Hi, I need to switch to use FreeIPA kerberos server and made all necessary changes for keytabs and principals, but services can not be started:
resource_management.core.exceptions.Fail: Execution of '/usr/bin/kinit -kt /etc/security/keytabs/hdfs.headless.keytab [email protected]' returned 1. kinit: Keytab contains no suitable keys for [email protected] while getting initial credentials Note that my realm is changed to "BAR.COM", and I also updated Ambari Kerberos configuration for Realm name and KDS host name, which is verified in Ambari UI kerberos configuration. Not sure why Ambari still use FOO.COM when doing the kinit. Please note that I did not disable or enable kerberos. I simply added principals to IPA kerberos server and retrieved keystabs from it by following the instruction below: Manual Keytab / Principal creation for IPA to support Ambari Kerberos Wizard - Hortonworks Any help is highly appreciated! -fay | | | | | | | | | | | Manual Keytab / Principal creation for IPA to support Ambari Kerberos Wizar... Forums, Q&A, Knowledgebase articles, gallery of the best GitHub repos for Hadoop, HDF, Spark, HDP, IOT, Stre... | | | |
