<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>question Configuring the HDFS superuser in Kerberos in Archives of Support Questions (Read Only)</title>
    <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Configuring-the-HDFS-superuser-in-Kerberos/m-p/60901#M69599</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;One question regqrding the documentation of Kerberos, and more specifically "&lt;A href="https://www.cloudera.com/documentation/enterprise/latest/topics/cm_sg_s5_hdfs_principal.html" target="_self"&gt;Step 5: Create the HDFS superuser&lt;/A&gt;". As the document states:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Cloudera recommends you use a different &lt;STRONG&gt;user&lt;/STRONG&gt; account as the superuser, not the default hdfs account.&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;However, later on the steps described, the description mixes the notion of &lt;FONT color="#FF0000"&gt;&lt;STRONG&gt;group&lt;/STRONG&gt;&lt;/FONT&gt; and &lt;FONT color="#0000FF"&gt;&lt;STRONG&gt;user&lt;/STRONG&gt;&lt;/FONT&gt; and it is not quite clear what should be configured:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;5. Locate the &lt;STRONG&gt;Superuser &lt;FONT color="#FF0000"&gt;Group&lt;/FONT&gt;&lt;/STRONG&gt; property and change the value to the appropriate group name for your environment. For example, &amp;lt;super&lt;FONT color="#0000FF"&gt;user&lt;/FONT&gt;&amp;gt;.&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Assuming that &lt;FONT color="#FF0000"&gt;group&lt;/FONT&gt; is what should be configured here (it's can't be user in that property), the rest of the configuration does not make sense, as it says that we need to "&lt;EM&gt;create a Kerberos principal called &amp;lt;super&lt;FONT color="#0000FF"&gt;user&lt;/FONT&gt;&amp;gt;&lt;/EM&gt;". But Kerberos principals refers to users and services and not groups.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In any case, the above configuration does not work. Can someone clarify the documentation?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you!&lt;/P&gt;</description>
    <pubDate>Fri, 13 Oct 2017 13:10:15 GMT</pubDate>
    <dc:creator>gerasimos</dc:creator>
    <dc:date>2017-10-13T13:10:15Z</dc:date>
    <item>
      <title>Configuring the HDFS superuser in Kerberos</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Configuring-the-HDFS-superuser-in-Kerberos/m-p/60901#M69599</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;One question regqrding the documentation of Kerberos, and more specifically "&lt;A href="https://www.cloudera.com/documentation/enterprise/latest/topics/cm_sg_s5_hdfs_principal.html" target="_self"&gt;Step 5: Create the HDFS superuser&lt;/A&gt;". As the document states:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Cloudera recommends you use a different &lt;STRONG&gt;user&lt;/STRONG&gt; account as the superuser, not the default hdfs account.&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;However, later on the steps described, the description mixes the notion of &lt;FONT color="#FF0000"&gt;&lt;STRONG&gt;group&lt;/STRONG&gt;&lt;/FONT&gt; and &lt;FONT color="#0000FF"&gt;&lt;STRONG&gt;user&lt;/STRONG&gt;&lt;/FONT&gt; and it is not quite clear what should be configured:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;5. Locate the &lt;STRONG&gt;Superuser &lt;FONT color="#FF0000"&gt;Group&lt;/FONT&gt;&lt;/STRONG&gt; property and change the value to the appropriate group name for your environment. For example, &amp;lt;super&lt;FONT color="#0000FF"&gt;user&lt;/FONT&gt;&amp;gt;.&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Assuming that &lt;FONT color="#FF0000"&gt;group&lt;/FONT&gt; is what should be configured here (it's can't be user in that property), the rest of the configuration does not make sense, as it says that we need to "&lt;EM&gt;create a Kerberos principal called &amp;lt;super&lt;FONT color="#0000FF"&gt;user&lt;/FONT&gt;&amp;gt;&lt;/EM&gt;". But Kerberos principals refers to users and services and not groups.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In any case, the above configuration does not work. Can someone clarify the documentation?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you!&lt;/P&gt;</description>
      <pubDate>Fri, 13 Oct 2017 13:10:15 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Configuring-the-HDFS-superuser-in-Kerberos/m-p/60901#M69599</guid>
      <dc:creator>gerasimos</dc:creator>
      <dc:date>2017-10-13T13:10:15Z</dc:date>
    </item>
    <item>
      <title>Re: Configuring the HDFS superuser in Kerberos</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Configuring-the-HDFS-superuser-in-Kerberos/m-p/60914#M69600</link>
      <description>It is a group. By default Hadoop create the user hdfs in the group hdfs. The first statement does make it confusing but assumes the defaults as that is the only user in the group. You could add users to the group as well (not recommended).&lt;BR /&gt;&lt;BR /&gt;The last portion referencing the Kerberos principal is just pointing out that it isn't enough to have a user in the superusergroup/supergroup they also need a valid Kerberos principal.&lt;BR /&gt;&lt;BR /&gt;In reality, the users in the group you assign to that property will have Kerberos principals already.&lt;BR /&gt;&lt;BR /&gt;I also recommend, as Cloudera does, to not use the default hdfs group.</description>
      <pubDate>Sat, 14 Oct 2017 04:42:27 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Configuring-the-HDFS-superuser-in-Kerberos/m-p/60914#M69600</guid>
      <dc:creator>mbigelow</dc:creator>
      <dc:date>2017-10-14T04:42:27Z</dc:date>
    </item>
  </channel>
</rss>

