Re: Kerberos auth + user impersonation

2018-01-26 Thread Bear Giles
The supergroup is 'supergroup'. The user 'snapuser' is in that group. I've added hadoop.proxyuser.snapuser.hosts, .groups, and .users to the conf file. (Via advanced options safety valve for core-site.xml in CDH manager.) I verified the change is in the deployed configuration. It works for SIMPL

Re: Kerberos auth + user impersonation

2018-01-26 Thread Jorge Machado
Have you added the proxy.***.hosts to hadoop config ? Check this: https://hadoop.apache.org/docs/r2.8.0/hadoop-project-dist/hadoop-common/Superusers.html Jorge Machado www.jmachado.me > On 26 Jan 201

Re: Kerberos auth + user impersonation

2018-01-26 Thread Bear Giles
Thanks all. I've made the changes but am still getting an error. Notably it's not a "user X cannot impersonate Y" error. exc: Caused by: org.apache.hadoop.security.AccessControlException: Client cannot authenticate via:[TOKEN, KERBEROS] exc: at org.apache.hadoop.security.SaslRpcClient.select

Re: Anyone has tried accessing TDE using HDFS Java APIs

2018-01-26 Thread praveenesh kumar
Hi Ajay We are using HDP 2.5.5 with HDFS 2.7.1.2.5 Thanks Prav On Thu, Jan 25, 2018 at 5:47 PM, Ajay Kumar wrote: > Hi Praveenesh, > > > > What version of Hadoop you are using? > > > > Thanks, > > Ajay > > > > *From: *praveenesh kumar > *Date: *Thursday, January 25, 2018 at 8:22 AM > *To: *"u