Our Community is getting an upgrade! To get everything ready for the relaunch, we’ll be placing the site in read-only mode starting September 21st.
We really appreciate your understanding while we get things set up behind the scenes. Catch up on all the exciting details about the move here.
Need help or have questions? Drop us a line at [email protected]
Created 09-21-2017 08:04 AM
Hi I have is install HDP 2.5 and ambari 2.4. I have configured kdc server and then try to enable kerberos but my /etc/krb5.conf file getting change. And it gets failed with error
Command: [/usr/bin/kadmin, -s, abc.example.com, -p, root/[email protected], -r, example.COM, -q, get_principal root/[email protected]]
ExitCode: 1
STDOUT: Authenticating as principal root/[email protected] with password.
Password for root/[email protected]:
STDERR: kadmin: Cannot read password while initializing kadmin interface
21 Sep 2017 12:21:16,295 ERROR [ambari-client-thread-32897] KerberosHelperImpl:1861 - Cannot validate credentials: org.apache.ambari.server.AmbariException: Unexpected error condition executing the kadmin command
21 Sep 2017 12:21:16,296 ERROR [ambari-client-thread-32897] AbstractResourceProvider:285 - Caught AmbariException when creating a resource
Created 09-21-2017 10:29 AM
Notice krb5-auth-dialog is optional
Assuming you installed the KDC server
yum -y install krb5-server krb5-libs krb5-auth-dialog
Assuming you installed the KDC clients
yum -y install krb5-auth-dialog krb5-workstation
Your /etc/krb5.conf looks like below and copied to all the hosts in the cluster
[logging]
default = FILE:/var/log/krb5libs.log
kdc = FILE:/var/log/krb5kdc.log
admin_server = FILE:/var/log/kadmind.log
[libdefaults]
default_realm = EXAMPLE.COM
dns_lookup_realm = false
dns_lookup_kdc = false
ticket_lifetime = 24h
renew_lifetime = 7d
forwardable = true
[realms]
EXAMPLE.COM = {
kdc = kdc.examplecom
admin_server = kdc.examplecom
}
[domain_realm]
.example.com = EXAMPLE.COM
example.com = EXAMPLE.COMYour kdc.conf should resemble this
[kdcdefaults]
kdc_ports = 88
kdc_tcp_ports = 88
[realms]
EXAMPLE.COM = {
#master_key_type = aes256-cts
acl_file = /var/kerberos/krb5kdc/kadm5.acl
dict_file = /usr/share/dict/words
admin_keytab = /var/kerberos/krb5kdc/kadm5.keytab
supported_enctypes = aes256-cts:normal aes128-cts:normal des3-hmac-sha1:normal arcfour-hmac:normal des-hmac-sha1:normal des-cbc-md5:normal des-cbc-crc:normal
}You kadm5.acl in /var/kerberos/krb5kdc as below
*/[email protected] *
Can you create an admin principal as suit
# kadmin.local -q "addprinc admin/admin" Authenticating as principal admin/[email protected] with password. WARNING: no policy specified for admin/[email protected]; defaulting to no policy Enter password for principal "admin/[email protected]": Re-enter password for principal "admin/[email protected]": Principal "admin/[email protected]" created.
This is the principal you should use for the Ambari Kerberos,make sure you started the appropriate daemons below
Centos7/RHEL7
# systemctl start krb5kdc # systemctl start kadmin
Centos6/RHEL6
# systemctl start krb5kdc # systemctl start kadmin
All should be fine please let me know
Created 09-21-2017 10:29 AM
Notice krb5-auth-dialog is optional
Assuming you installed the KDC server
yum -y install krb5-server krb5-libs krb5-auth-dialog
Assuming you installed the KDC clients
yum -y install krb5-auth-dialog krb5-workstation
Your /etc/krb5.conf looks like below and copied to all the hosts in the cluster
[logging]
default = FILE:/var/log/krb5libs.log
kdc = FILE:/var/log/krb5kdc.log
admin_server = FILE:/var/log/kadmind.log
[libdefaults]
default_realm = EXAMPLE.COM
dns_lookup_realm = false
dns_lookup_kdc = false
ticket_lifetime = 24h
renew_lifetime = 7d
forwardable = true
[realms]
EXAMPLE.COM = {
kdc = kdc.examplecom
admin_server = kdc.examplecom
}
[domain_realm]
.example.com = EXAMPLE.COM
example.com = EXAMPLE.COMYour kdc.conf should resemble this
[kdcdefaults]
kdc_ports = 88
kdc_tcp_ports = 88
[realms]
EXAMPLE.COM = {
#master_key_type = aes256-cts
acl_file = /var/kerberos/krb5kdc/kadm5.acl
dict_file = /usr/share/dict/words
admin_keytab = /var/kerberos/krb5kdc/kadm5.keytab
supported_enctypes = aes256-cts:normal aes128-cts:normal des3-hmac-sha1:normal arcfour-hmac:normal des-hmac-sha1:normal des-cbc-md5:normal des-cbc-crc:normal
}You kadm5.acl in /var/kerberos/krb5kdc as below
*/[email protected] *
Can you create an admin principal as suit
# kadmin.local -q "addprinc admin/admin" Authenticating as principal admin/[email protected] with password. WARNING: no policy specified for admin/[email protected]; defaulting to no policy Enter password for principal "admin/[email protected]": Re-enter password for principal "admin/[email protected]": Principal "admin/[email protected]" created.
This is the principal you should use for the Ambari Kerberos,make sure you started the appropriate daemons below
Centos7/RHEL7
# systemctl start krb5kdc # systemctl start kadmin
Centos6/RHEL6
# systemctl start krb5kdc # systemctl start kadmin
All should be fine please let me know
Created 09-21-2017 03:16 PM
I have done same steps and got same error.
Created 10-03-2017 12:47 PM
My issue is resolved. I have configure KDC server on different machine. Thanks for the help...!!!