<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>question Re: Enable kerberos in HDP 2.6.2: &amp;quot;Test kerberos Client &amp;quot; is handed in Archives of Support Questions (Read Only)</title>
    <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Enable-kerberos-in-HDP-2-6-2-quot-Test-kerberos-Client-quot/m-p/218021#M69423</link>
    <description>&lt;P&gt;&lt;EM&gt;@&lt;A href="https://community.hortonworks.com/users/19015/xpelive.html"&gt;forest lin&lt;/A&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;BR /&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;You need to change the REAL entry in your /etc/krb5.conf to be like below and distribute to all the nodes in the cluster &lt;/EM&gt;&lt;/P&gt;&lt;PRE&gt;&lt;EM&gt;[domain_realm]
  abc.com = ABC.COM
  .abc.com = ABC.COM&lt;/EM&gt;&lt;/PRE&gt;&lt;P&gt;&lt;EM&gt;Instead of &lt;/EM&gt;&lt;/P&gt;&lt;PRE&gt;&lt;EM&gt;[domain_realm]        
ABC.COM = ABC.COM&lt;/EM&gt;&lt;/PRE&gt;&lt;P&gt;&lt;EM&gt;You must validate that the other files  &lt;STRONG&gt;kdc.conf,&lt;/STRONG&gt;&lt;STRONG&gt;kadm5.acl&lt;/STRONG&gt; are correct &lt;/EM&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 11 Oct 2017 19:34:17 GMT</pubDate>
    <dc:creator>Shelton</dc:creator>
    <dc:date>2017-10-11T19:34:17Z</dc:date>
    <item>
      <title>Enable kerberos in HDP 2.6.2: "Test kerberos Client " is handed</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Enable-kerberos-in-HDP-2-6-2-quot-Test-kerberos-Client-quot/m-p/218020#M69422</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;i have installed hdp2.6.2 cluster on ubuntu16.04 servers, while enabling kerberos, it hanged on the step "Test Kerberos Client" as the picture showed.  &lt;/P&gt;&lt;P&gt;I followed the guideline &lt;A href="https://docs.hortonworks.com/HDPDocuments/Ambari-2.5.1.0/bk_ambari-security/content/optional_install_a_new_mit_kdc.html" target="_blank" rel="nofollow noopener noreferrer"&gt;https://docs.hortonworks.com/HDPDocuments/Ambari-2.5.1.0/bk_ambari-security/content/optional_install_a_new_mit_kdc.html&lt;/A&gt; but seems stranged that when running "krb5_newrealm", it only asked me to enter the master key password, but NOT asked me to input the default &lt;/P&gt;&lt;P&gt;realms.  then I edited the krb5.conf to add the realm manually( &lt;A href="https://community.cloudera.com/legacyfs/online/attachments/40787-krb5conf.txt" target="_blank"&gt;krb5conf.txt&lt;/A&gt;) and the command "kadmin -p admin/admin@ABC.COM" is tested successfully.&lt;/P&gt;&lt;P&gt;Any one had happened to encouter this and have any hints?  &lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="40785-kerberos-hang.png" style="width: 780px;"&gt;&lt;img src="https://community.cloudera.com/t5/image/serverpage/image-id/16095i3318F5EA9D338A49/image-size/medium?v=v2&amp;amp;px=400" role="button" title="40785-kerberos-hang.png" alt="40785-kerberos-hang.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="kerberos-hang-1.png" style="width: 925px;"&gt;&lt;img src="https://community.cloudera.com/t5/image/serverpage/image-id/7937i585232B88B65B1DC/image-size/large?v=v2&amp;amp;px=999" role="button" title="kerberos-hang-1.png" alt="kerberos-hang-1.png" /&gt;&lt;/span&gt;</description>
      <pubDate>Fri, 16 Sep 2022 12:23:15 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Enable-kerberos-in-HDP-2-6-2-quot-Test-kerberos-Client-quot/m-p/218020#M69422</guid>
      <dc:creator>xpelive</dc:creator>
      <dc:date>2022-09-16T12:23:15Z</dc:date>
    </item>
    <item>
      <title>Re: Enable kerberos in HDP 2.6.2: "Test kerberos Client " is handed</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Enable-kerberos-in-HDP-2-6-2-quot-Test-kerberos-Client-quot/m-p/218021#M69423</link>
      <description>&lt;P&gt;&lt;EM&gt;@&lt;A href="https://community.hortonworks.com/users/19015/xpelive.html"&gt;forest lin&lt;/A&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;BR /&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;You need to change the REAL entry in your /etc/krb5.conf to be like below and distribute to all the nodes in the cluster &lt;/EM&gt;&lt;/P&gt;&lt;PRE&gt;&lt;EM&gt;[domain_realm]
  abc.com = ABC.COM
  .abc.com = ABC.COM&lt;/EM&gt;&lt;/PRE&gt;&lt;P&gt;&lt;EM&gt;Instead of &lt;/EM&gt;&lt;/P&gt;&lt;PRE&gt;&lt;EM&gt;[domain_realm]        
ABC.COM = ABC.COM&lt;/EM&gt;&lt;/PRE&gt;&lt;P&gt;&lt;EM&gt;You must validate that the other files  &lt;STRONG&gt;kdc.conf,&lt;/STRONG&gt;&lt;STRONG&gt;kadm5.acl&lt;/STRONG&gt; are correct &lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 11 Oct 2017 19:34:17 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Enable-kerberos-in-HDP-2-6-2-quot-Test-kerberos-Client-quot/m-p/218021#M69423</guid>
      <dc:creator>Shelton</dc:creator>
      <dc:date>2017-10-11T19:34:17Z</dc:date>
    </item>
    <item>
      <title>Re: Enable kerberos in HDP 2.6.2: "Test kerberos Client " is handed</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Enable-kerberos-in-HDP-2-6-2-quot-Test-kerberos-Client-quot/m-p/218022#M69424</link>
      <description>&lt;P&gt;i tried the approach as &lt;A rel="user" href="https://community.cloudera.com/users/1271/sheltong.html" nodeid="1271"&gt;@Geoffrey Shelton Okot&lt;/A&gt; adviced, but no luck.  &lt;/P&gt;&lt;P&gt;The kdc.conf is &lt;A href="https://community.cloudera.com/legacyfs/online/attachments/39778-kdcconf.txt"&gt;kdcconf.txt&lt;/A&gt;,  and the &lt;A href="https://community.cloudera.com/legacyfs/online/attachments/40787-krb5conf.txt"&gt;krb5&lt;/A&gt;.conf is changed to &lt;A href="https://community.cloudera.com/legacyfs/online/attachments/39779-krb5conf-after-install-client.txt"&gt;krb5conf-after-install-client.txt&lt;/A&gt; after the step "&lt;/P&gt;&lt;P&gt;Install Kerberos Client"&lt;/P&gt;&lt;P&gt;The nodes are VMs on the same physical server, and the command "kadmin -p admin/admin@ABC.COM" is successfully on all nodes.&lt;/P&gt;&lt;P&gt;Any hints? I can't find any output log for the step "&lt;/P&gt;&lt;P&gt;Test Kerberos Client" . Actually, can i skip it?&lt;/P&gt;</description>
      <pubDate>Thu, 12 Oct 2017 10:48:53 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Enable-kerberos-in-HDP-2-6-2-quot-Test-kerberos-Client-quot/m-p/218022#M69424</guid>
      <dc:creator>xpelive</dc:creator>
      <dc:date>2017-10-12T10:48:53Z</dc:date>
    </item>
    <item>
      <title>Re: Enable kerberos in HDP 2.6.2: "Test kerberos Client " is handed</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Enable-kerberos-in-HDP-2-6-2-quot-Test-kerberos-Client-quot/m-p/218023#M69425</link>
      <description>&lt;P&gt;&lt;EM&gt;@&lt;A href="https://community.hortonworks.com/users/19015/xpelive.html"&gt;forest lin&lt;/A&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;The &lt;STRONG&gt;kdc.conf&lt;/STRONG&gt; looks fine, but your initial and final &lt;STRONG&gt;krb5.conf&lt;/STRONG&gt; don't look correct you forgot to add the entry in lowercase see below !. Please backup of your current &lt;STRONG&gt;krb5.conf &lt;/STRONG&gt;on all the hosts and replace them with the below exactly as it is.&lt;/EM&gt;&lt;/P&gt;&lt;PRE&gt;[libdefaults]
  renew_lifetime = 7d
  forwardable = true
  default_realm = ABC.COM
  ticket_lifetime = 24h
  dns_lookup_realm = false
  dns_lookup_kdc = false
  default_ccache_name = /tmp/krb5cc_%{uid}
  #default_tgs_enctypes = aes des3-cbc-sha1 rc4 des-cbc-md5
  #default_tkt_enctypes = aes des3-cbc-sha1 rc4 des-cbc-md5
[domain_realm]
  abc.com = ABC.COM
  .abc.com = ABC.COM
[logging]
  default = FILE:/var/log/krb5kdc.log
  admin_server = FILE:/var/log/kadmind.log
  kdc = FILE:/var/log/krb5kdc.log
[realms]
  ABC.COM = {
    admin_server = nn1-dev1-tbdp
    kdc = nn1-dev1-tbdp
  }&lt;/PRE&gt;&lt;P&gt;&lt;EM&gt;Did you re-run the below to correctly setup the &lt;/EM&gt;&lt;EM&gt;KDC and KDC Admin hostnames&lt;/EM&gt;&lt;/P&gt;&lt;PRE&gt;dpkg-reconfigure krb5-kdc&lt;/PRE&gt;&lt;P&gt;&lt;EM&gt;Can you also validate that the &lt;STRONG&gt;host entries&lt;/STRONG&gt; on all the hosts are the same and include the&lt;STRONG&gt; KDC server&lt;/STRONG&gt; host entry?&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;What the content of your &lt;STRONG&gt;kadm5.acl&lt;/STRONG&gt;  file?&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;On the &lt;STRONG&gt;KDC server&lt;/STRONG&gt; can you paste the output of the below command. Please obscure the domain name &lt;/EM&gt;&lt;/P&gt;&lt;PRE&gt;# kdestroy 
# kadmin.local 
Authenticating as principal root/admin@ABC.COM with password. 
kadmin.local: listprincs&lt;/PRE&gt;&lt;P&gt;&lt;I&gt;After  validating and changing the above restart the services&lt;/I&gt;&lt;/P&gt;&lt;PRE&gt;service krb5-kdc restart 
service krb5-admin-server restart&lt;/PRE&gt;&lt;P&gt;&lt;EM&gt;Don't forget to enable auto-restart of &lt;B&gt;kdc&lt;/B&gt;  and kadmin&lt;STRONG&gt; &lt;/STRONG&gt;use appropriate ubuntu command&lt;/EM&gt;&lt;/P&gt;&lt;PRE&gt;chkconfig krb5kdc on 
chkconfig kadmin on&lt;/PRE&gt;&lt;P&gt;&lt;EM&gt;Now try the &lt;STRONG&gt;Ambari--&amp;gt; Kerberos wizard&lt;/STRONG&gt; again it should succeed&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;The logs are in these directories on the &lt;STRONG&gt;KDC &lt;/STRONG&gt;and &lt;STRONG&gt;Clients&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;&lt;PRE&gt;default = /var/log/krb5kdc.log 
admin_server = /var/log/kadmind.log 
kdc = /var/log/krb5kdc.log&lt;/PRE&gt;&lt;P&gt;&lt;EM&gt;Please revert &lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 12 Oct 2017 15:28:31 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Enable-kerberos-in-HDP-2-6-2-quot-Test-kerberos-Client-quot/m-p/218023#M69425</guid>
      <dc:creator>Shelton</dc:creator>
      <dc:date>2017-10-12T15:28:31Z</dc:date>
    </item>
  </channel>
</rss>

