Return-Path: X-Original-To: apmail-hadoop-mapreduce-user-archive@minotaur.apache.org Delivered-To: apmail-hadoop-mapreduce-user-archive@minotaur.apache.org Received: from mail.apache.org (hermes.apache.org [140.211.11.3]) by minotaur.apache.org (Postfix) with SMTP id DD2061934E for ; Fri, 29 Apr 2016 15:35:01 +0000 (UTC) Received: (qmail 53327 invoked by uid 500); 29 Apr 2016 15:34:57 -0000 Delivered-To: apmail-hadoop-mapreduce-user-archive@hadoop.apache.org Received: (qmail 53203 invoked by uid 500); 29 Apr 2016 15:34:57 -0000 Mailing-List: contact user-help@hadoop.apache.org; run by ezmlm Precedence: bulk List-Help: List-Unsubscribe: List-Post: List-Id: Delivered-To: mailing list user@hadoop.apache.org Received: (qmail 53191 invoked by uid 99); 29 Apr 2016 15:34:57 -0000 Received: from pnap-us-west-generic-nat.apache.org (HELO spamd4-us-west.apache.org) (209.188.14.142) by apache.org (qpsmtpd/0.29) with ESMTP; Fri, 29 Apr 2016 15:34:57 +0000 Received: from localhost (localhost [127.0.0.1]) by spamd4-us-west.apache.org (ASF Mail Server at spamd4-us-west.apache.org) with ESMTP id 9FF90C0227 for ; Fri, 29 Apr 2016 15:34:56 +0000 (UTC) X-Virus-Scanned: Debian amavisd-new at spamd4-us-west.apache.org X-Spam-Flag: NO X-Spam-Score: 3.431 X-Spam-Level: *** X-Spam-Status: No, score=3.431 tagged_above=-999 required=6.31 tests=[DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_ENVFROM_END_DIGIT=0.25, HTML_MESSAGE=2, KAM_BADIPHTTP=2, NORMAL_HTTP_TO_IP=0.001, RCVD_IN_DNSWL_LOW=-0.7, RCVD_IN_MSPIKE_H3=-0.01, RCVD_IN_MSPIKE_WL=-0.01, SPF_PASS=-0.001, WEIRD_PORT=0.001] autolearn=disabled Authentication-Results: spamd4-us-west.apache.org (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com Received: from mx1-lw-eu.apache.org ([10.40.0.8]) by localhost (spamd4-us-west.apache.org [10.40.0.11]) (amavisd-new, port 10024) with ESMTP id AYduL5e0ZyfP for ; Fri, 29 Apr 2016 15:34:54 +0000 (UTC) Received: from mail-wm0-f42.google.com (mail-wm0-f42.google.com [74.125.82.42]) by mx1-lw-eu.apache.org (ASF Mail Server at mx1-lw-eu.apache.org) with ESMTPS id DA7B55F39B for ; Fri, 29 Apr 2016 15:34:53 +0000 (UTC) Received: by mail-wm0-f42.google.com with SMTP id n129so32517407wmn.1 for ; Fri, 29 Apr 2016 08:34:53 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113; h=mime-version:date:message-id:subject:from:to; bh=7Fz3STFCiUa1KpV8w2IkRBiCZdpp5xyi31MuZX9/jTw=; b=ponkY/s30sD8MFA3nzsh9AFJkujsvHoEoE2aOEX9vLv/T/21YjeNjbeuN8fsMGeT5B AOHUjPkDRhxq8goJbLvof9sG+KOOjpLGD1KVYHvEn8l3GFqW6/Ldb82VWCkXFWSdD2ov kOwhSZwGFypniSGBl/P2s/TMEXK6bnKYIEtf88h96E0+hVdteWpHkZYp/N9sbaBVZMsj VUAcWfSkGubIJsKbRkXfFgIMUrR+Zi6Gf0FKpTq90t0zvp2afaLUit0JNmkXTYdIQ3ib lYa/OxTsW5QZCf+vIDj4nSRdOTb/ISpC3sJrnDQZf+sQtIeZOjaDJxgDPEnmnx4oXWPI frPA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20130820; h=x-gm-message-state:mime-version:date:message-id:subject:from:to; bh=7Fz3STFCiUa1KpV8w2IkRBiCZdpp5xyi31MuZX9/jTw=; b=RiJfjCKj9yOcIJHL+fEFS5+boq6oO5SnT1CYNpaLU70sDm0Ery6p+qnt8whs5FU10O stK5UbzmQsOSRPsg0M2pZ6KFqzZkggRzIcNrsSwmQh/Sepj6Uw1Vd42OHj3LzpFHKAEB 9d9lJkspLz6644TAElftHawVDz+R6OZ7CkYUacYBzOzqFEcOvSgWui61XwEke9LjU1/z gTEFRu+NyztsSJLiA7HMBVOWQBmVAURrPe41P9qIz0Idnx24cFGa4G7MfzZy4UwVhGWr PKKcqNqkOAqL9mWIQD06rdd1dZh4SKBnoU+/ke+zSRBBMrsT9pHaxrHiXhnpIVK5huRv 0n8g== X-Gm-Message-State: AOPr4FXLjWAq4n8ym+01T5zNBSjo3SLocHcOOHX93mclPDdhi4JC2fN/jPXwcayEAwizzRblEX3tgtjSlLlBEA== MIME-Version: 1.0 X-Received: by 10.28.90.65 with SMTP id o62mr4788865wmb.16.1461944093458; Fri, 29 Apr 2016 08:34:53 -0700 (PDT) Received: by 10.28.182.84 with HTTP; Fri, 29 Apr 2016 08:34:53 -0700 (PDT) Date: Fri, 29 Apr 2016 08:34:53 -0700 Message-ID: Subject: 403 when trying to access secure hadoop http UI /logs/ - any workaround? or explanation? From: Jeffrey Rodriguez To: user@hadoop.apache.org Content-Type: multipart/alternative; boundary=001a11453cf85f5a660531a16234 --001a11453cf85f5a660531a16234 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: quoted-printable Hi Folks, I am getting a 403 accessing Kerberized cluster (Hadoop Kerberized). kinit ..... valid Kerberos user... curl -L --negotiate -u : http://locathost:50070/logs/ .. > GET /logs/ HTTP/1.1 > Authorization: Negotiate YIICVwYJKoZIhvcSAQICAQBuggJGMIICQqADAgEFoQMCAQ6iBwMFAAAAAACjggFjYYIBXzCCAVu= gAwIBBaEJGwdJQk0uQ09NoicwJaADAgEDoR4wHBsESFRUUBsUYmRhdm00ODQuc3ZsLmlibS5jb2= 2jggEeMIIBGqADAgERoQMCAQaiggEMBIIBCGTmcjb1WNFRYaTCzAxgCC9ZMaKdHHyt+7qHV/Q4m= RFyuhhouo0hFccjNH7TTC1eUXTf31+zo5Zfg3dNPV/NJ1WH53YdMYWHuHDAkWvd7amBPQB/j5q2= pOqn+3X8DEW8hcPYo1vRrzLWht8BKmorxCNuRIDETw0Qn7Q9cETLPgPHbEqTCjeEKNqux/26CaJ= 8/Ixu6qBbj1DtsJzJZJCKbIVoYbj6hGajv4ACIXTXeIIUa9dqDXeI9R97OZXSVlq/M3foyltPQf= jRL3DEWiDdavpmr/3LJbJ6rr3UYeZKona8Wz4SlGWKJwkqSTdBTdpHatVZVRXkTfkeuAi03HNVv= ZwsJ1v1hPpCaqSBxTCBwqADAgERooG6BIG3jNhBU4niOi+a32hsF5qCAVDne7815PrvvGhweF14= u+1nJ2Nk+54eQWUNNIF87AomF0vEoUFjzKtKJ6pAcTer9L9ab782acAhEH0H+O3kW88qc45LGhR= tquimF2Xrguq1RrjPIlS1sAoTLtj/b0ctvcFQBH1Vuuryyn5AKyWBvW0IFVzBcJQcLlVjlFoaeA= 9RpF39BktO3RutCONA4/B/RzbeucEvIhyODss7XBs83o49KemsQT7x > User-Agent: curl/7.19.7 (x86_64-redhat-linux-gnu) libcurl/7.19.7 NSS/ 3.16.2.3 Basic ECC zlib/1.2.3 libidn/1.18 libssh2/1.4.2 > Host: localhost:50070 > Accept: */* > < HTTP/1.1 403 User ambari-qa is unauthorized to access this page. < Content-Type: text/html; charset=3Diso-8859-1 < Set-Cookie: hadoop.auth=3D"u=3Dambari-qa&p=3Dambari-qa-testme@IBM.COM&t= =3Dkerberos&e=3D1461979860144&s=3DoXW3iQyX0/SAWxup9pngeyNSGO4=3D"; Path=3D/; Domain=3Dsvl.ibm.com; Expires=3DSat, 30-Apr-2016 01:31:00 GMT; Ht= tpOnly id ambari-qa id ambari-qa uid=3D1006(ambari-qa) gid=3D502(hadoop) groups=3D502(hadoop),100(users) All super user/proxy set to * Any reason why /logs/ are not accessible? Can that be set in configuration? BTW is I run the request as hdfs user it succeeds so hdfs service user has authorization. This is confusing some users since they expect access for hadoop UI /logs/ --001a11453cf85f5a660531a16234 Content-Type: text/html; charset=UTF-8 Content-Transfer-Encoding: quoted-printable
Hi Folks,
=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0 I a= m getting a 403 accessing Kerberized cluster (Hadoop Kerberized).

<= div>
kinit ..... valid Kerberos user...

curl -L=C2=A0 --negotiat= e -u :=C2=A0 http://locathost:5007= 0/logs/

..
> GET /logs/ HTTP/1.1
> Authorization: Ne= gotiate YIICVwYJKoZIhvcSAQICAQBuggJGMIICQqADAgEFoQMCAQ6iBwMFAAAAAACjggFjYYI= BXzCCAVugAwIBBaEJGwdJQk0uQ09NoicwJaADAgEDoR4wHBsESFRUUBsUYmRhdm00ODQuc3ZsLm= libS5jb22jggEeMIIBGqADAgERoQMCAQaiggEMBIIBCGTmcjb1WNFRYaTCzAxgCC9ZMaKdHHyt+= 7qHV/Q4mRFyuhhouo0hFccjNH7TTC1eUXTf31+zo5Zfg3dNPV/NJ1WH53YdMYWHuHDAkWvd7amB= PQB/j5q2pOqn+3X8DEW8hcPYo1vRrzLWht8BKmorxCNuRIDETw0Qn7Q9cETLPgPHbEqTCjeEKNq= ux/26CaJ8/Ixu6qBbj1DtsJzJZJCKbIVoYbj6hGajv4ACIXTXeIIUa9dqDXeI9R97OZXSVlq/M3= foyltPQfjRL3DEWiDdavpmr/3LJbJ6rr3UYeZKona8Wz4SlGWKJwkqSTdBTdpHatVZVRXkTfkeu= Ai03HNVvZwsJ1v1hPpCaqSBxTCBwqADAgERooG6BIG3jNhBU4niOi+a32hsF5qCAVDne7815Prv= vGhweF14u+1nJ2Nk+54eQWUNNIF87AomF0vEoUFjzKtKJ6pAcTer9L9ab782acAhEH0H+O3kW88= qc45LGhRtquimF2Xrguq1RrjPIlS1sAoTLtj/b0ctvcFQBH1Vuuryyn5AKyWBvW0IFVzBcJQcLl= VjlFoaeA9RpF39BktO3RutCONA4/B/RzbeucEvIhyODss7XBs83o49KemsQT7x
> User= -Agent: curl/7.19.7 (x86_64-redhat-linux-gnu) libcurl/7.19.7 NSS/3.16.2.3 Basic ECC zlib/1.2.3 libidn/1.18 libssh2/1.4= .2
> Host: localhost:50070
> Accept: */*
>
< HTTP/= 1.1 403 User ambari-qa is unauthorized to access this page.
< Content= -Type: text/html; charset=3Diso-8859-1
< Set-Cookie: hadoop.auth=3D&q= uot;u=3Dambari-qa&p=3Dambar= i-qa-testme@IBM.COM&t=3Dkerberos&e=3D1461979860144&s=3DoXW3= iQyX0/SAWxup9pngeyNSGO4=3D"; Path=3D/; Domain=3Dsvl.ibm.com; Expires=3DSat, 30-Apr-2016 01:31:00 GMT; HttpOnly=



id ambari-qa

id ambari-qa
= uid=3D1006(ambari-qa) gid=3D502(hadoop) groups=3D502(hadoop),100(users)
=

All super user/proxy set to *

Any reas= on why /logs/ are not accessible? Can that be set in configuration?

=
BTW is I run the request as hdfs user it succeeds so hdfs servic= e user has authorization.

This is confusing some users si= nce they expect access for hadoop UI /logs/
--001a11453cf85f5a660531a16234--