<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>question Re: CM upgrade - stale Kerberos configuration in Archives of Support Questions (Read Only)</title>
    <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/CM-upgrade-stale-Kerberos-configuration/m-p/297764#M73139</link>
    <description>&lt;P&gt;I was not stoping cdh and cloudera management services&amp;nbsp; and deploying Kerberos configurations.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Now I stopped&amp;nbsp;cdh and cloudera management services and&amp;nbsp;deploying Kerberos configurations.&lt;BR /&gt;It worked for me and /etc/krb5.conf is updated for all hosts in cluster.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This issue resolved.&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 10 Jun 2020 09:42:15 GMT</pubDate>
    <dc:creator>ThriftTran</dc:creator>
    <dc:date>2020-06-10T09:42:15Z</dc:date>
    <item>
      <title>CM upgrade - stale Kerberos configuration</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/CM-upgrade-stale-Kerberos-configuration/m-p/63345#M73136</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;after an upgrade from CM 5.11 to 5.13 the Cloudera Manager complains with a red excl mark:&amp;nbsp;&lt;STRONG&gt;Cluster has stale Kerberos client configuration.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The cluster was all in green before upgrade and had no problem with kerberos configs (/etc/krb5.conf).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What is more concerning, that after opening this warning, three (gateway) nodes does not require upgrade, but the rest of them does:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#FF0000"&gt;&lt;SPAN&gt;Consider stopping roles on these hosts to ensure that they are updated by this command:&lt;/SPAN&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;STRONG&gt;&lt;FONT color="#FF0000"&gt;ip-10-197-13-169.eu-west-1.compute.internal; ip-10-197-15-82.eu-west-1.compute.internal; ip-10-197-18-[113, 248].eu-west-1.compute.internal... &lt;/FONT&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;But the command is not there.&amp;nbsp;&lt;/STRONG&gt;What should I do? Stop the whole CDH and then rerun the deploy?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for the advise,&lt;/P&gt;&lt;P&gt;T.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 05 Jan 2018 15:23:36 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/CM-upgrade-stale-Kerberos-configuration/m-p/63345#M73136</guid>
      <dc:creator>Tomas79</dc:creator>
      <dc:date>2018-01-05T15:23:36Z</dc:date>
    </item>
    <item>
      <title>Re: CM upgrade - stale Kerberos configuration</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/CM-upgrade-stale-Kerberos-configuration/m-p/63381#M73137</link>
      <description>&lt;P&gt;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/11235"&gt;@Tomas79&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The &lt;STRONG&gt;Cluster has stale Kerberos client configuration&lt;/STRONG&gt; message indicates that there was some configuration change in Cloudera Manager to your Kerberos configuration that resulted in a change to the managed krb5.conf file.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am not sure what the upgrade may have done, but it would be worth checking your Cloudera Manager configuration to see.&lt;/P&gt;&lt;P&gt;Try going to &lt;STRONG&gt;Administration --&amp;gt; Settings&lt;/STRONG&gt; and then click the &lt;STRONG&gt;History and Rollback&lt;/STRONG&gt; link.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;See if there were any recent changes to your kerberos configuration.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you don't find anything conclusive, the following should clear this up:&lt;BR /&gt;&lt;BR /&gt;- stop CDH and Cloudera Management Service&lt;/P&gt;&lt;P&gt;- copy aside one of your existing /etc/krb5.conf files (for later comparison)&lt;/P&gt;&lt;P&gt;- From the cluster drop-down in the Cloudera Manager home page, choose &lt;STRONG&gt;Deploy Kerberos Client Configuration &lt;/STRONG&gt;and deploy&lt;/P&gt;&lt;P&gt;- After the deploy is complete, start Cloudera Management Service and CDH&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If the issue still occurs, let us know.&lt;/P&gt;&lt;P&gt;You may also want to compare the previous and new /etc/krb5.conf files to see if there are difference.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Not sure what happened to cause this situation, but the steps should help (as you suggested).&lt;/P&gt;</description>
      <pubDate>Sun, 07 Jan 2018 20:26:38 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/CM-upgrade-stale-Kerberos-configuration/m-p/63381#M73137</guid>
      <dc:creator>bgooley</dc:creator>
      <dc:date>2018-01-07T20:26:38Z</dc:date>
    </item>
    <item>
      <title>Re: CM upgrade - stale Kerberos configuration</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/CM-upgrade-stale-Kerberos-configuration/m-p/63554#M73138</link>
      <description>&lt;P&gt;I stopped CDH and did a Kerberos configuration redeploy.&lt;/P&gt;&lt;P&gt;The /etc/krb5.conf is more or less the same.&lt;/P&gt;&lt;P&gt;The only difference is the last line "[domain_realm], it was added by the CM.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;After the redeploy the CDH started and now everything is in green&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Tomas&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;[libdefaults]
default_realm = MYREALM.LOCAL
dns_lookup_kdc = false
dns_lookup_realm = false
ticket_lifetime = 86400
renew_lifetime = 604800
forwardable = true
default_tgs_enctypes = aes256-cts aes128-cts
default_tkt_enctypes = aes256-cts aes128-cts
permitted_enctypes = aes256-cts aes128-cts
udp_preference_limit = 1
kdc_timeout = 3000
[realms]
MYREALM.LOCAL = {
kdc = 10.197.16.197 10.197.16.88
admin_server = 10.197.16.197 10.197.16.88
}
&lt;STRONG&gt;[domain_realm]

&lt;/STRONG&gt;&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 10 Jan 2018 17:15:05 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/CM-upgrade-stale-Kerberos-configuration/m-p/63554#M73138</guid>
      <dc:creator>Tomas79</dc:creator>
      <dc:date>2018-01-10T17:15:05Z</dc:date>
    </item>
    <item>
      <title>Re: CM upgrade - stale Kerberos configuration</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/CM-upgrade-stale-Kerberos-configuration/m-p/297764#M73139</link>
      <description>&lt;P&gt;I was not stoping cdh and cloudera management services&amp;nbsp; and deploying Kerberos configurations.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Now I stopped&amp;nbsp;cdh and cloudera management services and&amp;nbsp;deploying Kerberos configurations.&lt;BR /&gt;It worked for me and /etc/krb5.conf is updated for all hosts in cluster.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This issue resolved.&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 10 Jun 2020 09:42:15 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/CM-upgrade-stale-Kerberos-configuration/m-p/297764#M73139</guid>
      <dc:creator>ThriftTran</dc:creator>
      <dc:date>2020-06-10T09:42:15Z</dc:date>
    </item>
  </channel>
</rss>

