Options
- Subscribe to RSS Feed
- Mark as New
- Mark as Read
- Bookmark
- Subscribe
- Printer Friendly Page
- Report Inappropriate Content
Contributor
Created on
09-28-2020
11:49 AM
- edited on
10-06-2020
05:35 AM
by
VidyaSargur
Zookeeper does not allow listing or editing znodes if the current ACL doesn't have a set of permissions for the user or group. This is observed as a security authentication of znodes in all Cloudera Distros inherited from Apache Zookeeper. There are few references for the workaround, just compiling them together for Cloudera Managed clusters.
For the following error:
Authentication is not valid
There are two ways to address them:
- Disable any ACL validation in Zookeeper (Not recommended):
- Add the following config in CM > Zookeeper config > Search for 'Java Configuration Options for Zookeeper Server':
-Dzookeeper.skipACL=yes
- Then Restart and refresh the stale configs.
- Add the following config in CM > Zookeeper config > Search for 'Java Configuration Options for Zookeeper Server':
- Add a Zookeeper super auth:
- Skip the part added in <SKIP> if you want to use ‘password' as the auth key.
<SKIP>
Use the last line from the following output on running the above command :cd /opt/cloudera/parcels/CDH/lib/zookeeper/ java -cp "./zookeeper.jar:lib/*" org.apache.zookeeper.server.auth.DigestAuthenticationProvider super:password
</SKIP>SLF4J: Failed to load class "org.slf4j.impl.StaticLoggerBinder". SLF4J: Defaulting to no-operation (NOP) logger implementation SLF4J: See http://www.slf4j.org/codes.html#StaticLoggerBinder for further details. super:password->super:DyNYQEQvajljsxlhf5uS4PJ9R28=
- Add the following config in CM > Zookeeper config > Search 'Java Configuration Options for Zookeeper Server':
-Dzookeeper.DigestAuthenticationProvider.superDigest=super:DyNYQEQvajljsxlhf5uS4PJ9R28=
- Restart and refresh the stale configs.
- Once connected to zookeeper-client, add the following command before executing any further command:
addauth digest super:password
- You will be able to run any operation on any znode post this command.
- Skip the part added in <SKIP> if you want to use ‘password' as the auth key.
NOTE:
- Version of slf4j-api may differ on later builds.
- Update the super password to any string you desire. <password>
5,548 Views