Reply
Highlighted
Explorer
Posts: 7
Registered: ‎03-22-2019

impala kerberos issues

[ Edited ]

Hi All - we have added disk space to the all the nodes in our cluster and restarted each node. after the restart everything is working fine now and Impala from Hue browser is also working but we have a haproxy configured on one node for impala for applications from applications to connect - this is not working.

these are the logs we see on the impala daemons. Please suggest how this can be resolved.

Thanks in advance.

Explorer
Posts: 7
Registered: ‎03-22-2019

Re: impala kerberos issues

these are the errors on logs: 

SASL message (Kerberos (external)): GSSAPI Error: Unspecified GSS failure. Minor code may provide more information (Wrong principal in request)
TThreadPoolServer: Caught TException: SASL(-13): authentication failure: GSSAPI Failure: gss_accept_sec_context

Posts: 1,035
Topics: 1
Kudos: 258
Solutions: 128
Registered: ‎04-22-2014

Re: impala kerberos issues

@IVenkatesh,

 

Make sure your applications are connecting to the HAProxy server and not directly to the Impala daemons themselves.  If you have configured a load balancer, you'll need to use it in order to authenticate via Kerberos.

See if that works... if not, then let us know.

Explorer
Posts: 7
Registered: ‎03-22-2019

Re: impala kerberos issues

Hi bgooley - thank you for the response.

we checked and can see on haproxy logs that applications are connecting proxy and not to daemons directly.

on cloudera manager Impala Daemons Load Balancer properties , i see proxy server and port is configured on executors section. please advise if there is anything else to be verified.

Announcements