Chernishev Aleksander created OOZIE-1928:
--------------------------------------------
Summary: Client mapred/_HOST@DOMAIN tries to renew a token with
renewer specified as mapred
Key: OOZIE-1928
URL: https://issues.apache.org/jira/browse/OOZIE-1928
Project: Oozie
Issue Type: Task
Components: action
Affects Versions: 3.3.2
Environment: Centos6.4, cdh4.4,
oozie-3.3.2+92-1.cdh4.4.0.p0.15.el6.noarch. hdfs + ha , mapred + ha ,
hbase,zookeper, oozie all with krb5. two masters hdfs/mapred in ha, three data
nodes. task runnig on the master hdfs
Reporter: Chernishev Aleksander
i'm run task in oozie (login as user kmsearch_spider, kinit like
kmsearch_spider) , task moved to mapred(in oozie web console everything looks
good) .When mapred trying renew token, job finished and i see in mapred
jobtracker log:
2014-07-11 16:02:23,769 INFO
org.apache.hadoop.security.token.delegation.AbstractDelegationTokenSecretManager:
Token renewal requested for identifier: owner=kmsearch_spider, renewer=mapred,
realUser=oozie/[email protected], is
sueDate=1405080142430, maxDate=1405684942430, sequenceNumber=14, masterKeyId=2
2014-07-11 16:02:23,769 ERROR org.apache.hadoop.security.UserGroupInformation:
PriviledgedActionException as:mapred/[email protected]
(auth:KERBEROS) cause:org.apache.hadoop.security.AccessControlException: Client
mapred/pluto
[email protected] tries to renew a token with renewer specified as
mapred
2014-07-11 16:02:23,770 INFO org.apache.hadoop.ipc.Server: IPC Server handler 0
on 8021, call renewDelegationToken(Kind: MAPREDUCE_DELEGATION_TOKEN, Service:
10.241.240.57:8021, Ident: (owner=kmsearch_spider, renewer=mapred,
realUser=oozie
/[email protected], issueDate=1405080142430,
maxDate=1405684942430, sequenceNumber=14, masterKeyId=2)), rpc version=2,
client version=28, methodsFingerPrint=1830206421 from 10.241.240.57:42726:
error: org.apache.hadoop.securit
y.AccessControlException: Client mapred/[email protected] tries to
renew a token with renewer specified as mapred
org.apache.hadoop.security.AccessControlException: Client
mapred/[email protected] tries to renew a token with renewer
specified as mapred
In log mapred task node:
2014-07-11 16:02:35,009 ERROR org.apache.hadoop.security.UserGroupInformation:
PriviledgedActionException as:kmsearch_spider (auth:SIMPLE)
cause:javax.security.sasl.SaslException: GSS initiate failed [Caused by
GSSException: No valid credentials provided (Mechanism level: Failed to find
any Kerberos tgt)]
2014-07-11 16:02:35,010 WARN org.apache.hadoop.ipc.SecureClient: Exception
encountered while connecting to the server : javax.security.sasl.SaslException:
GSS initiate failed [Caused by GSSException: No valid credentials provided
(Mechanism level: Failed to find any Kerberos tgt)]
2014-07-11 16:02:35,011 FATAL org.apache.hadoop.ipc.SecureClient: SASL
authentication failed. The most likely cause is missing or invalid credentials.
Consider 'kinit'.
javax.security.sasl.SaslException: GSS initiate failed [Caused by GSSException:
No valid credentials provided (Mechanism level: Failed to find any Kerberos
tgt)]
--
This message was sent by Atlassian JIRA
(v6.2#6252)