Support Questions
Find answers, ask questions, and share your expertise

Kerberos encryption type is not one of the expected values

Solved Go to solution

Kerberos encryption type is not one of the expected values

Contributor

Hi all.

I'm facing a CM configuration error I can't understand.

I've kerberized a Cloudera 5.16 cluster which authenticates against an AD/DC controller.

I've set aes256-cts and aes256-cts-hmac-sha1-96 encryption types.

CM reports a configuration issue:

thumbnail_image001.jpg

I've a separate cluster, configured with the same values and authenticating to the same AD/DC controller, that have no errors.

 

I'm struggling on that error but can't solve.

 

Any idea?

 

 

1 ACCEPTED SOLUTION

Accepted Solutions

Re: Kerberos encryption type is not one of the expected values

Master Collaborator

@svasi @jackass  Just to close the loop. Yes Cloudera Manager will not recognize "AES" as a valid encryption type. These encryption types must match the permitted e-types listed in the /etc/krb5.conf file. We technically support what ever Kerberos supports, however the field validation only checks for cipher short names in this release. As such, if all is working well, you can safely ignore this alert.


Cheers!
Was your question answered? Make sure to mark the answer as the accepted solution.
If you find a reply useful, say thanks by clicking on the thumbs up button.

View solution in original post

4 REPLIES 4

Re: Kerberos encryption type is not one of the expected values

Master Collaborator

@svasi Are you getting the same error when providing one value in on box, I guess you should try that and see if this works. There might be some weird issue, try to restart CM server. 


Cheers!
Was your question answered? Make sure to mark the answer as the accepted solution.
If you find a reply useful, say thanks by clicking on the thumbs up button.

Re: Kerberos encryption type is not one of the expected values

New Contributor

@svasi 
Can you check and share your pseudonymized   /etc/krb5.conf?

Re: Kerberos encryption type is not one of the expected values

Contributor
I've tried to set a value at a time and restart CM.
Nothing changes

It seems to be a known bug on that CDH release
Had the opportunity to open a SR through my customer's account and support
answered that the message can be dismissed

Thanks for your answers

Re: Kerberos encryption type is not one of the expected values

Master Collaborator

@svasi @jackass  Just to close the loop. Yes Cloudera Manager will not recognize "AES" as a valid encryption type. These encryption types must match the permitted e-types listed in the /etc/krb5.conf file. We technically support what ever Kerberos supports, however the field validation only checks for cipher short names in this release. As such, if all is working well, you can safely ignore this alert.


Cheers!
Was your question answered? Make sure to mark the answer as the accepted solution.
If you find a reply useful, say thanks by clicking on the thumbs up button.

View solution in original post