Member since
10-19-2016
34
Posts
1
Kudos Received
1
Solution
My Accepted Solutions
Title | Views | Posted |
---|---|---|
2689 | 04-03-2017 12:12 PM |
10-06-2020
10:46 AM
Following KB can be used to delete users/groups in bulk https://community.cloudera.com/t5/Community-Articles/Remove-AD-LDAP-accounts-from-Ambari-using-REST-API/tac-p/244196
... View more
03-09-2017
03:15 PM
I forgot...this looks clearly like an devops error and / or broken installation.
... View more
10-20-2016
07:19 AM
Thanks VERY much, Eyad! *Lifts up Finger* To the Console
... View more
02-16-2017
10:51 AM
Some Comments in 2017:-) The Process i most of the time correct but i have a few more information on this: 1. Kerberos Cache Mechanisms: Depending on your line: [libdefaults]
default_ccache_name you have various odd behaviors, when not seeing your Kerberos Ticket in your Kerberos Ticket Manager Windows Client. You need to check out, which Cache Behavior suits your environment. default_ccache_name = FILE:%TEMP%\krb5cc
default_ccache_name = DIR:%TEMP%\krb5cc
default_ccache_name = API:krb5cc
default_ccache_name = MEMORY:krb5cc
default_ccache_name = MSLSA:krb5cc 2. Choosing the "workable" Kerberos Windows Client. Version 4.01 as of now demands its records from an DNS, if i understood that correctly. Since most Lab Environemnts don't have a full fledged DNS Server with Kerberos SRV Entries, which the client is looking for, switching to the older Version 3.22 seems appropriate. Also version 3.22 havs a lot more Functtions than the stripped down 4.01 Client - So it seems. Please check out the version for yourself. 3. Choosing the right Firefox Browser with the right gssapi Library. When modifying your Firefox Network.* directives, you need to make sure, that your Firefox Version (32bit/64Bit) matches EXACTLY the used gssapi Library -> gssapi32.dll / gssapi64.dll network.negotiate-auth.using-native-gsslib: false
network.negotiate-auth.gsslib;C:\09_Tools\MIT_Kerberos\bin\gssapi64.dll
It wont work otherwise and noone will tell you 😉 Additionally, when Hortonworks speak about to Kerberize the Hadoop Cluster, they actually forgot to mention that its really important to kerberize the client too. It does not magically happen. The Amount of Questions regarding "Kerberos - View doesnt work anymore, cant access my Site anymore. etc.) speaks for itself. @Hortonworks: Lot of room for more decent and more importantly End2End Documentation. Best Regards, Normen
... View more