<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>question Kerberos principal should have 3 parts: hive in Archives of Support Questions (Read Only)</title>
    <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Kerberos-principal-should-have-3-parts-hive/m-p/159981#M53370</link>
    <description>&lt;P&gt;not able to start metastore....it is kerborized using Ambari, version 2.5.3&lt;/P&gt;&lt;P&gt;[hive@master2 ~]$ klist&lt;/P&gt;&lt;P&gt;
klist: No credentials cache found (ticket cache FILE:/tmp/krb5cc_501)&lt;/P&gt;&lt;P&gt;
[hive@master2 ~]$ kinit -k -t /etc/security/keytabs/hive.service.keytab hive/master2.chrsv.com@KERBEROS.COM
[hive@master2 ~]$ klist &lt;/P&gt;&lt;P&gt;Ticket cache: FILE:/tmp/krb5cc_501 &lt;/P&gt;&lt;P&gt;Default principal: hive/master2.chrsv.com@KERBEROS.COM&lt;/P&gt;&lt;P&gt;
Valid starting     Expires            Service principal &lt;/P&gt;&lt;P&gt;02/03/17 14:55:41  02/04/17 14:55:41  krbtgt/KERBEROS.COM@KERBEROS.COM &lt;/P&gt;&lt;P&gt;        renew until 02/03/17 14:55:41 &lt;/P&gt;&lt;P&gt;[hive@master2 ~]$&lt;/P&gt;</description>
    <pubDate>Sat, 04 Feb 2017 05:05:51 GMT</pubDate>
    <dc:creator>chrsvarma</dc:creator>
    <dc:date>2017-02-04T05:05:51Z</dc:date>
    <item>
      <title>Kerberos principal should have 3 parts: hive</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Kerberos-principal-should-have-3-parts-hive/m-p/159981#M53370</link>
      <description>&lt;P&gt;not able to start metastore....it is kerborized using Ambari, version 2.5.3&lt;/P&gt;&lt;P&gt;[hive@master2 ~]$ klist&lt;/P&gt;&lt;P&gt;
klist: No credentials cache found (ticket cache FILE:/tmp/krb5cc_501)&lt;/P&gt;&lt;P&gt;
[hive@master2 ~]$ kinit -k -t /etc/security/keytabs/hive.service.keytab hive/master2.chrsv.com@KERBEROS.COM
[hive@master2 ~]$ klist &lt;/P&gt;&lt;P&gt;Ticket cache: FILE:/tmp/krb5cc_501 &lt;/P&gt;&lt;P&gt;Default principal: hive/master2.chrsv.com@KERBEROS.COM&lt;/P&gt;&lt;P&gt;
Valid starting     Expires            Service principal &lt;/P&gt;&lt;P&gt;02/03/17 14:55:41  02/04/17 14:55:41  krbtgt/KERBEROS.COM@KERBEROS.COM &lt;/P&gt;&lt;P&gt;        renew until 02/03/17 14:55:41 &lt;/P&gt;&lt;P&gt;[hive@master2 ~]$&lt;/P&gt;</description>
      <pubDate>Sat, 04 Feb 2017 05:05:51 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Kerberos-principal-should-have-3-parts-hive/m-p/159981#M53370</guid>
      <dc:creator>chrsvarma</dc:creator>
      <dc:date>2017-02-04T05:05:51Z</dc:date>
    </item>
    <item>
      <title>Re: Kerberos principal should have 3 parts: hive</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Kerberos-principal-should-have-3-parts-hive/m-p/159982#M53371</link>
      <description>&lt;P&gt;&lt;A rel="user" href="https://community.cloudera.com/users/968/chrsvarma.html" nodeid="968"&gt;@Raja Sekhar Chintalapati&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Can you share log information from the moment you try to start the metastore?&lt;/P&gt;&lt;P&gt;Also the output of --&amp;gt; klist -kte /etc/security/keytabs/hive.service.keytab&lt;/P&gt;</description>
      <pubDate>Sat, 04 Feb 2017 05:18:51 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Kerberos-principal-should-have-3-parts-hive/m-p/159982#M53371</guid>
      <dc:creator>icocio</dc:creator>
      <dc:date>2017-02-04T05:18:51Z</dc:date>
    </item>
    <item>
      <title>Re: Kerberos principal should have 3 parts: hive</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Kerberos-principal-should-have-3-parts-hive/m-p/159983#M53372</link>
      <description>&lt;P&gt;&lt;A rel="user" href="https://community.cloudera.com/users/493/icocio.html" nodeid="493"&gt;@icocio&lt;/A&gt; &lt;/P&gt;&lt;P&gt;[hive@master2 ~]$  klist -kte /etc/security/keytabs/hive.service.keytab
Keytab name: FILE:/etc/security/keytabs/hive.service.keytab
KVNO Timestamp         Principal
---- ----------------- --------------------------------------------------------
   2 02/03/17 15:12:29 hive/master2.chrsv.com@KERBEROS.COM (arcfour-hmac)
   2 02/03/17 15:12:29 hive/master2.chrsv.com@KERBEROS.COM (des-cbc-md5)
   2 02/03/17 15:12:29 hive/master2.chrsv.com@KERBEROS.COM (aes256-cts-hmac-sha1-96)
   2 02/03/17 15:12:29 hive/master2.chrsv.com@KERBEROS.COM (aes128-cts-hmac-sha1-96)
   2 02/03/17 15:12:29 hive/master2.chrsv.com@KERBEROS.COM (des3-cbc-sha1)
[hive@master2 ~]$&lt;/P&gt;</description>
      <pubDate>Sat, 04 Feb 2017 05:32:12 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Kerberos-principal-should-have-3-parts-hive/m-p/159983#M53372</guid>
      <dc:creator>chrsvarma</dc:creator>
      <dc:date>2017-02-04T05:32:12Z</dc:date>
    </item>
    <item>
      <title>Re: Kerberos principal should have 3 parts: hive</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Kerberos-principal-should-have-3-parts-hive/m-p/159984#M53373</link>
      <description>&lt;P&gt;Feb 03 15:23:55 master2.chrsv.com krb5kdc[3363](info): TGS_REQ (4 etypes {18 17 16 23}) 192.168.56.21: ISSUE: authtime 1486153210, etypes {rep=18 tkt=18 ses=18}, nn/master1.chrsv.com@KERBEROS.COM for nn/master1.chrsv.com@KERBEROS.COM
Feb 03 15:24:00 master2.chrsv.com krb5kdc[3363](info): AS_REQ (4 etypes {18 17 16 23}) 192.168.56.63: ISSUE: authtime 1486153440, etypes {rep=18 tkt=18 ses=18}, hdfs-hdp@KERBEROS.COM for krbtgt/KERBEROS.COM@KERBEROS.COM
Feb 03 15:24:08 master2.chrsv.com krb5kdc[3363](info): AS_REQ (4 etypes {18 17 16 23}) 192.168.56.22: ISSUE: authtime 1486153448, etypes {rep=18 tkt=18 ses=18}, ambari-qa-hdp@KERBEROS.COM for krbtgt/KERBEROS.COM@KERBEROS.COM
Feb 03 15:24:12 master2.chrsv.com krb5kdc[3363](info): TGS_REQ (4 etypes {18 17 16 23}) 192.168.56.22: ISSUE: authtime 1486153222, etypes {rep=18 tkt=18 ses=18}, nn/master2.chrsv.com@KERBEROS.COM for HTTP/master2.chrsv.com@KERBEROS.COM&lt;/P&gt;&lt;P&gt;I see services but not hive in krb5.log&lt;/P&gt;</description>
      <pubDate>Sat, 04 Feb 2017 05:37:10 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Kerberos-principal-should-have-3-parts-hive/m-p/159984#M53373</guid>
      <dc:creator>chrsvarma</dc:creator>
      <dc:date>2017-02-04T05:37:10Z</dc:date>
    </item>
    <item>
      <title>Re: Kerberos principal should have 3 parts: hive</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Kerberos-principal-should-have-3-parts-hive/m-p/159985#M53374</link>
      <description>&lt;A rel="user" href="https://community.cloudera.com/users/968/chrsvarma.html" nodeid="968"&gt;@Raja Sekhar Chintalapati&lt;/A&gt;&lt;P&gt;Can you share the hivemetastore log? Kerberos principal should have 3 parts would mean that  kerberos principal provided for auth is incomplete ,this can happen if you have provided principal like hive/master2.chrsv.com(excluding REALM name) If you are trying to start from Ambari then you should see output.log and error.log from here we can see which principal is being used while starting the service and correct it in config according to that error. &lt;/P&gt;</description>
      <pubDate>Sun, 05 Feb 2017 13:32:27 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Kerberos-principal-should-have-3-parts-hive/m-p/159985#M53374</guid>
      <dc:creator>rguruvannagari</dc:creator>
      <dc:date>2017-02-05T13:32:27Z</dc:date>
    </item>
    <item>
      <title>Re: Kerberos principal should have 3 parts: hive</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Kerberos-principal-should-have-3-parts-hive/m-p/159986#M53375</link>
      <description>&lt;P&gt;this is because mysql is external to ambari and when kerberos is enabled ambari is not smart enough to recognize mysql and it didnot create keytabs for mysql. that was the reason hive was not able to start.&lt;/P&gt;&lt;P&gt;i still need to find out a way to create keytabs for non ambari components. as of now i moved these components to another server where all the services were deployed through ambari.&lt;/P&gt;&lt;P&gt;thanks to all for your help so far.&lt;/P&gt;</description>
      <pubDate>Sat, 18 Feb 2017 06:41:32 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Kerberos-principal-should-have-3-parts-hive/m-p/159986#M53375</guid>
      <dc:creator>chrsvarma</dc:creator>
      <dc:date>2017-02-18T06:41:32Z</dc:date>
    </item>
    <item>
      <title>Re: Kerberos principal should have 3 parts: hive</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Kerberos-principal-should-have-3-parts-hive/m-p/159987#M53376</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;Having the same issue &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;&lt;P&gt;I find in the hive meta store log&lt;/P&gt;&lt;PRE&gt;2017-03-10 16:50:52,164 INFO  [main]: zookeeper.ZooKeeper (Environment.java:logEnv(100)) - Client environment:user.name=hive&lt;/PRE&gt;&lt;P&gt;No idea where this is coming from though&lt;/P&gt;&lt;P&gt;All tips appreciated!
&lt;/P&gt;&lt;P&gt;Peter&lt;/P&gt;</description>
      <pubDate>Sat, 11 Mar 2017 00:55:40 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Kerberos-principal-should-have-3-parts-hive/m-p/159987#M53376</guid>
      <dc:creator>peter_coppens</dc:creator>
      <dc:date>2017-03-11T00:55:40Z</dc:date>
    </item>
  </channel>
</rss>

