Member since
10-14-2016
35
Posts
14
Kudos Received
0
Solutions
10-30-2017
12:19 PM
1 Kudo
Also works for me after some experiments: yarn.admin.acl=yarn,dr.who,<AD LOGIN IN UPPERCASE WITHOUT REALM>
... View more
10-30-2017
11:42 AM
Your settings solve the problem. I have default values yarn.admin.acl=yarn,dr.who
yarn.acl.enable=true
hadoop.http.staticuser.user = yarn
... View more
10-30-2017
10:33 AM
Hello! I have HDP 2.5 cluster with KERBEROS enabled, connected to Active Directory. When I try to switch on HTTP AUTH - https://docs.hortonworks.com/HDPDocuments/HDP2/HDP-2.6.2/bk_security/content/_configuring_http_authentication_for_HDFS_YARN_MapReduce2_HBase_Oozie_Falcon_and_Storm.html Logs can be retrived using shell yarn logs -applicationId application_1509115509826_0001 I can't access any logs from YARN UI for example <YARN-RM-HOST>:19888/jobhistory/logs/<NODE>:45454/container_e56_1509115509826_0001_01_000001/container_e56_1509115509826_0001_01_000001/hive With following error: User <MY Active Directory User> is not authorized to view the logs for container_e56_1509115509826_0001_01_000001 in log file [<NODE>_45454_1509118017724]No logs available for container container_e56_1509115509826_0001_01_000001
... View more
Labels:
- Labels:
-
Apache YARN
10-10-2017
06:36 PM
Thanks! Which keytab I should use to get access to this Zookepper Node (kerberized cluster)? Is it possible to use ZooKeeper Java API to get same info?
... View more
10-10-2017
01:21 PM
3 Kudos
Is it possible to identify active YARN ResourceManager using ZooKeeper or any other method?
... View more
Labels:
- Labels:
-
Apache YARN
06-01-2017
07:59 AM
@spolavarapu thank! It is exactly my case
... View more
05-31-2017
08:54 AM
@spolavarapu Filter on user was there for ages. And a short time ago sync user from groups task appears and looks like the filter prevent user from sync
... View more
05-29-2017
08:54 AM
Thanks, all! I have all settings in place but was not sure that it is correct. Only thing that prevent from correct sync was User Filter where I restrict only exact user list and new users for groups can't be synced into Ranger because of filter
... View more
05-26-2017
08:13 AM
Hi, all! Environment: RHEL 7.2 + Winbind HDP 2.5 Ranger 0.6.0.2.5 AD: Windows 2008 R2 Server User sync and group sync configured. QUESTION: I have some groups in AD with users inside. User in group pointed as member=CN=FirstName LastName, DN=EXAMPLE, DN=COM Exactly the same FirstName LastName synced inside Ranger while usersync working. However Ranger use sAMAccountName in policy and sAMAccountName came from Kerberos. Is it possible to sync user from groups with sAMAccountName instead of CN?
... View more
Labels:
10-24-2016
03:09 PM
Thanks for help! Issue gone after ambari-server reatrt. Don't know what was the root cause. BTW I've done all steps from your article
... View more