Member since
01-19-2017
3679
Posts
632
Kudos Received
372
Solutions
My Accepted Solutions
| Title | Views | Posted |
|---|---|---|
| 804 | 06-04-2025 11:36 PM | |
| 1379 | 03-23-2025 05:23 AM | |
| 686 | 03-17-2025 10:18 AM | |
| 2479 | 03-05-2025 01:34 PM | |
| 1616 | 03-03-2025 01:09 PM |
10-05-2017
11:00 AM
@Adil Muganlinsky Please can you have a look at these examples you are missing the hiveserver2 binary or HTTP ports in your connect string ! Hope that helps
... View more
10-05-2017
10:07 AM
@Pooja Kamle Ranger admin in HDP 2.5 has a new property for a truststore. So if using ldaps, you need to import the ldapserver cert to the ranger admin truststore , property name ranger.truststore.file. Although no log is being showed for failed connection to ldapserver, setting ranger to debug will show that ranger admin is not able to establish SSL connection to ldap server and there by not able to validate the user login. usersync has similar property ranger.usersync.truststore.file which must already have ldap server cert in it,is usersync is working correctly?. If not use the same truststore file for ranger.truststore.file Make sure that you set the UserSearchFilter as sAMAccountName={0} if using AD for ldap accounts.
... View more
10-05-2017
08:31 AM
@Pooja Kamle Then I think you missed to toggle the Ranger Authentication to AD as shown in the attached screenshot Ambari UI--->Ranger--->Configs--->Advanced--->AD Revert
... View more
10-04-2017
06:53 PM
@Andres Urrego Some laptops/desktop you might need to enable virtualization Please go through theses steps Power on the machine and open the BIOS (as per Step 1). Open the Processor submenu The processor settings menu may be hidden in the Chipset, Advanced CPU Configuration or Northbridge. Enable Intel Virtualization Technology (also known as Intel VT) or AMD-V depending on the brand of the processor.
... View more
10-04-2017
06:47 PM
@D Giri Did you by chance download the CSV file with the keytabs for manual creation? There is an option to ONLY regenerate keytabs for missing hosts and components !! Did you correctly key in the user/passowrd in the Ambari-Kerberos wizard? Could you briefly describe your cluster setup? Master/slave and where the KDC is installed? Make sure the [realms] and [domain_realms] entries in /etc/krb5.conf is correct.
Validate the contents of these 2 files /var/kerberos/krb5kdc/kdc.conf , /var/kerberos/krb5kdc/kadm5.acl Can you share the contents of the above file don't forget to scramble site specific information
... View more
10-04-2017
05:56 PM
@arjun more If you have KDC and AD integrated, this simply means the account to which the keytab is related has been disabled, locked, expired, or deleted. The AD service account should NEVER expire. If not could you validate the below steps Make sure the [realms] and [domain_realms] entries in cat /etc/krb5.conf is correct. Validate the contents of these 2 files /var/kerberos/krb5kdc/kdc.conf , /var/kerberos/krb5kdc/kadm5.acl Check the hdfs prinncipal # kadmin.local
Authenticating as principal hdfs-uktehdpprod/admin@EUROPE.ODCORP.NET with password.
kadmin.local: listprincs hdfs*
hdfs-uktehdpprod@EUROPE.ODCORP.NET
kadmin.local: Get the correct prncipal for hdfs # klist -kt /etc/security/keytabs/hdfs.headless.keytab
Keytab name: FILE:/etc/security/keytabs/hdfs.headless.keytab
KVNO Timestamp Principal ---- ------------------- ------------------------------------------------------
1 08/24/2017 15:42:23 hdfs-uktehdpprod@EUROPE.ODCORP.NET
1 08/24/2017 15:42:23 hdfs-uktehdpprod@EUROPE.ODCORP.NET
1 08/24/2017 15:42:23 hdfs-uktehdpprod@EUROPE.ODCORP.NET Try grabbing a valid Kerberos ticket # kinit -kt /etc/security/keytabs/hdfs.headless.keytab hdfs-uktehdpprod@EUROPE.ODCORP.NET Validate the avalability period # klist
Ticket cache: FILE:/tmp/krb5cc_0
Default principal: hdfs-uktehdpprod@EUROPE.ODCORP.NET
Valid starting Expires Service principal
10/04/2017 19:36:12 10/05/2017 19:36:12 krbtgt/EUROPE.ODCORP.NET@EUROPE.ODCORP.NET Please revert
... View more
10-03-2017
10:53 AM
@D Giri HDP 2.6 has a new feature called Service Auto start see Ambaru UI-->admin-> Service Auto Start Can you validate that the component status ? Or the Auto start Services status should be either enabled/disabled Can you also check the KDC if the principals are createdCan you also check in the KDC # kadmin.local
kadmin.local: listprincs Are you running Ambari as root if not then that user MUST authorization to write to /var/lib/ambari-server/tmp. Please revert
... View more
09-30-2017
10:48 PM
@Prakash Punj Can you check that the Ambari-agent is running on your Ambari host? Did you also upgrade the Ambari agents? The ambari-agents versions should match the ambari-server version 🙂 Run this command on all the nodes and make sure their output match ! # yum list installed | grep ambari Once you have the same versions then restart all the ambari-agent # ambari-agent restart Hope this resolves your lost heartbeat problem.
... View more
09-30-2017
04:58 PM
@ashim sinha Here is a good document that you use as a reference. Let me know
... View more
09-30-2017
11:22 AM
@Sree Kupp I see you are attempting something that is taken care of by real HA setup with active and standby namenode, you can use below command to force failover. $ hdfs haadmin -failover Let me know whether that helps
... View more