Probably a better question for the Ambari mailing lists. https://ambari.apache.org/mail-lists.html Also lots of issues tagged in the Ambari JIRA for 3.0.0 - https://issues.apache.org/jira/browse/AMBARI-23611?jql=project%20%3D%20AMBARI%20AND%20fixVersion%20%3D%203.0.0
... View more
I am trying to kerberize an Ambari (2.6.0) Hadoop (HDP 126.96.36.199) cluster. I have IPA and was not able to get the Ambari Automatic config to work so I have moved on to the "Manual" process.... which I am also running into problems. Ambari Server is running as root. I also have an ambari user that is in IPA that has passwordless sudo access to all hosts. root on ambari server also has passwordless ssh access to all hosts(Is this needed?) Here are my questions: 1) If doing the manual procedure does one still need to enable the IPA experimental feature? 2) Does Ambari Server need to be configured to run as a non-root user or can we kerberize and still have ambari server run as root? 3) If I do want to have Kerberos princs that include the cluster name... Do the USER Kerberos princs have to be the same as the local unix user names and do these Kerberos USER princs need to match anything else in the Ambari configuration? For example if I create an hdfs-clustername USER princ do the SERVICE keytabs in /etc/security/keytabs then need to be owned by the Kerberos USER or just by the local user name? I am using the process in article https://community.hortonworks.com/articles/811/manual-keytab-principal-creation-for-ipa-to-suppor.html and it is not working.
... View more