Support Questions
Find answers, ask questions, and share your expertise
Announcements
Alert: Welcome to the Unified Cloudera Community. Former HCC members be sure to read and learn how to activate your account here.

Ambari Infra Solr UI error

Ambari Infra Solr UI error

Super Guru

On HDP 2.5 I am getting the follow error while pulling up SOLR Admin UI

HTTP ERROR 403

Problem accessing /solr/. Reason:

GSSException: Failure unspecified at GSS-API level (Mechanism level: Invalid argument (400) - Cannot find key of appropriate type to decrypt AP REP - AES256 CTS mode with HMAC SHA1-96)

I verified via klist -kte /etc/security/keytab/ambari-infra-solr.service.keytab and I see one with AES 256 HMAC SHA1-96

Any ideas?

4 REPLIES 4
Highlighted

Re: Ambari Infra Solr UI error

Can you validate your config in krb5.conf and your jce packages? Have you tried to regenerate the keytabs for ambari infra? hdfs, hive, etc. keytabs are ok ?

Re: Ambari Infra Solr UI error

Super Guru

@Jonas Straub Yes we have regenerated the keytabs from ambari. still not success.

Re: Ambari Infra Solr UI error

@Sunile Manjee It looks like this is an issue related to a change of the httpclient package. A possible workaround for this is to create a spnego keytab file that contains two principals, HTTP/ and HTTPS/.

You can use the ktutil (http://web.mit.edu/kerberos/krb5-1.12/doc/admin/admin_commands/ktutil.html) for that.

Re: Ambari Infra Solr UI error

Super Collaborator

@Jonas Straub @Sunile Manjee

I have the same problem here: (also on HDP2.5 / Ambari 2.4)

Error 403 GSSException: Failure unspecified at GSS-API level (Mechanism level: Invalid argument (400) - Cannot find key of appropriate type to decrypt AP REP - RC4 with HMAC)

JCE libraries are OK

krb5.conf has lines regarding encrytion libs uncommented:

 #default_tgs_enctypes = aes des3-cbc-sha1 rc4 des-cbc-md5
 #default_tkt_enctypes = aes des3-cbc-sha1 rc4 des-cbc-md5
Don't have an account?
Coming from Hortonworks? Activate your account here