Support Questions

Find answers, ask questions, and share your expertise
Announcements
Check out our newest addition to the community, the Cloudera Data Analytics (CDA) group hub.

Kerberos on Cloudera 5.16 is failing (CDH5.16 on CentOS 7)

Explorer

Below is the error log after I have entered all the values.

Enable Kerberos for Cluster 1

Import KDC Account Manager Credentials Command
Status  Failed  Oct 11, 12:32:02 PM   5.04s 
/usr/share/cmf/bin/import_credentials.sh failed with exit code 1 and output of <<
+ export PATH=/usr/kerberos/bin:/usr/kerberos/sbin:/usr/lib/mit/sbin:/usr/sbin:/usr/lib/mit/bin:/usr/bin:/sbin:/usr/sbin:/bin:/usr/bin
+ PATH=/usr/kerberos/bin:/usr/kerberos/sbin:/usr/lib/mit/sbin:/usr/sbin:/usr/lib/mit/bin:/usr/bin:/sbin:/usr/sbin:/bin:/usr/bin
+ KEYTAB_OUT=/var/run/cloudera-scm-server/cmf7175218120539698971.keytab
+ USER=admin/admin@CLSECURITY.COM
+ PASSWD=REDACTED
+ KVNO=1
+ SLEEP=0
+ RHEL_FILE=/etc/redhat-release
+ '[' -f /etc/redhat-release ']'
+ set +e
+ grep Tikanga /etc/redhat-release
+ '[' 1 -eq 0 ']'
+ '[' 0 -eq 0 ']'
+ grep 'CentOS release 5' /etc/redhat-release
+ '[' 1 -eq 0 ']'
+ '[' 0 -eq 0 ']'
+ grep 'Scientific Linux release 5' /etc/redhat-release
+ '[' 1 -eq 0 ']'
+ set -e
+ '[' -z /var/run/cloudera-scm-server/krb586485986323377252.conf ']'
+ echo 'Using custom config path '\''/var/run/cloudera-scm-server/krb586485986323377252.conf'\'', contents below:'
+ cat /var/run/cloudera-scm-server/krb586485986323377252.conf
+ IFS=' '
+ read -a ENC_ARR
+ ktutil
+ for ENC in '"${ENC_ARR[@]}"'
+ echo 'addent -REDACTED -p admin/admin@CLSECURITY.COM -k 1 -e aes256-cts:normal'
+ '[' 0 -eq 1 ']'
+ echo REDACTED
+ for ENC in '"${ENC_ARR[@]}"'
+ echo 'addent -REDACTED -p admin/admin@CLSECURITY.COM -k 1 -e aes128-cts:normal'
+ '[' 0 -eq 1 ']'
+ echo REDACTED
+ for ENC in '"${ENC_ARR[@]}"'
+ echo 'addent -REDACTED -p admin/admin@CLSECURITY.COM -k 1 -e des3-hmac-sha1:normal'
+ '[' 0 -eq 1 ']'
+ echo REDACTED
+ echo 'wkt /var/run/cloudera-scm-server/cmf7175218120539698971.keytab'
addent: Bad encryption type while adding new entry
ktutil: Unknown request "REDACTED".  Type "?" for a request list.
addent: Bad encryption type while adding new entry
ktutil: Unknown request "REDACTED".  Type "?" for a request list.
addent: Bad encryption type while adding new entry
ktutil: Unknown request "REDACTED".  Type "?" for a request list.
+ chmod 600 /var/run/cloudera-scm-server/cmf7175218120539698971.keytab
chmod: cannot access `/var/run/cloudera-scm-server/cmf7175218120539698971.keytab': No such file or directory

 

[root@m1 ~]# cat /etc/krb5.conf

# Configuration snippets may be placed in this directory as well
#includedir /etc/krb5.conf.d/

[logging]
default = FILE:/var/log/krb5libs.log
kdc = FILE:/var/log/krb5kdc.log
admin_server = FILE:/var/log/kadmind.log

[libdefaults]
dns_lookup_realm = false
ticket_lifetime = 24h
renew_lifetime = 7d
forwardable = true
rdns = false
pkinit_anchors = /etc/pki/tls/certs/ca-bundle.crt
default_realm = CLSECURITY.COM
default_ccache_name = KEYRING:persistent:%{uid}

[realms]
CLSECURITY.COM = {
kdc = m1.bigdata.com
admin_server = m1.bigdata.com
}

[domain_realm]
.clsecurity.com = CLSECURITY.COM
clsecurity.com = CLSECURITY.COM

 

 

 

 

[root@m1 ~]# cat /var/kerberos/krb5kdc/kadm5.acl
*/admin@CLSECURITY.COM *
*admin/admin@CLSECURITY.COM *
*root/admin@CLSECURITY.COM *
[root@m1 ~]#cl156 a.jpgcl156 b.jpg

 

Attached the pictures of configuration

2 REPLIES 2

Mentor

@vsrikanth9 

 

The UI  and the contents of your krb5.conf look okay my only concern is the encryption types entries for the Kerberos encryption types field matches what your KDC supports, so can  look at the line

supported_enctypes =


Do you have a particular reason to have the 3 entries in /var/kerberos/krb5kdc/kadm5.acl the first line ONLY is enough

*/admin@CLSECURITY.COM *

 

Please do that and  revert 

Explorer

Hi Shelton,

Not sure it is a prerequisite or not, I will have to create another user Cloudera and put that in .acl file then Kerberos installed in CDH.  Strange thing it was on hold at the last step to restart the server for a couple of hours and then I closed it and trying to install again but it said Kerberos already installed... maybe CM trying to restart.  I think I have Kerberos in CDH now.  I will let you know if any issues.

 

Thanks for your quick help Shelton.

Take a Tour of the Community
Don't have an account?
Your experience may be limited. Sign in to explore more.