Support Questions
Find answers, ask questions, and share your expertise

Missing KDC administrator credentials. Please enter admin principal and password

Solved Go to solution
Highlighted

Re: Missing KDC administrator credentials. Please enter admin principal and password

Mentor

@Ankita Ghate

Find attached the tokenized version of my files.

Highlighted

Re: Missing KDC administrator credentials. Please enter admin principal and password

Ok.

You can check files which I have already attached in above comments. Absolute path of files are /etc/hosts, /etc/krb5.conf, /etc/krbkdc/kadm5.acl, /etc/krb5kdc/kdc.conf

PFA,

krb5conf.png

kdcconf.png

kadm5conf.png

hosts.png

Highlighted

Re: Missing KDC administrator credentials. Please enter admin principal and password

Mentor

@Ankita Ghate

The values look correct, I guess you are running ubuntu that's why the path differs a bit from my centos ! Can you start the equivalent of these services and retry

service krb5kdc start 
service kadmin start

Can you share the screenshot of the parameters you are using in the Enabling kerberos wizard ?


Highlighted

Re: Missing KDC administrator credentials. Please enter admin principal and password

@Geoffrey Shelton Okot

PFA for services restart,

services-restart.png

Highlighted

Re: Missing KDC administrator credentials. Please enter admin principal and password

Mentor

@Ankita Ghate

Now can you proceed with the kerberization check the 2 screenshots attached ensure your input values are correct.

Please revert


get-started.jpgget-started02.jpg
Highlighted

Re: Missing KDC administrator credentials. Please enter admin principal and password

All,

Thanks for your response. I found the root cause of this issue in my case, Ambari was using Ambari master key for KDC admin credentials which was present at /var/lib/ambari-server/keys/credentials.jceks. I have taken backup of it and was able to work on 'Enable kerberos through Ambari UI'.

But that previous file is required at the time of ambari-server restart. So need to keep ambari-master key same as KDC admin key (password).

PFA,

kerberos-admin-creds-issue-solved.png

Re: Missing KDC administrator credentials. Please enter admin principal and password

All,

Thanks for your response. I found the root cause of the issue. Ambari was using its master's key in KDC admin credentials that is why it was giving "Missing KDC administrator credentials. Please enter admin principal and password". So I have removed that crendential file (PFA for this) and issue has been solved.

For others, you may need to keep ambari master key and KDC admin creds same, because that file is required at the time of ambari-server restart (if you have configured jceks).

PFA,

kerberos-admin-creds-issue-solved.png

View solution in original post