Support Questions
Find answers, ask questions, and share your expertise
Announcements
Alert: Welcome to the Unified Cloudera Community. Former HCC members be sure to read and learn how to activate your account here.

LDAP: error code 49 when setting LDAP auth for HiveServer2

Solved Go to solution

LDAP: error code 49 when setting LDAP auth for HiveServer2

Expert Contributor

Hello Gurus :) HDP 2.3.2 Ambari 2.1.2.1

I'm trying to setup HiveServer2 with LDAP authentication. It seems pretty straightforward: I performed the following: Changed HiveServer2 Authentication to LDAP

1954-1.png Then i setup my LDAP server url (as the Ambari requested): 1955-2.png Restarted the Hive but hiveserver2.log shows the following during it's startup: ERROR [HiveServer2-Handler-Pool: Thread-56]: transport.TSaslTransport (TSaslTransport.java:open(315)) - SASL negotiation failure javax.security.sasl.SaslException: Error validating the login [Caused by javax.security.sasl.AuthenticationException: Error validating LDAP user [Caused by javax.naming.AuthenticationException: [LDAP: error code 49 - 80090308: LdapErr: DSID-0C0903A9, comment: AcceptSecurityContext error, data 52e, v1db1]]]

According to the error LDAP 49 - 52e the problem is with the credentials that were passed to the LDAP server. I don't find any field \ parameter in which i set the LDAP user & password for authentication... Needless to say that the authentication acts as if it is set to NONE (which is a major problem....)

Any ideas ? Thanks in advance Adi J.

1 ACCEPTED SOLUTION

Accepted Solutions

Re: LDAP: error code 49 when setting LDAP auth for HiveServer2

@Adi Jabkowsky

Is this happening when HS2 is started ONLY or when you connect via Beeline or both?

Try the following:

  1. Your hive.server2.authentication.ldap.baseDN has a blank space. Remove the blank space and restart HS2 from Hosts in Ambari
    #From
    <property>
    <name>hive.server2.authentication.ldap.baseDN</name>
    <value> </value>
    </property>
    
    #To
    <property>
    <name>hive.server2.authentication.ldap.baseDN</name>
    <value></value>
    </property>
  2. Remove hive.server2.authentication.ldap.Domain or set to Blank. Then log into HS2 using beeline and set your user to myuser@corp.cellcom.co.il as your login and see if it authenticates
  3. Set hive.server2.enable.doAs to False so that Hive user executes the query,
  4. If you are using a Hive AD user, Double check that the hive AD UID is the same in /etc/passwd file. Make an archive of HS2 Logs, change /etc/passwd to have the same UUID as the AD hive user, and restart HS2.
39 REPLIES 39

Re: LDAP: error code 49 when setting LDAP auth for HiveServer2

Expert Contributor

Re: LDAP: error code 49 when setting LDAP auth for HiveServer2

@Adi Jabkowsky Looking into it ;)

Re: LDAP: error code 49 when setting LDAP auth for HiveServer2

Re: LDAP: error code 49 when setting LDAP auth for HiveServer2

@Adi Jabkowsky

You should use beeline and provide ldap username and password during the authentication.

Re: LDAP: error code 49 when setting LDAP auth for HiveServer2

Expert Contributor
@Neeraj Sabharwal The beeline in the documentation is just an example for how to test the configuration.

My problem is when i use third party querying tools such as SQLdeveloper (or even IBM cognos) - i'm able to connect to the hive, see tables and query - without providing any password or with providing wrong password (As if the Security is set to NONE).

Re: LDAP: error code 49 when setting LDAP auth for HiveServer2

Expert Contributor

The HiveServer2 acts the same if the security is set to LDAP or NONE, and it shouldn't. When set to NONE - as long as my user has authorization for a specific table - i can query it without authentication against LDAP. (hence - NONE. no Authentication needed). When set to LDAP, if setup is correct, i won't be able to query anything without connecting using my credentials.

Re: LDAP: error code 49 when setting LDAP auth for HiveServer2

Expert Contributor

During the HiveServer2 startup i see that error in the log (52e) - so HiveServer2 has some sort of configuration problem regarding LDAP. There must be a property in which i setup a user & password for HS2 to check authentication against LDAP but i can't find any...

(I've managed to configure Ambari to use LDAP, and HUE to use LDAP, and even Ranger's user sync - all of them use a manager DN or a bind DN. But where is this value in HS2 config ??

Re: LDAP: error code 49 when setting LDAP auth for HiveServer2

@Adi Jabkowsky

adldap.txt

See if you can set this up

Re: LDAP: error code 49 when setting LDAP auth for HiveServer2

@Adi Jabkowsky

Can you send me your hive-site.xml?

Don't have an account?
Coming from Hortonworks? Activate your account here