Support Questions
Find answers, ask questions, and share your expertise
Announcements
Alert: Welcome to the Unified Cloudera Community. Former HCC members be sure to read and learn how to activate your account here.

Failed to renew token: Kind: kms-dt during running Pig job

Solved Go to solution

Failed to renew token: Kind: kms-dt during running Pig job

Contributor

Dear all!

 

I have kerberized cluster on Cloudera Express 5.9.3, Java Version: 1.7.0_67.

Since I turned on HDFS Data At Rest Encryption using Java Keystore KMS I recieve an error in Pig job

 

 Failed to renew token: Kind: kms-dt, Service: 10.6.1.44:16000, Ident: (kms-dt owner=hdfs, renewer=yarn, realUser=, issueDate=1547451323413, maxDate=1548056123413, sequenceNumber=2, masterKeyId=2)

 

Yarn log:

 

Caused by: java.io.IOException: Keystore was tampered with, or password was incorrect

Caused by: java.security.UnrecoverableKeyException: Password verification failed

 

I have checked the pessword by doing keytool -list, the password is correct.

 

Please, help me to resolve this problem.

 

1 ACCEPTED SOLUTION

Accepted Solutions
Highlighted

Re: Failed to renew token: Kind: kms-dt during running Pig job

Contributor

Passwords for trust store and keystore must be the same. After changing the password for trust store everything went good.

1 REPLY 1
Highlighted

Re: Failed to renew token: Kind: kms-dt during running Pig job

Contributor

Passwords for trust store and keystore must be the same. After changing the password for trust store everything went good.