hadoop-hdfs-user mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From Akash Mishra <akash.mishr...@gmail.com>
Subject Namenode Unable to Authenticate to QJM in Secure mode.
Date Fri, 19 Aug 2016 10:45:49 GMT
Hi *,

I am trying to run Hadoop cluster [ 2.7.1] in Secure mode. In my cluster
Namenode is failing while restart with

2016-08-19 10:34:49,754 DEBUG
org.apache.hadoop.security.authentication.client.KerberosAuthenticator:
Using fallback authenticator sequence.
2016-08-19 10:34:49,774 DEBUG
org.apache.hadoop.security.UserGroupInformation: PrivilegedActionException
as:hdfs/hadoopdev1.mlan@HADOOPDEV.MLAN (auth:KERBEROS)
cause:java.io.IOException:
org.apache.hadoop.security.authentication.client.AuthenticationException:
Authentication failed, status: 403, message: GSSException: No valid
credentials provided (Mechanism level: Failed to find any Kerberos
credentails)
2016-08-19 10:34:49,775 ERROR
org.apache.hadoop.hdfs.server.namenode.EditLogInputStream: caught exception
initializing
http://hadoopdev1:8480/getJournal?jid=hadoopdev&segmentTxId=2275460&storageInfo=-63%3A1455401088%3A1444912570574%3ACID-f748dfef-c174-4d19-8d18-43b74552c8e6
java.io.IOException:
org.apache.hadoop.security.authentication.client.AuthenticationException:
Authentication failed, status: 403, message: GSSException: No valid
credentials provided (Mechanism level: Failed to find any Kerberos
credentails)
        at
org.apache.hadoop.hdfs.server.namenode.EditLogFileInputStream$URLLog$1.run(EditLogFileInputStream.java:464)
        at
org.apache.hadoop.hdfs.server.namenode.EditLogFileInputStream$URLLog$1.run(EditLogFileInputStream.java:456)
        at java.security.AccessController.doPrivileged(Native Method)
        at javax.security.auth.Subject.doAs(Subject.java:422)
        at
org.apache.hadoop.security.UserGroupInformation.doAs(UserGroupInformation.java:1657)
        at
org.apache.hadoop.security.SecurityUtil.doAsUser(SecurityUtil.java:448)
        at
org.apache.hadoop.security.SecurityUtil.doAsCurrentUser(SecurityUtil.java:442)
        at
org.apache.hadoop.hdfs.server.namenode.EditLogFileInputStream$URLLog.getInputStream(EditLogFileInputStream.java:455)
        at
org.apache.hadoop.hdfs.server.namenode.EditLogFileInputStream.init(EditLogFileInputStream.java:141)
        at
org.apache.hadoop.hdfs.server.namenode.EditLogFileInputStream.nextOpImpl(EditLogFileInputStream.java:192)
        at
org.apache.hadoop.hdfs.server.namenode.EditLogFileInputStream.nextOp(EditLogFileInputStream.java:250)
        at
org.apache.hadoop.hdfs.server.namenode.EditLogInputStream.readOp(EditLogInputStream.java:85)
        at
org.apache.hadoop.hdfs.server.namenode.EditLogInputStream.skipUntil(EditLogInputStream.java:151)
        at
org.apache.hadoop.hdfs.server.namenode.RedundantEditLogInputStream.nextOp(RedundantEditLogInputStream.java:178)
        at
org.apache.hadoop.hdfs.server.namenode.EditLogInputStream.readOp(EditLogInputStream.java:85)
        at
org.apache.hadoop.hdfs.server.namenode.EditLogInputStream.skipUntil(EditLogInputStream.java:151)
        at
org.apache.hadoop.hdfs.server.namenode.RedundantEditLogInputStream.nextOp(RedundantEditLogInputStream.java:178)
        at
org.apache.hadoop.hdfs.server.namenode.EditLogInputStream.readOp(EditLogInputStream.java:85)


I am using MIT 5 Kerberos. I am able to successfully kinit using keytab
file. I have DEBUG log enabled and attaching log from Namenode [nn.log]
 and one of QJM [ qjm.log]



Thanks.




-- 

Regards,
Akash Mishra.


"It's not our abilities that make us, but our decisions."--Albus Dumbledore

Mime
View raw message