Support Questions

Find answers, ask questions, and share your expertise

CDP Private Cluster Authentication Issue after upgrade

avatar
New Contributor

I am facing below error all jobs are failing because of this.

this is the error give guidance why it occurs because of this error all jobs failed also please share what other relevant information needed.

Data integration service failed to create DIM instance because of the following error:

jave.lang runtime exception java.IOException

[error while authentication with endpoint. https://sitlxdvdlap097/kms/v1?op=GETDELEGATIONTOKEN&doAs=k164prda&renewer=K164PRDA%40SAIBSIT.COM]
AUTHENTICATION FAILED, URL https://sitlxdvdlap097.saibsit.com:9494/kms/v1/?op==GETDELEGATIONTOKEN&doAs=k164prda&re

newer==K164PRDA%40SAIBSIT.COM&user.name=K164PRDA, status=403 message: null ]

2 REPLIES 2

avatar
Master Collaborator

Hello @Amr5 

Thank you for reaching out to the Cloudera Community

>> Could you please confirm the exact upgrade path you followed? Was it for CDP or CM?

>> Is your Ranger KMS working fine? We might need to check the Ranger KMS logs as well

>> 403 means request reached KMS but KMS refused it due to authentication or authorization. Can you check Ranger KMS audits as well? 

>> Also please verify the kerberos keytabs once as well by manually performing the kinit from latest process directory /var/run/cloudera-scm-agent/process/<Latest-Ranger-KMS> directory

 

>> Additionaly has anything changes with respect to TLS certificates

 

Also this issue might need a deep investigation so if you have Cloudera Support. license I would request you to raise a support case with Cloudera

 

Please help our community grow. If you found any of the suggestions/solutions provided helped you with solving your issue or answering your question, please take a moment to login and click "Accept as Solution" on one or more of them that helped.

Thank you

Kshitij Upadhyay

 

avatar
New Contributor

Hi Kshitij Upadhyay,

Thanks, 
>> Could you please confirm the exact upgrade path you followed? Was it for CDP or CM?

7.1.9 runtime
7.11.3 CM

upgraded to

7.3.1 runtime
7.13.1 CM

i will collect other information as well