Our Community is getting an upgrade! To get everything ready for the relaunch, we’ll be placing the site in read-only mode starting September 21st. We really appreciate your understanding while we get things set up behind the scenes. Catch up on all the exciting details about the move here. Need help or have questions? Drop us a line at [email protected]
Created on 12-28-201611:05 PM - edited 08-17-201906:30 AM
HDP Environment:
Secure cluster (kerberos enabled)
Users managed by Active Directory (AD)
SYMPTOMS:
When user tries to access the Falcon UI with the following address, they are prompted to enter their username and password:
http://<falcon server host>:15000/index.html?user.name=admin#/
After entering the correct AD username and password, user gets this exception in the UI:
Using curl to negotiate with Falcon UI URL has no issues.
ROOT CAUSE: User is not using kerberos to authenticate
RESOLUTION: In order to access the Falcon UI after enabling kerberos, user needs to authenticate using SPNEGO to negotiate with kerberos not with a user name and password.
Each browser supports SPNEGO, but configuration is different for each browser. Safari needs no further configuration.
After configuring your browser to negotiate using SPNEGO, user must kinit and can try to access the Falcon UI again.