Our Community is getting an upgrade! To get everything ready for the relaunch, we’ll be placing the site in read-only mode starting September 21st.
We really appreciate your understanding while we get things set up behind the scenes. Catch up on all the exciting details about the move here.
Need help or have questions? Drop us a line at [email protected]
Created on
03-08-2020
03:26 PM
- last edited on
04-21-2026
04:32 AM
by
GrazittiAPI
Dear All,
I have ran into a very troublesome issue which is creating headache for the last 1 week. I installed and HDF Cluster(v3.4.1.1) with the services Nifi,Kafka,Metrics and Smart Sense. Everything was working perfectly until I decided to enable Kerberos(MIT) in the cluster. During the keberization, everything went fine till the last step.(Start and Test services). At that point, the Zookeeper server start got failed and thereafter no services are starting. The following is the error I got from the zookeeper logs.Any help is appreciated.
2020-03-06 18:38:51,489 - INFO [main:QuorumPeerMain@127] - Starting quorum peer
2020-03-06 18:38:51,552 - ERROR [main:QuorumPeerMain@89] - Unexpected exception, exiting abnormally
java.io.IOException: Could not configure server because SASL configuration did not allow the ZooKeeper server to authenticate itself properly:
javax.security.auth.login.LoginException: Message stream modified (41)
at org.apache.zookeeper.server.ServerCnxnFactory.configureSaslLogin(ServerCnxnFactory.java:207)
at org.apache.zookeeper.server.NIOServerCnxnFactory.configure(NIOServerCnxnFactory.java:87)
at org.apache.zookeeper.server.quorum.QuorumPeerMain.runFromConfig(QuorumPeerMain.java:130)
at org.apache.zookeeper.server.quorum.QuorumPeerMain.initializeAndRun(QuorumPeerMain.java:111)
at org.apache.zookeeper.server.quorum.QuorumPeerMain.main(QuorumPeerMain.java:78)
Note :
I tried setting the following resolutions that I found online. But nothing worked.
1. udp_preference_limit = 1
2. aes256-cts
aes128-cts
des3-hmac-sha1
arcfour-hmac
des-hmac-sha1
des-cbc-md5
des-cbc-crc
3.Regenerate Keytabs
Created 03-08-2020 10:33 PM
Issue resolved. Donno how it worked,but commenting out the following property in /etc/krb5.conf resolved the issue.
#renew_lifetime =7d
Same can be done through - Ambari-Services-Kerberos-Configs-Advanced krb5-conf- krb5-conf template.
Save the configuration and restart
Created 03-08-2020 10:33 PM
Issue resolved. Donno how it worked,but commenting out the following property in /etc/krb5.conf resolved the issue.
#renew_lifetime =7d
Same can be done through - Ambari-Services-Kerberos-Configs-Advanced krb5-conf- krb5-conf template.
Save the configuration and restart