From user-return-26101-archive-asf-public=cust-asf.ponee.io@flink.apache.org Fri Feb 22 08:38:47 2019 Return-Path: X-Original-To: archive-asf-public@cust-asf.ponee.io Delivered-To: archive-asf-public@cust-asf.ponee.io Received: from mail.apache.org (hermes.apache.org [140.211.11.3]) by mx-eu-01.ponee.io (Postfix) with SMTP id 9F2FC180648 for ; Fri, 22 Feb 2019 09:38:46 +0100 (CET) Received: (qmail 9338 invoked by uid 500); 22 Feb 2019 08:38:45 -0000 Mailing-List: contact user-help@flink.apache.org; run by ezmlm Precedence: bulk List-Help: List-Unsubscribe: List-Post: List-Id: Delivered-To: mailing list user@flink.apache.org Received: (qmail 9311 invoked by uid 99); 22 Feb 2019 08:38:45 -0000 Received: from pnap-us-west-generic-nat.apache.org (HELO spamd1-us-west.apache.org) (209.188.14.142) by apache.org (qpsmtpd/0.29) with ESMTP; Fri, 22 Feb 2019 08:38:45 +0000 Received: from localhost (localhost [127.0.0.1]) by spamd1-us-west.apache.org (ASF Mail Server at spamd1-us-west.apache.org) with ESMTP id BDF6FCA6D9 for ; Fri, 22 Feb 2019 08:38:44 +0000 (UTC) X-Virus-Scanned: Debian amavisd-new at spamd1-us-west.apache.org X-Spam-Flag: NO X-Spam-Score: 3.023 X-Spam-Level: *** X-Spam-Status: No, score=3.023 tagged_above=-999 required=6.31 tests=[DKIMWL_WL_MED=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HTML_MESSAGE=2, MIME_BOUND_DIGITS_15=1.225, RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001] autolearn=disabled Authentication-Results: spamd1-us-west.apache.org (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com Received: from mx1-lw-us.apache.org ([10.40.0.8]) by localhost (spamd1-us-west.apache.org [10.40.0.7]) (amavisd-new, port 10024) with ESMTP id Lm0aIDtasPju for ; Fri, 22 Feb 2019 08:38:43 +0000 (UTC) Received: from mail-oi1-f194.google.com (mail-oi1-f194.google.com [209.85.167.194]) by mx1-lw-us.apache.org (ASF Mail Server at mx1-lw-us.apache.org) with ESMTPS id 532F95F20B for ; Fri, 22 Feb 2019 08:29:08 +0000 (UTC) Received: by mail-oi1-f194.google.com with SMTP id s16so1100411oih.9 for ; Fri, 22 Feb 2019 00:29:08 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=mime-version:from:date:message-id:subject:to; bh=fARTw70rc4ky/XB19LgXSBk0NxnU4gmVUYYLl07qy60=; b=tOkvHdQTAYjjbaJ0XdcZPXilEsGbKOvY6BGPfDWZ7sQjUT73ItxMlZK1Q6nawJv58Q f/iqO4he8719PBxGt0+dEuM1kaQmHjuix8VvLpx25W2huLuP2CLwyiM0cpR7dGNWaypv q0lAPqAMAdVbZgHlQem4JVofnqkxFGaeGjtAOsEwvUS4ruJfbRVCms70V5EwPxuOJK8c mY1WcJ9tJ/KwgG/UoUlVTV+2ilRqEdMotuUNY5vSwfPeb/9+59TTCl7j5icRSucUemRC 53c33ZBnLXB1he0BOpsuj1PrP+2M/tJksVcAZWQK3IzJxPLdD26pUAe38+Q0cBpWKdfd lP9Q== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:from:date:message-id:subject:to; bh=fARTw70rc4ky/XB19LgXSBk0NxnU4gmVUYYLl07qy60=; b=AOL9xHRuDccuiCoUbJM/NiNIIvhh+OfywWsyTWYU4tnM9AQRKJLtfR7NwBJ3sgTfrE 6og20265iPQPyvun4+2Wo5pKublc4aHFVcvN7CcV/220OG++RQ7RPFl7KZ/jI/KOxtyb JZtywfoAVOWLLlNm4FIKIc9dobVIaKF4wjtzZs1gxMGem+T6XmBguYB5WwLfeNJQNCfB 4QGTc6XNNE6WSbn1At6uDiKB1+zkw8Rj0sTcENE1OX63Q8Rm3Xq4pFHlvme3aC4p4N1Y KzqXszJ12vzGOWxlTT2HpOTtXiO+mZP7nsRmx/euvtLa4Y/bQw4rDl+l4ZccSRWkxagf THBg== X-Gm-Message-State: AHQUAub/xwFgPf1mSya7+nLfqVwoDhHOBlOtcVOl3fDetOcKAIcHFMb4 T1hXTXoXkyb+/8BTD6hy9tFJI53hElTxCD3jP9TxRB1D X-Google-Smtp-Source: AHgI3IbXO25F8/7ATAA4THBO3jJZxy5ZlcnxySLgxz1zl0xFH8wp7DI/oiLWSBxW1uA0jQDwd6bnYe5ANcS6G4y5v+s= X-Received: by 2002:aca:3786:: with SMTP id e128mr1880633oia.120.1550824141961; Fri, 22 Feb 2019 00:29:01 -0800 (PST) MIME-Version: 1.0 From: Marke Builder Date: Fri, 22 Feb 2019 09:28:50 +0100 Message-ID: Subject: Flink 1.6.1 Kerberos configuration To: user@flink.apache.org Content-Type: multipart/alternative; boundary="0000000000001743400582776211" --0000000000001743400582776211 Content-Type: text/plain; charset="UTF-8" Hello, I'm using flink 1.6.1 for streaming. In addition I need access to an storage layer with kerberos auth. . I added the following parameter in the flink-conf.yml security.kerberos.login.use-ticket-cache: true security.kerberos.login.keytab: /.../*.keytab security.kerberos.login.principal: *@* But after a view days (token expired) the job failed with the GSSException: No valid credentials provided (Mechanism level: Failed to find any Kerberos tgt) Do I have to make additional settings or have I missed something else? Thanks and Best Regards, Marke --0000000000001743400582776211 Content-Type: text/html; charset="UTF-8" Content-Transfer-Encoding: quoted-printable
Hello,<= div>
I'm using flink 1.6.1 for streaming. In addition I n= eed access to an storage layer with kerberos auth. . I added the following = parameter in the flink-conf.yml=C2=A0

securit= y.kerberos.login.use-ticket-cache: true
security.kerberos.login.k= eytab: /.../*.keytab
security.kerberos.login.principal: *@*
=

But after a view days (token expired) the job fai= led with the GSSException:
No valid credentials provided (Mechanism leve= l: Failed to find any Kerberos tgt)

Do I have = to make additional settings or have I missed something else?
=
Thanks and Best Regards,
Marke

--0000000000001743400582776211--