<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>question Re: Enabling TLS/SSL and Kerberos for a single-user Cloudera Manager setup in Archives of Support Questions (Read Only)</title>
    <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Enabling-TLS-SSL-and-Kerberos-for-a-single-user-Cloudera/m-p/64346#M74255</link>
    <description>&lt;P&gt;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/25370"&gt;@PrashantAgrawal&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You need to either have your &lt;STRONG&gt;DataNode HTTP Web UI Port&lt;/STRONG&gt; and &lt;STRONG&gt;DataNode Transceiver Port&lt;/STRONG&gt; set to privileged ports or you need to do that or configure TLS to protect the HDFS connections.&lt;/P&gt;&lt;P&gt;If you configured Kerberos via Cloudera Manager, the wizard would have made the port changes for you.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 05 Feb 2018 17:51:59 GMT</pubDate>
    <dc:creator>bgooley</dc:creator>
    <dc:date>2018-02-05T17:51:59Z</dc:date>
    <item>
      <title>Enabling TLS/SSL and Kerberos for a single-user Cloudera Manager setup</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Enabling-TLS-SSL-and-Kerberos-for-a-single-user-Cloudera/m-p/64291#M74254</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am setting up TLS/SSL and Kerberos on a single-user setup of Cloudera Manager. The cloudera Manager version used is 5.12 and the underlying CDH parcel is 5.11.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Kerberors setup is done using MIT KDC and TLS/SSL is configured upto Level 1. After doing this, when I restart CM, Agents and HDFS I see that the HDFS doesn't restart. The error is as below:&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;5:49:39.498 PM&lt;/TD&gt;&lt;TD&gt;FATAL&lt;/TD&gt;&lt;TD&gt;DataNode&lt;/TD&gt;&lt;TD&gt;&lt;PRE&gt;Exception in secureMain
java.lang.RuntimeException: Cannot start secure DataNode without configuring either privileged resources or SASL RPC data transfer protection and SSL for HTTP.  Using privileged resources in combination with SASL RPC data transfer protection is not supported.
	at org.apache.hadoop.hdfs.server.datanode.DataNode.checkSecureConfig(DataNode.java:1333)
	at org.apache.hadoop.hdfs.server.datanode.DataNode.startDataNode(DataNode.java:1233)
	at org.apache.hadoop.hdfs.server.datanode.DataNode.&amp;lt;init&amp;gt;(DataNode.java:464)
	at org.apache.hadoop.hdfs.server.datanode.DataNode.makeInstance(DataNode.java:2545)
	at org.apache.hadoop.hdfs.server.datanode.DataNode.instantiateDataNode(DataNode.java:2432)
	at org.apache.hadoop.hdfs.server.datanode.DataNode.createDataNode(DataNode.java:2479)
	at org.apache.hadoop.hdfs.server.datanode.DataNode.secureMain(DataNode.java:2661)
	at org.apache.hadoop.hdfs.server.datanode.DataNode.main(DataNode.java:2685)&lt;/PRE&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;After searching for a probable solution on Google, I stumbled upon a link that asks to do additional configuration for single-user seutps. The section '&lt;/P&gt;&lt;P&gt;Configuration for Secure Clusters' talks about the additional 4 steps to be performed.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.cloudera.com/documentation/enterprise/5-11-x/topics/install_singleuser_reqts.html" target="_blank"&gt;https://www.cloudera.com/documentation/enterprise/5-11-x/topics/install_singleuser_reqts.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have performed the steps of HDFS with TLS but not sure what to do for the remaining two :&amp;nbsp;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Do not configure the DataNode Transceiver port and HTTP Web UI port to use privileged ports.&lt;/LI&gt;&lt;LI&gt;Configure DataNode data transfer protection.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please suggest what is the expectation for these 2 steps in single-user mode.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 03 Feb 2018 18:24:23 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Enabling-TLS-SSL-and-Kerberos-for-a-single-user-Cloudera/m-p/64291#M74254</guid>
      <dc:creator>PrashantAgrawal</dc:creator>
      <dc:date>2018-02-03T18:24:23Z</dc:date>
    </item>
    <item>
      <title>Re: Enabling TLS/SSL and Kerberos for a single-user Cloudera Manager setup</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Enabling-TLS-SSL-and-Kerberos-for-a-single-user-Cloudera/m-p/64346#M74255</link>
      <description>&lt;P&gt;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/25370"&gt;@PrashantAgrawal&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You need to either have your &lt;STRONG&gt;DataNode HTTP Web UI Port&lt;/STRONG&gt; and &lt;STRONG&gt;DataNode Transceiver Port&lt;/STRONG&gt; set to privileged ports or you need to do that or configure TLS to protect the HDFS connections.&lt;/P&gt;&lt;P&gt;If you configured Kerberos via Cloudera Manager, the wizard would have made the port changes for you.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 05 Feb 2018 17:51:59 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Enabling-TLS-SSL-and-Kerberos-for-a-single-user-Cloudera/m-p/64346#M74255</guid>
      <dc:creator>bgooley</dc:creator>
      <dc:date>2018-02-05T17:51:59Z</dc:date>
    </item>
    <item>
      <title>Re: Enabling TLS/SSL and Kerberos for a single-user Cloudera Manager setup</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Enabling-TLS-SSL-and-Kerberos-for-a-single-user-Cloudera/m-p/64358#M74256</link>
      <description>&lt;P&gt;Thanks for the reply. HDFS started in green after making the below changes.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;DataNode HTTP Web UI Port - 50075&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Secure DataNode Web UI Port (TLS/SSL) -&amp;nbsp;50475&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;DataNode Transceiver Port - 50010&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;DataNode Data Transfer Protection - Authentication&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 06 Feb 2018 01:51:15 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Enabling-TLS-SSL-and-Kerberos-for-a-single-user-Cloudera/m-p/64358#M74256</guid>
      <dc:creator>PrashantAgrawal</dc:creator>
      <dc:date>2018-02-06T01:51:15Z</dc:date>
    </item>
  </channel>
</rss>

