Our Community is getting an upgrade! To get everything ready for the relaunch, we’ll be placing the site in read-only mode starting September 21st.
We really appreciate your understanding while we get things set up behind the scenes. Catch up on all the exciting details about the move here.
Need help or have questions? Drop us a line at [email protected]
Created 10-04-2017 06:51 AM
Hi,
I've recently decomissioned a couple of hosts from a cluster (replaced with newer machines).
The cluster is using kerberos authentication managed via Cloudera Manager and I've noticed that the page listing all the available credentials (Administration -> Security -> Kerberos Credentials) continues to list the SPNs for the decomissioned machines.
Is there any way to clean them up?
I've searched in the documentation and I've only found this API endpoint https://cloudera.github.io/cm_api/apidocs/v17/path__cm_commands_deleteCredentials.html that deletes ALL the SPNs (I need to delete only the old ones).
Thanks
p.
Created 10-09-2017 09:39 AM
Hi parnigot,
You can try selecting those specific principals and clicking "Regenerate Selected". Alternatively, you could just go into the KDC or AD and delete the principals there.
Created 10-09-2017 09:39 AM
Hi parnigot,
You can try selecting those specific principals and clicking "Regenerate Selected". Alternatively, you could just go into the KDC or AD and delete the principals there.
Created 10-10-2017 03:51 AM
Hi h@cloudera,
I didn't know that the "Regenerate Selected" executed on a old SPN will simply delete it without recreating it.
Thanks for the tip!
p.
Created 10-10-2017 12:40 PM
Glad to help, @parnigot!