Return-Path: X-Original-To: archive-asf-public-internal@cust-asf2.ponee.io Delivered-To: archive-asf-public-internal@cust-asf2.ponee.io Received: from cust-asf.ponee.io (cust-asf.ponee.io [163.172.22.183]) by cust-asf2.ponee.io (Postfix) with ESMTP id 5D04A200D21 for ; Mon, 16 Oct 2017 23:30:48 +0200 (CEST) Received: by cust-asf.ponee.io (Postfix) id 5B8DB1609EF; Mon, 16 Oct 2017 21:30:48 +0000 (UTC) Delivered-To: archive-asf-public@cust-asf.ponee.io Received: from mail.apache.org (hermes.apache.org [140.211.11.3]) by cust-asf.ponee.io (Postfix) with SMTP id 2D5F01609E3 for ; Mon, 16 Oct 2017 23:30:47 +0200 (CEST) Received: (qmail 50628 invoked by uid 500); 16 Oct 2017 21:30:46 -0000 Mailing-List: contact user-help@kudu.apache.org; run by ezmlm Precedence: bulk List-Help: List-Unsubscribe: List-Post: List-Id: Reply-To: user@kudu.apache.org Delivered-To: mailing list user@kudu.apache.org Received: (qmail 50617 invoked by uid 99); 16 Oct 2017 21:30:45 -0000 Received: from pnap-us-west-generic-nat.apache.org (HELO spamd1-us-west.apache.org) (209.188.14.142) by apache.org (qpsmtpd/0.29) with ESMTP; Mon, 16 Oct 2017 21:30:45 +0000 Received: from localhost (localhost [127.0.0.1]) by spamd1-us-west.apache.org (ASF Mail Server at spamd1-us-west.apache.org) with ESMTP id EB6F3C349C for ; Mon, 16 Oct 2017 21:30:44 +0000 (UTC) X-Virus-Scanned: Debian amavisd-new at spamd1-us-west.apache.org X-Spam-Flag: NO X-Spam-Score: 2.39 X-Spam-Level: ** X-Spam-Status: No, score=2.39 tagged_above=-999 required=6.31 tests=[DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_MESSAGE=2, KAM_SHORT=0.001, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H3=-0.01, RCVD_IN_MSPIKE_WL=-0.01, RCVD_IN_SORBS_SPAM=0.5, SPF_PASS=-0.001, T_KAM_HTML_FONT_INVALID=0.01] autolearn=disabled Authentication-Results: spamd1-us-west.apache.org (amavisd-new); dkim=pass (1024-bit key) header.d=miriade.it Received: from mx1-lw-eu.apache.org ([10.40.0.8]) by localhost (spamd1-us-west.apache.org [10.40.0.7]) (amavisd-new, port 10024) with ESMTP id wh-jtBYCYDGv for ; Mon, 16 Oct 2017 21:30:42 +0000 (UTC) Received: from mail-qt0-f177.google.com (mail-qt0-f177.google.com [209.85.216.177]) by mx1-lw-eu.apache.org (ASF Mail Server at mx1-lw-eu.apache.org) with ESMTPS id B943F5F3D1 for ; Mon, 16 Oct 2017 21:30:41 +0000 (UTC) Received: by mail-qt0-f177.google.com with SMTP id f8so34794436qta.5 for ; Mon, 16 Oct 2017 14:30:41 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=miriade.it; s=google; h=mime-version:in-reply-to:references:from:date:message-id:subject:to; bh=AS5Gl62Y/kAszlY0KlwrctQCWrtmZlST9QI7iu3sRDU=; b=Ykc59IuNUYEg2YQ6TySlB3gKBRO9JV53REk8mkz00bfQHgs9cz4W0QN3C2uBBr1iNT duiuVPXNZf5wk3OR3D1tKBjtkKSOAKliyFtMRhnGRrsFtanI4Z/vblQqI5nwawdtnBI8 pQCFN4L07La4k4KRKubcsEdsQkM4Q3IkwHX3o= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:in-reply-to:references:from:date :message-id:subject:to; bh=AS5Gl62Y/kAszlY0KlwrctQCWrtmZlST9QI7iu3sRDU=; b=FVegOo+jECIDcTp+H/ivbUXAY4iDfS5mMdqKDAFNytJw4oY5N6XBSJRzDa+jPHnVKP +JDlcY9nJdtWPVA9UvgDYgBhtyZMfzrJfkhZTdQ6Jia2DOHPa0WQByMry4/qNUnteFuj 02H0IMcN8JpMYiKHzb7uSqpyOiXk3LUcQm5jiiVnM+crfH8wS2g/+BTWxUeLNaeHhoR7 r8U97hUVl6Eh33/8suHOAabMUjZu1tw2IDBLIFM7P6AGzEIYaVeR+1JXIusRdpy+W9w4 4lPXRwP6cFBnbHcf1FQnFCgYRgKfMEqWG37i8mUlHo/clQxch3Jpg5jpYHmVuP3VbiOw jL7Q== X-Gm-Message-State: AMCzsaV18zMbcMqrf7T4AgShwXkoeLcu04HdmJmIEc4ZyuWm/5Bxmt1/ KesNoaixN+6Hsyw+cb3FI7/IMXfhAQ7/MtxtKR3RyxiLv2U= X-Google-Smtp-Source: ABhQp+QppfHjEhfDjDGIu9yAYpXtisbpdClcivBMSlopux6RmQAU4fUC/9LZ7Nrq3IaYZJ6yIUZXmB68MDkBdK730W0= X-Received: by 10.37.107.72 with SMTP id o8mr1273287ybm.230.1508189434679; Mon, 16 Oct 2017 14:30:34 -0700 (PDT) MIME-Version: 1.0 Received: by 10.37.46.79 with HTTP; Mon, 16 Oct 2017 14:29:54 -0700 (PDT) In-Reply-To: References: From: Matteo Durighetto Date: Mon, 16 Oct 2017 23:29:54 +0200 Message-ID: Subject: Re: kudu 1.4 kerberos To: user@kudu.apache.org Content-Type: multipart/alternative; boundary="089e08264d2c8246e0055bb0b72f" archived-at: Mon, 16 Oct 2017 21:30:48 -0000 --089e08264d2c8246e0055bb0b72f Content-Type: text/plain; charset="UTF-8" Content-Transfer-Encoding: quoted-printable Hello Todd, thank you very much for the answer. I think I have found something interesting. Kudu is doing the ACL list with the sAMAccountName or CN as it writes in the logs: "Logged in from keytab as kudu/@REALM (short username )" I begin to think that the problem is between sssd with plugin sssd_krb5_localauth_plugin.so so for every principal kudu/@REALM kudu maps to , so seems impossible to have the all kudu/@REALM mapped to the same "kudu" as suggested "So, basically, it's critical that the username that the master determines for itself (from this function) matches the username that it has determined for the tablet servers when they authenticate (what you pasted as 'abcdefgh1234' above)." The strange thing is that with hadoop I have the correct mapping ( probably because I have no rule, so it switch to default rule ) hadoop org.apache.hadoop.security.HadoopKerberosName kudu/@REALM =3D=3D> kudu Matteo Durighetto 2017-10-13 1:32 GMT+02:00 Todd Lipcon : > Hey Matteo, > > Looks like you did quite a bit of digging in the code! Responses inline > below. > > On Wed, Oct 11, 2017 at 1:24 PM, Matteo Durighetto < > m.durighetto@miriade.it> wrote: > >> Hello, >> I have a strange behaviour with Kudu 1.4 and kerberos. >> I enabled kerberos on kudu, I have the principal correctly in the OU of >> an AD, but >> at startup I got a lot of errors on method TSHeartbeat between tablet >> server and >> master server as unauthorized. There's no firewall between nodes. >> > > right, "unauthorized" indicates that the connection was made fine, but th= e > individual RPC call was determined to not be allowed for the identity > presented on the other side of the connection. > > >> >> W1011