Replies: 2 comments 3 replies
-
Update: I was not using the proper _HOST wildcard in my ozone-site.xml. After setting the UPN and SPN to the om/FQDN@Realm and scm/FQDN@Realm scm and om were able to login with their respective UPN. The error I am encoring now is:
The key tabs are all correctly setup and work from what I can tell by using kinit to verify that they are still valid. Anyone have an idea of what this error could be? |
Beta Was this translation helpful? Give feedback.
-
@Dalamar32 run into the same issue in Ozone 1.4.0 According to the example of Ozone HA secure in compose folder of Ozone distribution (as well in HDFS), one may use, for instance, the same principal like scm/scm@REALM for all SCMs in HA cluster. But in practice, it doesn't work properly. Is your question is actual for now? I am open to communication about this topic or any Ozone topic. |
Beta Was this translation helpful? Give feedback.
-
When starting up SCM I keep getting this error:
2023-06-07 11:42:20,826 [main] INFO retry.RetryInvocationHandler: com.google.protobuf.ServiceException: java.io.IOException: DestHost:destPort ddl07oscm03.root.local:9863 , LocalHost:localPort ddl07oscm02.root.local/10.236.152.50:0. Failed on local exception: java.io.IOException: Couldn't set up IO streams: java.lang.IllegalArgumentException: Kerberos principal name does NOT have the expected hostname part: [email protected], while invoking $Proxy14.send over nodeId=scm3,nodeAddress=ddl07oscm03.root.local/10.236.152.51:9863 after 9 failover attempts. Trying to failover after sleeping for 2000ms.
This error only happens on the other two in the three node cluster, not the 01 node.
According to the documentation on securing ozone it shows the principle name example as "e.g. scm/[email protected]"
Q: Does that mean that the AD account created to use with ozone needs to be named as follows:
scm/_ [email protected]
does it require the host SPN set or is there another issue that I may be unaware of?
Here is my ozone-site.xml file if needed:
ozone-site.txt
Beta Was this translation helpful? Give feedback.
All reactions