<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>question Re: Ambari is not creating keytab files though it says it has created in Archives of Support Questions (Read Only)</title>
    <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Ambari-is-not-creating-keytab-files-though-it-says-it-has/m-p/206294#M68869</link>
    <description>&lt;P&gt;Thanks &lt;A rel="user" href="https://community.cloudera.com/users/1271/sheltong.html" nodeid="1271"&gt;@Geoffrey Shelton Okot&lt;/A&gt; for the quick response.&lt;/P&gt;&lt;P&gt;Ambari is running as an user which has got sudo privileges. And auto-start services is enabled but only metrics-collector is enabled.&lt;/P&gt;&lt;P&gt;In the KDC i can see that it has created corresponding principals associated with the service and hostnames.&lt;/P&gt;&lt;P&gt;Only issue i have observed is it stopped creating keytab files and distribute it to the designated system which ambari reported successful.&lt;/P&gt;&lt;P&gt;I have carried out this activity some 9-10 times but all the time its ending up without creating keytab files.&lt;/P&gt;</description>
    <pubDate>Tue, 03 Oct 2017 19:42:29 GMT</pubDate>
    <dc:creator>dgiri_india1989</dc:creator>
    <dc:date>2017-10-03T19:42:29Z</dc:date>
    <item>
      <title>Ambari is not creating keytab files though it says it has created</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Ambari-is-not-creating-keytab-files-though-it-says-it-has/m-p/206290#M68865</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;I'm facing an issue while installing a new component to already kerberized cluster. &lt;/P&gt;&lt;P&gt;The installation happens successfully without any issues but services do not start due to unavailability of keytab file on that host where new component is installed.&lt;/P&gt;&lt;P&gt;After the installation I validated that new keytab files are not created in the designated location but ambari says it has created the keytabs and distributed to that host.&lt;/P&gt;&lt;P&gt;Ambari : 2.5.1&lt;/P&gt;&lt;P&gt;HDP : 2.6.1&lt;/P&gt;</description>
      <pubDate>Tue, 03 Oct 2017 17:08:12 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Ambari-is-not-creating-keytab-files-though-it-says-it-has/m-p/206290#M68865</guid>
      <dc:creator>dgiri_india1989</dc:creator>
      <dc:date>2017-10-03T17:08:12Z</dc:date>
    </item>
    <item>
      <title>Re: Ambari is not creating keytab files though it says it has created</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Ambari-is-not-creating-keytab-files-though-it-says-it-has/m-p/206291#M68866</link>
      <description>&lt;P&gt;Hi &lt;A rel="user" href="https://community.cloudera.com/users/20260/dgiriindia1989.html" nodeid="20260"&gt;@D Giri&lt;/A&gt;,&lt;/P&gt;&lt;P&gt;Can you try re-generating the keytabs and check if it works.&lt;/P&gt;&lt;P&gt;Ambari=&amp;gt;Admin=&amp;gt;Kerberos =&amp;gt; Regenerate keytabs&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Aditya&lt;/P&gt;</description>
      <pubDate>Tue, 03 Oct 2017 17:48:31 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Ambari-is-not-creating-keytab-files-though-it-says-it-has/m-p/206291#M68866</guid>
      <dc:creator>asirna</dc:creator>
      <dc:date>2017-10-03T17:48:31Z</dc:date>
    </item>
    <item>
      <title>Re: Ambari is not creating keytab files though it says it has created</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Ambari-is-not-creating-keytab-files-though-it-says-it-has/m-p/206292#M68867</link>
      <description>&lt;P&gt;&lt;EM&gt;@&lt;A href="https://community.hortonworks.com/users/20260/dgiriindia1989.html"&gt;D Giri&lt;/A&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;HDP 2.6 has a new feature called &lt;STRONG&gt;Service Auto start &lt;/STRONG&gt;see A&lt;STRONG&gt;mbaru UI--&amp;gt;admin-&amp;gt; Service Auto Start&lt;/STRONG&gt; &lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Can you validate that the component status ? Or the Auto start Services status should be either  &lt;STRONG&gt;enabled/disabled&lt;/STRONG&gt;&lt;BR /&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Can you also check the KDC if the principals are created&lt;STRONG&gt;Can you also check in the KDC &lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;&lt;PRE&gt;&lt;EM&gt;# kadmin.local
kadmin.local: listprincs&lt;/EM&gt;&lt;/PRE&gt;&lt;P&gt;&lt;EM&gt;Are you running Ambari as root if not then that user  MUST  authorization to write to /var/lib/ambari-server/tmp.&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Please revert&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 03 Oct 2017 17:53:49 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Ambari-is-not-creating-keytab-files-though-it-says-it-has/m-p/206292#M68867</guid>
      <dc:creator>Shelton</dc:creator>
      <dc:date>2017-10-03T17:53:49Z</dc:date>
    </item>
    <item>
      <title>Re: Ambari is not creating keytab files though it says it has created</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Ambari-is-not-creating-keytab-files-though-it-says-it-has/m-p/206293#M68868</link>
      <description>&lt;P&gt;Yes I have regenerated but it didn't help. What i have seen is it didn't create new keytabs.&lt;/P&gt;</description>
      <pubDate>Tue, 03 Oct 2017 19:33:10 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Ambari-is-not-creating-keytab-files-though-it-says-it-has/m-p/206293#M68868</guid>
      <dc:creator>dgiri_india1989</dc:creator>
      <dc:date>2017-10-03T19:33:10Z</dc:date>
    </item>
    <item>
      <title>Re: Ambari is not creating keytab files though it says it has created</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Ambari-is-not-creating-keytab-files-though-it-says-it-has/m-p/206294#M68869</link>
      <description>&lt;P&gt;Thanks &lt;A rel="user" href="https://community.cloudera.com/users/1271/sheltong.html" nodeid="1271"&gt;@Geoffrey Shelton Okot&lt;/A&gt; for the quick response.&lt;/P&gt;&lt;P&gt;Ambari is running as an user which has got sudo privileges. And auto-start services is enabled but only metrics-collector is enabled.&lt;/P&gt;&lt;P&gt;In the KDC i can see that it has created corresponding principals associated with the service and hostnames.&lt;/P&gt;&lt;P&gt;Only issue i have observed is it stopped creating keytab files and distribute it to the designated system which ambari reported successful.&lt;/P&gt;&lt;P&gt;I have carried out this activity some 9-10 times but all the time its ending up without creating keytab files.&lt;/P&gt;</description>
      <pubDate>Tue, 03 Oct 2017 19:42:29 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Ambari-is-not-creating-keytab-files-though-it-says-it-has/m-p/206294#M68869</guid>
      <dc:creator>dgiri_india1989</dc:creator>
      <dc:date>2017-10-03T19:42:29Z</dc:date>
    </item>
    <item>
      <title>Re: Ambari is not creating keytab files though it says it has created</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Ambari-is-not-creating-keytab-files-though-it-says-it-has/m-p/206295#M68870</link>
      <description>&lt;P&gt;&lt;EM&gt;@&lt;A href="https://community.hortonworks.com/users/20260/dgiriindia1989.html"&gt;D Giri&lt;/A&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Did you by chance download the CSV file with the keytabs for manual creation? &lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;There is an option to &lt;STRONG&gt;ONLY&lt;/STRONG&gt;  regenerate keytabs for missing hosts and components !!  &lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Did you correctly key in the user/passowrd in the Ambari-Kerberos wizard? Could you briefly describe your cluster setup?  Master/slave and where the KDC is installed?&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Make sure the &lt;STRONG&gt;[realms]&lt;/STRONG&gt; and &lt;STRONG&gt;[domain_realms]&lt;/STRONG&gt; entries in  &lt;STRONG&gt;/etc/krb5.conf &lt;/STRONG&gt;is correct.
Validate the contents of these 2 files &lt;STRONG&gt;/var/kerberos/krb5kdc/kdc.conf &lt;/STRONG&gt;, &lt;STRONG&gt;/var/kerberos/krb5kdc/kadm5.acl&lt;/STRONG&gt;&lt;BR /&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Can you share the contents of the above file don't forget to scramble site specific information&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 05 Oct 2017 01:47:03 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Ambari-is-not-creating-keytab-files-though-it-says-it-has/m-p/206295#M68870</guid>
      <dc:creator>Shelton</dc:creator>
      <dc:date>2017-10-05T01:47:03Z</dc:date>
    </item>
    <item>
      <title>Re: Ambari is not creating keytab files though it says it has created</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Ambari-is-not-creating-keytab-files-though-it-says-it-has/m-p/206296#M68871</link>
      <description>&lt;P&gt;Hi &lt;A rel="user" href="https://community.cloudera.com/users/1271/sheltong.html" nodeid="1271"&gt;@Geoffrey Shelton Okot&lt;/A&gt;, &lt;/P&gt;&lt;P&gt;I have checked the content and everything looks good and we are using same krb config files across different clusters. I dont see any discrepencies with the kerberos.&lt;/P&gt;</description>
      <pubDate>Fri, 06 Oct 2017 18:49:32 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Ambari-is-not-creating-keytab-files-though-it-says-it-has/m-p/206296#M68871</guid>
      <dc:creator>dgiri_india1989</dc:creator>
      <dc:date>2017-10-06T18:49:32Z</dc:date>
    </item>
    <item>
      <title>Re: Ambari is not creating keytab files though it says it has created</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Ambari-is-not-creating-keytab-files-though-it-says-it-has/m-p/206297#M68872</link>
      <description>&lt;P&gt;&lt;EM&gt;@&lt;A href="https://community.hortonworks.com/users/20260/dgiriindia1989.html"&gt;D Giri&lt;/A&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Can you descript your cluster setup (master, Slave and Edge nodes)&lt;BR /&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Okay what are the new components you are trying to install? &lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;You could be checking for the keytabs on the wrong host, can you rerun the below command&lt;/EM&gt;&lt;/P&gt;&lt;PRE&gt;# kadmin.local 
Authenticating as principal root/admin@REALM with password. 
kadmin.local: listprincs&lt;/PRE&gt;&lt;P&gt;&lt;EM&gt;All the principals created should be visible in the KD database. If the principal for the component is present  take note of the host and try to  locate the&lt;STRONG&gt; keytabs&lt;/STRONG&gt; in the below  location of that node&lt;/EM&gt;&lt;/P&gt;&lt;PRE&gt;/etc/security/keytabs&lt;/PRE&gt;&lt;P&gt;&lt;EM&gt;Please let me know&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 06 Oct 2017 20:05:52 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Ambari-is-not-creating-keytab-files-though-it-says-it-has/m-p/206297#M68872</guid>
      <dc:creator>Shelton</dc:creator>
      <dc:date>2017-10-06T20:05:52Z</dc:date>
    </item>
    <item>
      <title>Re: Ambari is not creating keytab files though it says it has created</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Ambari-is-not-creating-keytab-files-though-it-says-it-has/m-p/206298#M68873</link>
      <description>&lt;P&gt;@D Giri, &lt;/P&gt;&lt;P&gt;Can you post the output of "ls /etc/security/keytabs" here. Along with the component that is part of cluster and fails to start ?&lt;/P&gt;&lt;P&gt;My suspect is that we should not put anything in "Principal Suffix" parameter filed when the keytab is created for any service. As, that adds cluster name into the keytab principle where as the service only looks by the username of respective service.&lt;/P&gt;</description>
      <pubDate>Tue, 10 Oct 2017 17:20:38 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Ambari-is-not-creating-keytab-files-though-it-says-it-has/m-p/206298#M68873</guid>
      <dc:creator>narendrakumar</dc:creator>
      <dc:date>2017-10-10T17:20:38Z</dc:date>
    </item>
    <item>
      <title>Re: Ambari is not creating keytab files though it says it has created</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Ambari-is-not-creating-keytab-files-though-it-says-it-has/m-p/206299#M68874</link>
      <description>&lt;P&gt;Apologies &lt;A rel="user" href="https://community.cloudera.com/users/16330/nkumar.html" nodeid="16330"&gt;@nkumar&lt;/A&gt; for the delay in response.&lt;/P&gt;&lt;P&gt;The issue is related to Ambari which behaves differently after disabling and re-enabling the kerberos.&lt;/P&gt;&lt;P&gt;Issue got fixed after making changes to ambari with the help of Hortonworks Support using below REST calls.&lt;/P&gt;&lt;P&gt;curl -u test:test -H "X-Requested-By: ambari" -X POST &lt;A href="http://ambari-server:8080/api/v1/clusters/MyClusterName/services/KERBEROS" target="_blank"&gt;http://ambari-server:8080/api/v1/clusters/MyClusterName/services/KERBEROS&lt;/A&gt;&lt;/P&gt;&lt;P&gt;curl -u test:test -H "X-Requested-By: ambari" -X POST &lt;A href="http://ambari-server:8080/api/v1/clusters/MyClusterName/services/KERBEROS/components/KERBEROS_CLIENT" target="_blank"&gt;http://ambari-server:8080/api/v1/clusters/MyClusterName/services/KERBEROS/components/KERBEROS_CLIENT&lt;/A&gt;&lt;/P&gt;&lt;P&gt;curl -s -u test:test &lt;A href="http://ambari-server:8080/api/v1/hosts|grep" target="_blank"&gt;http://ambari-server:8080/api/v1/hosts|grep&lt;/A&gt; host_name| sed -n 's/.*"host_name" : "\([^\"]*\)".*/\1/p'&amp;gt;hostcluster.txt&lt;/P&gt;&lt;P&gt;for i in `cat hostcluster.txt`; do curl -u test:test -H "X-Requested-By: ambari" -X POST &lt;A href="http://ambari-server:8080/api/v1/clusters/MyClusterName/hosts/$i/host_components/KERBEROS_CLIENT" target="_blank"&gt;http://ambari-server:8080/api/v1/clusters/MyClusterName/hosts/$i/host_components/KERBEROS_CLIENT&lt;/A&gt;; done&lt;/P&gt;&lt;P&gt;curl -u test:test -H 'X-Requested-By: ambari' -X PUT -d '{"HostRoles": {"state":"INSTALLED"}}' &lt;A href="http://ambari-server:8080/api/v1/clusters/MyClusterName/host_components?HostRoles/state=INIT" target="_blank"&gt;http://ambari-server:8080/api/v1/clusters/MyClusterName/host_components?HostRoles/state=INIT&lt;/A&gt;&lt;/P&gt;&lt;P&gt;curl -H "X-Requested-By:ambari" -u test:test -i -X PUT -d @./payload.json &lt;A href="http://ambari-server:8080/api/v1/clusters/MyClusterName" target="_blank"&gt;http://ambari-server:8080/api/v1/clusters/MyClusterName&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 09 Nov 2017 23:01:03 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Ambari-is-not-creating-keytab-files-though-it-says-it-has/m-p/206299#M68874</guid>
      <dc:creator>dgiri_india1989</dc:creator>
      <dc:date>2017-11-09T23:01:03Z</dc:date>
    </item>
    <item>
      <title>Re: Ambari is not creating keytab files though it says it has created</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Ambari-is-not-creating-keytab-files-though-it-says-it-has/m-p/320300#M68875</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/57292"&gt;@dgiri_india1989&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Could you please share more details for this issue about how you are able to fix this.&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are also facing similar issue with Ranger KMS service.&lt;/P&gt;&lt;P&gt;RangerKMS Principal is created in AD KDC, Also Keytab creation is success according to Ambari Server log, but it's not distributed to RangerKMS service hosted node. Due to this service is not starting up.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 10 Jul 2021 12:38:55 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Ambari-is-not-creating-keytab-files-though-it-says-it-has/m-p/320300#M68875</guid>
      <dc:creator>avinashmv442</dc:creator>
      <dc:date>2021-07-10T12:38:55Z</dc:date>
    </item>
  </channel>
</rss>

