 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Can-CDH5-3-Sentry-work-without-Kerberos/m-p/24735#M4975</guid>
      <dc:creator>dice</dc:creator>
      <dc:date>2015-02-17T01:00:44Z</dc:date>
    </item>
    <item>
      <title>Re: Can CDH5.3 Sentry work without Kerberos?</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Can-CDH5-3-Sentry-work-without-Kerberos/m-p/24752#M4976</link>
      <description>&lt;P&gt;I'm afraid it's not smooth sailing on this one.&amp;nbsp; I found the github project here: &lt;A target="_blank" href="https://github.com/esammer/krb-bootstrap"&gt;https://github.com/esammer/krb-bootstrap&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It all seems to work ok.&amp;nbsp; I seem to get Kerberos and a realm (CLOUDERA) and a principal (cloudera-scm/admin).&amp;nbsp; After some searching I managed to set the password for cloudera-scm/admin usinf the command line tool kadmin.local&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Unfortunately when I get to step 5 (import KDC Account Manager Credentials) of the Coudera Manager kerberos setup wizard I get the following message.&amp;nbsp; I'm afraid I'm stuck again and could use some help if anyone knows how to get past this problem.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;/usr/share/cmf/bin/import_credentials.sh failed with exit code 1 and output of &amp;lt;&amp;lt;
+ export PATH=/usr/kerberos/bin:/usr/kerberos/sbin:/usr/lib/mit/sbin:/usr/sbin:/sbin:/usr/sbin:/bin:/usr/bin
+ PATH=/usr/kerberos/bin:/usr/kerberos/sbin:/usr/lib/mit/sbin:/usr/sbin:/sbin:/usr/sbin:/bin:/usr/bin
+ KEYTAB_OUT=/var/run/REDACTED-scm-server/cmf242896655772090475.keytab
+ USER=REDACTED-scm/admin@CLOUDERA
+ PASSWD=REDACTED
+ KVNO=1
+ SLEEP=0
+ RHEL_FILE=/etc/redhat-release
+ '[' -f /etc/redhat-release ']'
+ set +e
+ grep Tikanga /etc/redhat-release
+ '[' 1 -eq 0 ']'
+ '[' 0 -eq 0 ']'
+ grep 'CentOS release 5' /etc/redhat-release
+ '[' 1 -eq 0 ']'
+ '[' 0 -eq 0 ']'
+ grep 'Scientific Linux release 5' /etc/redhat-release
+ '[' 1 -eq 0 ']'
+ set -e
+ '[' -z /etc/krb5.conf ']'
+ echo 'Using custom config path '\''/etc/krb5.conf'\'', contents below:'
+ cat /etc/krb5.conf
+ IFS=' '
+ read -a ENC_ARR
+ for ENC in '"${ENC_ARR[@]}"'
+ echo 'addent -password -p REDACTED-scm/admin@CLOUDERA -k 1 -e des-hmac-sha1'
+ '[' 0 -eq 1 ']'
+ echo REDACTED
+ echo 'wkt /var/run/REDACTED-scm-server/cmf242896655772090475.keytab'
+ ktutil
+ chmod 600 /var/run/REDACTED-scm-server/cmf242896655772090475.keytab
+ kinit -k -t /var/run/REDACTED-scm-server/cmf242896655772090475.keytab REDACTED-scm/admin@CLOUDERA
kinit: Key table entry not found while getting initial credentials

&amp;gt;&amp;gt;&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 17 Feb 2015 05:30:40 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Can-CDH5-3-Sentry-work-without-Kerberos/m-p/24752#M4976</guid>
      <dc:creator>ty.n</dc:creator>
      <dc:date>2015-02-17T05:30:40Z</dc:date>
    </item>
    <item>
      <title>Re: Can CDH5.3 Sentry work without Kerberos?</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Can-CDH5-3-Sentry-work-without-Kerberos/m-p/24753#M4977</link>
      <description>&lt;P&gt;ok, I posted too soon.&amp;nbsp; I seem to have solved it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I addedd all the key algorithms that kadmin.local listed when I did a get_principal on the cloudera-scm/admin principal.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Restarting the cluster now...&lt;/P&gt;</description>
      <pubDate>Tue, 17 Feb 2015 05:39:53 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Can-CDH5-3-Sentry-work-without-Kerberos/m-p/24753#M4977</guid>
      <dc:creator>ty.n</dc:creator>
      <dc:date>2015-02-17T05:39:53Z</dc:date>
    </item>
    <item>
      <title>Re: Can CDH5.3 Sentry work without Kerberos?</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Can-CDH5-3-Sentry-work-without-Kerberos/m-p/24757#M4978</link>
      <description>&lt;P&gt;The original script Eric Sammer wrote up used to be working when CM didn't have the wizard which enables Kerberos. I made some changes with his.&lt;/P&gt;&lt;P&gt;Please use mine instead and specify the password as cloudera in the wizard.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;See also the step 7 in my github page.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A target="_blank" href="https://github.com/daisukebe/krb-bootstrap"&gt;https://github.com/daisukebe/krb-bootstrap&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;daisukebe has changed the behavior for configuring Kerberos with Cloudera Manager 5.1 (and above). Then this script just generates a principal as &lt;STRONG&gt;cloudera-scm/admin&lt;/STRONG&gt; for CM with a password as '&lt;STRONG&gt;cloudera&lt;/STRONG&gt;'.&lt;/P&gt;</description>
      <pubDate>Tue, 17 Feb 2015 05:45:18 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Can-CDH5-3-Sentry-work-without-Kerberos/m-p/24757#M4978</guid>
      <dc:creator>dice</dc:creator>
      <dc:date>2015-02-17T05:45:18Z</dc:date>
    </item>
    <item>
      <title>Re: Can CDH5.3 Sentry work without Kerberos?</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Can-CDH5-3-Sentry-work-without-Kerberos/m-p/24758#M4979</link>
      <description>&lt;P&gt;Before you do try mine, please uninstall &lt;SPAN class="pl-s1"&gt;krb5-server and krb5-workstation packages.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 17 Feb 2015 05:46:35 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Can-CDH5-3-Sentry-work-without-Kerberos/m-p/24758#M4979</guid>
      <dc:creator>dice</dc:creator>
      <dc:date>2015-02-17T05:46:35Z</dc:date>
    </item>
    <item>
      <title>Re: Can CDH5.3 Sentry work without Kerberos?</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Can-CDH5-3-Sentry-work-without-Kerberos/m-p/24768#M4980</link>
      <description>&lt;P&gt;Thanks for the link to your kerberos bootstrap'er.&amp;nbsp; It seems to work for me.&amp;nbsp; Unfortunately I ran into a secondary problem and I'm not sure how to let Cloudera know about it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;On a clean CDH5.3 virtual machine I started Cloudera Manager and then ran your kerberos bootstrapper.&amp;nbsp; Then I ran the Kerberos configuration wizard in Cloudera Manager.&amp;nbsp; The restart failed to complete successfully.&amp;nbsp; It seemed like the Yarn NameNode was having trouble with the topology.map amd container-executer.cfg file permissions in the /var/run/cloudera-scm-agent/process/??-yarn-NODEMANAGER/ directory (note: ?? is a number generated each time I tried to restart the NodeManager).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;On further inspection, and a couple snapshot reverts, I think I found the real problem.&amp;nbsp; the /etc and /etc/hadoop directories have group write permissions set.&amp;nbsp; This was identified in the NodeManager logs.&amp;nbsp; I started again and changed the permissions to remove the group write permission on both directories - before running the Cloudera Manager Kerberos configuration wizard.&amp;nbsp; This time it seems to have worked.&amp;nbsp; note: I hve not yet had a chance to test kerberos actually doing anything from a hdfs/hive/pig user perspective.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Only one last glitch in the system.&amp;nbsp; It looks like Spark does not have Kerberos credentials created for it.&amp;nbsp; The Spark History Server is showing as critical health and its log is identifying missing Kerberos credentials.&amp;nbsp; When I look at the Kerberos Credentials screen in Cloudera Manager I see credentials for all the services excpt Spark.&amp;nbsp; I'm not doing anything with Spark and I don't know anything about it so I'll just stop the service for now.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am not sure if changing the directory permissions on /etc and /etc/hadoop will adversely affect other functions; but I hope my little investigation can help others.&lt;/P&gt;</description>
      <pubDate>Tue, 17 Feb 2015 12:44:40 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Can-CDH5-3-Sentry-work-without-Kerberos/m-p/24768#M4980</guid>
      <dc:creator>ty.n</dc:creator>
      <dc:date>2015-02-17T12:44:40Z</dc:date>
    </item>
    <item>
      <title>Re: Can CDH5.3 Sentry work without Kerberos?</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Can-CDH5-3-Sentry-work-without-Kerberos/m-p/24769#M4981</link>
      <description>Thanks for the information!&lt;BR /&gt;Hmm, I have never met such kinds of problem, but I don't think the change&lt;BR /&gt;you did will break the other finctionalities.&lt;BR /&gt;&lt;BR /&gt;Daisuke&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Tue, 17 Feb 2015 12:55:44 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Can-CDH5-3-Sentry-work-without-Kerberos/m-p/24769#M4981</guid>
      <dc:creator>dice</dc:creator>
      <dc:date>2015-02-17T12:55:44Z</dc:date>
    </item>
    <item>
      <title>Re: Can CDH5.3 Sentry work without Kerberos?</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Can-CDH5-3-Sentry-work-without-Kerberos/m-p/24823#M4982</link>
      <description>Usually /etc/ and /etc/hadoop don't have group write permissions. Not sure how they got there, but removing it seems like a good idea.</description>
      <pubDate>Wed, 18 Feb 2015 19:44:17 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Can-CDH5-3-Sentry-work-without-Kerberos/m-p/24823#M4982</guid>
      <dc:creator>Darren</dc:creator>
      <dc:date>2015-02-18T19:44:17Z</dc:date>
    </item>
  </channel>
</rss>

