<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>question Re: How can I fix this? Kerberos with AD (no local KDC) will not accept the admin user/password. in Archives of Support Questions (Read Only)</title>
    <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/How-can-I-fix-this-Kerberos-with-AD-no-local-KDC-will-not/m-p/95428#M8785</link>
    <description>&lt;P&gt;This appears to look correct.&lt;/P&gt;&lt;P&gt;Are we sure the realm name is correct and it is not something like "TCORP.COM"?  Realm names are case-sensitive, so make sure the realm name in AD is all uppercase characters.  I don't believe that the admin principal or password is trimmed, so make sure no (extra) spaces exist before or after them.&lt;/P&gt;&lt;P&gt;Also, does the admin user have delegated control over the specified LDAP container?&lt;/P&gt;&lt;P&gt;Can you take a look at the Ambari server log to see if any errors are posted there? &lt;/P&gt;</description>
    <pubDate>Wed, 14 Oct 2015 22:36:38 GMT</pubDate>
    <dc:creator>rlevas</dc:creator>
    <dc:date>2015-10-14T22:36:38Z</dc:date>
    <item>
      <title>How can I fix this? Kerberos with AD (no local KDC) will not accept the admin user/password.</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/How-can-I-fix-this-Kerberos-with-AD-no-local-KDC-will-not/m-p/95427#M8784</link>
      <description>&lt;P&gt;Before a production installation, we are testing the Kerberos install from the Sandbox to the client's Test Active Directory as a dry run. The entries in the KDC portion of the UI allow the "Test KDC Connection" to be successful.  But the Kerberos install fails after the "Next" button and a prompt appears asking for the correct Admin name/password combination.&lt;/P&gt;&lt;P&gt;The same connection info, when tried through Apache Directory Studio, gives a "Unable to obtain Principal Name for authentication" error.&lt;/P&gt;&lt;P&gt; The entries being used on the Kerberos setup page. &lt;/P&gt;&lt;UL&gt;
&lt;LI&gt;KDC:
&lt;UL&gt;
&lt;LI&gt;KDC host: ad.client.com&lt;/LI&gt;&lt;LI&gt;Realm name:TCORP&lt;/LI&gt;&lt;LI&gt;LDAP url: ldaps://ad.client.com&lt;/LI&gt;&lt;LI&gt;Container DN: ou=hadoop,ou=hdp,dc=client,dc=com&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;Kadmin
&lt;UL&gt;
&lt;LI&gt;Kadmin host: ad.client.com&lt;/LI&gt;&lt;LI&gt;Admin principal: &lt;A href="mailto:sandboxadmin@HORTONWORKS.COM" target="_blank"&gt;adminname@&lt;/A&gt;TCORP&lt;/LI&gt;&lt;LI&gt;Admin password: AD password for adminname&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;/UL&gt;</description>
      <pubDate>Fri, 16 Sep 2022 09:44:11 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/How-can-I-fix-this-Kerberos-with-AD-no-local-KDC-will-not/m-p/95427#M8784</guid>
      <dc:creator>TerryP</dc:creator>
      <dc:date>2022-09-16T09:44:11Z</dc:date>
    </item>
    <item>
      <title>Re: How can I fix this? Kerberos with AD (no local KDC) will not accept the admin user/password.</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/How-can-I-fix-this-Kerberos-with-AD-no-local-KDC-will-not/m-p/95428#M8785</link>
      <description>&lt;P&gt;This appears to look correct.&lt;/P&gt;&lt;P&gt;Are we sure the realm name is correct and it is not something like "TCORP.COM"?  Realm names are case-sensitive, so make sure the realm name in AD is all uppercase characters.  I don't believe that the admin principal or password is trimmed, so make sure no (extra) spaces exist before or after them.&lt;/P&gt;&lt;P&gt;Also, does the admin user have delegated control over the specified LDAP container?&lt;/P&gt;&lt;P&gt;Can you take a look at the Ambari server log to see if any errors are posted there? &lt;/P&gt;</description>
      <pubDate>Wed, 14 Oct 2015 22:36:38 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/How-can-I-fix-this-Kerberos-with-AD-no-local-KDC-will-not/m-p/95428#M8785</guid>
      <dc:creator>rlevas</dc:creator>
      <dc:date>2015-10-14T22:36:38Z</dc:date>
    </item>
    <item>
      <title>Re: How can I fix this? Kerberos with AD (no local KDC) will not accept the admin user/password.</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/How-can-I-fix-this-Kerberos-with-AD-no-local-KDC-will-not/m-p/95429#M8786</link>
      <description>&lt;P&gt;We are able to authenticate with the settings from above.  We dug further and see an error with creating the principals on the AD side.  It looks like the full control over the OU is not in place.&lt;/P&gt;</description>
      <pubDate>Thu, 15 Oct 2015 22:27:44 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/How-can-I-fix-this-Kerberos-with-AD-no-local-KDC-will-not/m-p/95429#M8786</guid>
      <dc:creator>TerryP</dc:creator>
      <dc:date>2015-10-15T22:27:44Z</dc:date>
    </item>
  </channel>
</rss>

