I just kerberized my cluster and hue kerberos ticket renewer is throwing below error
Couldn't renew kerberos ticket in order to work around Kerberos 1.8.1 issue. Please check that the ticket for 'hue/fqdn@EQ.COM' is still renewable: $ kinit -f -c /tmp/hue_krb5_ccache If the 'renew until' date is the same as the 'valid starting' date, the ticket cannot be renewed. Please check your KDC configuration, and the ticket renewal policy (maxrenewlife) for the 'hue/fqdn@EQ.COM' and `krbtgt' principals.
If I run the command, its prompting for password which I don't know for hue. I am not able to see renew time from below command either.
while I was kerberizing the cluster, it was starting the service one by one. Impala failed before Hue. So it never got to the point of starting hue. Since all services were running except for Impala and Hue. I proceeded with error, thinking I will start hue separately, perhaps it was a dumb move but the installation was stuck at that point so I had to move forward with error. Ever since that, I am seeing the error for hue. I removed Impala completely from cluster.
Removed and added hue in different nodes, still KTR fails. Is there a way to solve this ?
If the Hue Kerberos Ticket Renewer does not start, check your KDC configuration and the ticket renewal property, maxrenewlife, for the hue/<hostname> and krbtgt principals to ensure they are renewable. If not, running the following commands on the KDC will enable renewable tickets for these principals: