hadoop-mapreduce-user mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From John Lilley <john.lil...@redpoint.net>
Subject Trusted-realm vs default-realm kerberos issue
Date Tue, 17 Mar 2015 19:22:53 GMT
Greetings,

We encountered the issue reported here:
https://issues.cloudera.org/browse/DISTRO-526
It seems that someone should have figured out a workaround by now, does anyone know what it
is?

The problem is, the Hadoop installation uses an "Edge" AD controller as its KDC, and that
Edge AD controller trusts an "enterprise" AD controller.  Trying to authenticate using the
password equivalent of UserGroupInformation.loginUserFromKeytab() with a user in the "enterprise"
realm fails, while a user in the "edge" realm succeeds.

Thanks
John


Mime
View raw message