Support Questions

Find answers, ask questions, and share your expertise

Upon enabling kerberos, Zookeeper doesn't start

Expert Contributor

On Sandbox 2.6.4 I am trying to enable kerberos with existing MS AD 2012R2. I hardly managed to enable it with minor issues and warnings. Could not configure server because SASL configuration did not allow the  ZooKeeper server to authenticate itself properly: Clock skew too great (37)

Following this I synced Sandbox and Server 2012R2. The tried again. But Zookeeper doesn't start with the same error.



@Erkan ŞİRİN

You issue looks the NTPD service ie The clock on you system (Linux/UNIX) is too far off from the correct time or not in sync wit the AD 2012R".

Your machine needs to be within less than 5 minutes of the Kerberos servers in order to get any tickets.

Expert Contributor

Thank you @Geoffrey Shelton Okot for your quick answer. You are right there was huge difference between LDAP server and Sandbox. I am aware of that. But I have fixed it and retried but the result is the same.

[root@sandbox-hdp ~]# service ntpd status
ntpd (pid  29267) is running...
[root@sandbox-hdp ~]# date
Wed May  9 09:44:22 +03 2018



@Erkan ŞİRİN

Can you repost the latest error ! And how I can reproduce it

Expert Contributor
Traceback (most recent call last):
  File "/var/lib/ambari-agent/cache/common-services/ZOOKEEPER/3.4.5/package/scripts/", line 134, in <module>
  File "/usr/lib/python2.6/site-packages/resource_management/libraries/script/", line 375, in execute
  File "/usr/lib/python2.6/site-packages/resource_management/libraries/script/", line 978, in restart
    self.start(env, upgrade_type=upgrade_type)
  File "/var/lib/ambari-agent/cache/common-services/ZOOKEEPER/3.4.5/package/scripts/", line 56, in start
    zookeeper_service(action='start', upgrade_type=upgrade_type)
  File "/usr/lib/python2.6/site-packages/ambari_commons/", line 89, in thunk
    return fn(*args, **kwargs)
  File "/var/lib/ambari-agent/cache/common-services/ZOOKEEPER/3.4.5/package/scripts/", line 51, in zookeeper_service
  File "/usr/lib/python2.6/site-packages/resource_management/core/", line 166, in __init__
  File "/usr/lib/python2.6/site-packages/resource_management/core/", line 160, in run
    self.run_action(resource, action)
  File "/usr/lib/python2.6/site-packages/resource_management/core/", line 124, in run_action
  File "/usr/lib/python2.6/site-packages/resource_management/core/providers/", line 262, in action_run
    tries=self.resource.tries, try_sleep=self.resource.try_sleep)
  File "/usr/lib/python2.6/site-packages/resource_management/core/", line 72, in inner
    result = function(command, **kwargs)
  File "/usr/lib/python2.6/site-packages/resource_management/core/", line 102, in checked_call
    tries=tries, try_sleep=try_sleep, timeout_kill_strategy=timeout_kill_strategy)
  File "/usr/lib/python2.6/site-packages/resource_management/core/", line 150, in _call_wrapper
    result = _call(command, **kwargs_copy)
  File "/usr/lib/python2.6/site-packages/resource_management/core/", line 303, in _call
    raise ExecutionFailed(err_msg, code, out, err)
resource_management.core.exceptions.ExecutionFailed: Execution of '/usr/bin/kinit -kt /etc/security/keytabs/smokeuser.headless.keytab ambari-qa-sandbox@HADOOP.COM;' returned 1. kinit: Clock skew too great while getting initial credentials

On Virtulabox+Sandbox 2.6.4

Enable kerberos

Ambari force you to stop all services

When starting all services Zookeeper gives error shown above.

Thank you @Geoffrey Shelton Okot good luck.


@Erkan ŞİRİN

Seeing your error above "kinit: Clock skew too great while getting initial credentials"

Correct me if I am wrong I see on your sandbox date output translates to date 09/05/2018 and time 09:44

# date
Wed May 9 09:44:22 +03 2018

But on the screenshot of your Windows time attached translates to date 02/05/2018 and the time 09:44 that's is 7 days difference

Please set your Windows 2012R2's date to the same date like the Sandbox its should work!!

Please let me know

Take a Tour of the Community
Don't have an account?
Your experience may be limited. Sign in to explore more.