Created 03-08-2021 06:03 AM
Hi all.
I'm facing a CM configuration error I can't understand.
I've kerberized a Cloudera 5.16 cluster which authenticates against an AD/DC controller.
I've set aes256-cts and aes256-cts-hmac-sha1-96 encryption types.
CM reports a configuration issue:
I've a separate cluster, configured with the same values and authenticating to the same AD/DC controller, that have no errors.
I'm struggling on that error but can't solve.
Any idea?
Created 04-09-2021 01:34 AM
@svasi @jackass Just to close the loop. Yes Cloudera Manager will not recognize "AES" as a valid encryption type. These encryption types must match the permitted e-types listed in the /etc/krb5.conf file. We technically support what ever Kerberos supports, however the field validation only checks for cipher short names in this release. As such, if all is working well, you can safely ignore this alert.
Created 03-09-2021 11:26 PM
@svasi Are you getting the same error when providing one value in on box, I guess you should try that and see if this works. There might be some weird issue, try to restart CM server.
Created 03-10-2021 12:44 PM
@svasi
Can you check and share your pseudonymized /etc/krb5.conf?
Created 04-08-2021 11:36 PM
Created 04-09-2021 01:34 AM
@svasi @jackass Just to close the loop. Yes Cloudera Manager will not recognize "AES" as a valid encryption type. These encryption types must match the permitted e-types listed in the /etc/krb5.conf file. We technically support what ever Kerberos supports, however the field validation only checks for cipher short names in this release. As such, if all is working well, you can safely ignore this alert.