accumulo-user mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From "roman.drapeko@baesystems.com" <roman.drap...@baesystems.com>
Subject Accumulo and Kerberos
Date Tue, 26 Jan 2016 16:47:45 GMT
Hi there,

Trying to setup Accumulo 1.7 on Kerberized cluster. Only interested in master/tablets to be
kerberized (not end-users). Configured everything as per manual:


1)      Created principals

2)      Generated glob keytab

3)      Modified accumulo-site.xml providing general.kerberos.keytab and general.kerberos.principal

If I start as accumulo user I get: Caused by: GSSException: No valid credentials provided
(Mechanism level: Failed to find any Kerberos tgt)

However, if I give explicitly a token with kinit and keytab generated above in the shell -
it works as expected. To my understanding Accumulo has to obtain tickets automatically? Or
the idea is to write a cron job and apply kinit to every tablet server per day?

Regards,
Roman
Please consider the environment before printing this email. This message should be regarded
as confidential. If you have received this email in error please notify the sender and destroy
it immediately. Statements of intent shall only become binding when confirmed in hard copy
by an authorised signatory. The contents of this email may relate to dealings with other companies
under the control of BAE Systems Applied Intelligence Limited, details of which can be found
at http://www.baesystems.com/Businesses/index.htm.

Mime
View raw message