<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>question Yarn ATS replay request on security enabled cluster. in Archives of Support Questions (Read Only)</title>
    <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Yarn-ATS-replay-request-on-security-enabled-cluster/m-p/203282#M59658</link>
    <description>&lt;P&gt;Hello community,&lt;/P&gt;&lt;P&gt;I'have a cluster with kerberos and after a restart I'm having the following error when trying to reach the ATS
&lt;/P&gt;&lt;PRE&gt;&amp;lt;html&amp;gt;
&amp;lt;head&amp;gt;
&amp;lt;meta http-equiv="Content-Type" content="text/html; charset=ISO-8859-1"/&amp;gt;
&amp;lt;title&amp;gt;Error 403 GSSException: Failure unspecified at GSS-API level (Mechanism level: Request is a replay (34))&amp;lt;/title&amp;gt;
&amp;lt;/head&amp;gt;
&amp;lt;body&amp;gt;&amp;lt;h2&amp;gt;HTTP ERROR 403&amp;lt;/h2&amp;gt;
&amp;lt;p&amp;gt;Problem accessing /applicationhistory. Reason:
&amp;lt;pre&amp;gt;    GSSException: Failure unspecified at GSS-API level (Mechanism level: Request is a replay (34))&amp;lt;/pre&amp;gt;&amp;lt;/p&amp;gt;&amp;lt;hr /&amp;gt;&amp;lt;i&amp;gt;&amp;lt;small&amp;gt;Powered by Jetty://ll&amp;gt;&amp;lt;/i&amp;gt;&amp;lt;br/&amp;gt;
&amp;lt;br/&amp;gt;
&amp;lt;br/&amp;gt;
&amp;lt;br/&amp;gt;
&amp;lt;br/&amp;gt;
&amp;lt;br/&amp;gt;
&amp;lt;br/&amp;gt;
&amp;lt;br/&amp;gt;
&amp;lt;br/&amp;gt;
&amp;lt;br/&amp;gt;
&amp;lt;br/&amp;gt;
&amp;lt;br/&amp;gt;
&amp;lt;br/&amp;gt;
&amp;lt;br/&amp;gt;
&amp;lt;br/&amp;gt;
&amp;lt;br/&amp;gt;
&amp;lt;br/&amp;gt;
&amp;lt;br/&amp;gt;
&amp;lt;br/&amp;gt;
&amp;lt;br/&amp;gt;


&amp;lt;/body&amp;gt;
&amp;lt;/html&amp;gt;&lt;/PRE&gt;I've tried with diferent principals but the issue persist.&lt;P&gt;The resource manager and the rest of the spnego authenticated web consoles still working properly.&lt;/P&gt;&lt;P&gt;Any idea about what is going on?&lt;/P&gt;&lt;P&gt;Thank you in advance&lt;/P&gt;</description>
    <pubDate>Wed, 19 Apr 2017 00:57:04 GMT</pubDate>
    <dc:creator>juan_manuel_nie</dc:creator>
    <dc:date>2017-04-19T00:57:04Z</dc:date>
    <item>
      <title>Yarn ATS replay request on security enabled cluster.</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Yarn-ATS-replay-request-on-security-enabled-cluster/m-p/203282#M59658</link>
      <description>&lt;P&gt;Hello community,&lt;/P&gt;&lt;P&gt;I'have a cluster with kerberos and after a restart I'm having the following error when trying to reach the ATS
&lt;/P&gt;&lt;PRE&gt;&amp;lt;html&amp;gt;
&amp;lt;head&amp;gt;
&amp;lt;meta http-equiv="Content-Type" content="text/html; charset=ISO-8859-1"/&amp;gt;
&amp;lt;title&amp;gt;Error 403 GSSException: Failure unspecified at GSS-API level (Mechanism level: Request is a replay (34))&amp;lt;/title&amp;gt;
&amp;lt;/head&amp;gt;
&amp;lt;body&amp;gt;&amp;lt;h2&amp;gt;HTTP ERROR 403&amp;lt;/h2&amp;gt;
&amp;lt;p&amp;gt;Problem accessing /applicationhistory. Reason:
&amp;lt;pre&amp;gt;    GSSException: Failure unspecified at GSS-API level (Mechanism level: Request is a replay (34))&amp;lt;/pre&amp;gt;&amp;lt;/p&amp;gt;&amp;lt;hr /&amp;gt;&amp;lt;i&amp;gt;&amp;lt;small&amp;gt;Powered by Jetty://ll&amp;gt;&amp;lt;/i&amp;gt;&amp;lt;br/&amp;gt;
&amp;lt;br/&amp;gt;
&amp;lt;br/&amp;gt;
&amp;lt;br/&amp;gt;
&amp;lt;br/&amp;gt;
&amp;lt;br/&amp;gt;
&amp;lt;br/&amp;gt;
&amp;lt;br/&amp;gt;
&amp;lt;br/&amp;gt;
&amp;lt;br/&amp;gt;
&amp;lt;br/&amp;gt;
&amp;lt;br/&amp;gt;
&amp;lt;br/&amp;gt;
&amp;lt;br/&amp;gt;
&amp;lt;br/&amp;gt;
&amp;lt;br/&amp;gt;
&amp;lt;br/&amp;gt;
&amp;lt;br/&amp;gt;
&amp;lt;br/&amp;gt;
&amp;lt;br/&amp;gt;


&amp;lt;/body&amp;gt;
&amp;lt;/html&amp;gt;&lt;/PRE&gt;I've tried with diferent principals but the issue persist.&lt;P&gt;The resource manager and the rest of the spnego authenticated web consoles still working properly.&lt;/P&gt;&lt;P&gt;Any idea about what is going on?&lt;/P&gt;&lt;P&gt;Thank you in advance&lt;/P&gt;</description>
      <pubDate>Wed, 19 Apr 2017 00:57:04 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Yarn-ATS-replay-request-on-security-enabled-cluster/m-p/203282#M59658</guid>
      <dc:creator>juan_manuel_nie</dc:creator>
      <dc:date>2017-04-19T00:57:04Z</dc:date>
    </item>
    <item>
      <title>Re: Yarn ATS replay request on security enabled cluster.</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Yarn-ATS-replay-request-on-security-enabled-cluster/m-p/203283#M59659</link>
      <description>&lt;P&gt;Hello &lt;A rel="user" href="https://community.cloudera.com/users/1816/juanmanuelnieto.html" nodeid="1816"&gt;@Juan Manuel Nieto&lt;/A&gt;,&lt;/P&gt;&lt;P&gt;The 'request is a replay' usually means that your Kerberos KDC is processing two same requests (almost) at the same time and 'thinks' that the second request is actually a replay attack than a legitimate request. Therefore it will drop the second request.&lt;/P&gt;&lt;P&gt;Things to check here:&lt;/P&gt;&lt;P&gt;1. KDC logs - try to find out for which requests and what principal, it is complaining about&lt;/P&gt;&lt;P&gt;2. Application log - Check YARN ATS log for any possible error w.r.t. Kerberos&lt;/P&gt;&lt;P&gt;3. Are you using same keytab with multiple services? (apart from spnego.service.keytab which is shared across services on a node). If yes, please try and use different keytabs for different services.&lt;/P&gt;&lt;P&gt;For the logs, it'll be worth to increase the Kerberos debug level by setting up "-Dsun.security.krb5.debug=true" in the JVM parameters and also try 'export KRB5_TRACE=/tmp/somefile' on the client-side before running a curl request (using browser won't help much).&lt;/P&gt;&lt;P&gt;Hope this helps !&lt;/P&gt;</description>
      <pubDate>Mon, 24 Apr 2017 20:21:15 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Yarn-ATS-replay-request-on-security-enabled-cluster/m-p/203283#M59659</guid>
      <dc:creator>VR46</dc:creator>
      <dc:date>2017-04-24T20:21:15Z</dc:date>
    </item>
    <item>
      <title>Re: Yarn ATS replay request on security enabled cluster.</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Yarn-ATS-replay-request-on-security-enabled-cluster/m-p/203284#M59660</link>
      <description>&lt;P style="margin-left: 20px;"&gt;Hello &lt;A rel="user" href="https://community.cloudera.com/users/740/vrathor.html" nodeid="740"&gt;@Vipin Rathor&lt;/A&gt;,&lt;/P&gt;&lt;P style="margin-left: 20px;"&gt;An apology for the delay in the answer, finally I solved it, as you said the problem with the replay was that he was trying to authenticate multiple times in a very short time, this was caused by curl and the -L parameter, for some reason curl wasn't storing the session cookie, I fixed it using -c &amp;lt;file path&amp;gt; -b &amp;lt;file path&amp;gt; parameter to store the cookie.&lt;/P&gt;&lt;P style="margin-left: 20px;"&gt;Thank you.&lt;/P&gt;&lt;P style="margin-left: 20px;"&gt;&lt;/P&gt;&lt;P style="margin-left: 20px;"&gt; &lt;/P&gt;</description>
      <pubDate>Wed, 17 May 2017 22:15:59 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Yarn-ATS-replay-request-on-security-enabled-cluster/m-p/203284#M59660</guid>
      <dc:creator>juan_manuel_nie</dc:creator>
      <dc:date>2017-05-17T22:15:59Z</dc:date>
    </item>
  </channel>
</rss>

