Support Questions

Find answers, ask questions, and share your expertise

KDC Server Connection is not available. Unable to login

avatar
Rising Star

Hi all,

 

I have a cluster in CDP version 7.1.8 private cloud base. The Cloudera Management service show bad health and indicate that the connection to KDC server is not available.

BrianChan_0-1683022713283.png

 

I can regenerate missing credentials under Administration > Security > Kerberos Credentials

BrianChan_1-1683022818395.png

 

Moreover, I can do kinit in the CM server host. Therefore I have no idea why the connection shows failure.

 

Please let me know if I should provide further information. Thank you.

2 ACCEPTED SOLUTIONS

avatar
Rising Star

I finally managed to solve the problem by switching the OpenJDK version from 8u362 to 8u232.

 

However, is OpenJDK 8u232 the only version that support when working on CDP 7.1.8 with Kerberos enabled?

 

Could someone clarify it for me please? Thank you.

View solution in original post

avatar
New Contributor

@venkatsambath 
I was able to resolve the error by adding all supported kerberos Encryption Types instead of only default 'rc4-hmac'.
FYI added : rc4-hmac aes256-cts aes128-cts des-cbc-crc des-cbc-md5

View solution in original post

8 REPLIES 8

avatar
Rising Star

From the system log, I found error saying unsupported Keytype. I am using OpenJDK 8u332.

BrianChan_0-1683097564199.png

Do anyone know how to solve this? Thank you.

 

avatar
Rising Star

I finally managed to solve the problem by switching the OpenJDK version from 8u362 to 8u232.

 

However, is OpenJDK 8u232 the only version that support when working on CDP 7.1.8 with Kerberos enabled?

 

Could someone clarify it for me please? Thank you.

avatar
New Contributor

I am seeing the same issue and cant seem to find a way around it on Private Cloud Base 7.1.9 with AD based kerberos.
JAVA SE jdk11 and krb5.conf is set according to https://docs.cloudera.com/cdp-private-cloud-base/7.1.8/security-kerberos-authentication/topics/cm-se...

CMSERVER:<fqdn>: KDC Server Connection is not available. Unable to login.

Appreciate any help I can get to resolve this error.

Thank you!

avatar

Can you share the exact error you notice in CM server log around the timeframe in which you notice the error 'CMSERVER:<fqdn>: KDC Server Connection is not available. Unable to login.', the full exception from cm server log will help to understand the issue better.

avatar
New Contributor

@venkatsambath 
I was able to resolve the error by adding all supported kerberos Encryption Types instead of only default 'rc4-hmac'.
FYI added : rc4-hmac aes256-cts aes128-cts des-cbc-crc des-cbc-md5

avatar
Community Manager

@hardik2909 If you are still experiencing the issue, can you provide the information @venkatsambath has requested? Thanks.


Regards,

Diana Torres,
Community Moderator


Was your question answered? Make sure to mark the answer as the accepted solution.
If you find a reply useful, say thanks by clicking on the thumbs up button.
Learn more about the Cloudera Community:

avatar
New Contributor

Hi @DianaTorres ,

I am facing the same issue. Can you please connect me with someone who can help me resolve this issue?

Thanks

avatar
Community Manager

@Aqdas Welcome to the Cloudera Community!

To help you get the best possible solution, I have tagged our Kerberos experts @venkatsambath @james_jones @pajoshi  who may be able to assist you further.


Regards,

Diana Torres,
Community Moderator


Was your question answered? Make sure to mark the answer as the accepted solution.
If you find a reply useful, say thanks by clicking on the thumbs up button.
Learn more about the Cloudera Community: