It appears however that the KDC can get into a state where it doesn't create the V4 salted key. I've seen this caused because the host uses /etc/hosts to resolve name lookups before dns and the line for the host in /etc/hosts contains the un-fully qualified domain name before the fully-qualified one.
This error can be caused when you have a different login name on the local machine as compared to the machine you are loging into.To log in in these situation you need to specify your login name on the target machine with the telnet -l myncsausername modi4I have also seen this problem occur when a user creates a .k5login file in his home directory and does not add his own principal in the file.This leads to an annoying error message being printed out all the [email protected]:/h klist Ticket cache: FILE:/tmp/krb5cc_1014Default principal: hdfs/[email protected] Shell$Exit Code Exception: kinit: KDC can't fulfill requested option while renewing credentials Found 3 items-rw-r--r-- 3 cmccabe users 0 2012-07-09 /b-rw-r--r-- 3 hdfs supergroup 0 2012-07-09 /cdrwxrwxrwx - cmccabe audio 0 2012-07-19 /tmp--This message is automatically generated by JIRA.COMValid starting Expires Service principal07/18/12 07/19/12 krbtgt/CLOUDERA. [email protected]:/h ./bin/hadoop fs -ls /,882 WARN User Group Information:739 - Exception encountered while running the renewal command. If you think it was sent incorrectly, please contact your JIRA administrators: https://issues.apache.org/jira/secure/Contact Administrators!Just add the users principal to his .k5login if this is the case.
When you add a user using the 'addprinc' command in kadmin, normally two keys are created, a no salt key (kerberos 5) and a V4 salt key (for kerberos 4).
Kerberos Troubleshooting Tips LDAP Troubleshooting Tips This section will help you troubleshoot Kerberos authentication problems in a heterogeneous UNIX and Microsoft® Windows® operating system environment.
A good place to start is with the following white paper, “Troubleshooting Kerberos Errors,” which provides background and Microsoft-specific guidance and is available at
Tags: Add Linux Desktop to Windows Domain, Add Linux Server to Windows Domain, Add Ubuntu to Windows Domain, Dynamic DNS Updates In Windows Domain from Linux Member, Join Ubuntu to a Windows Domain using Realm D and SSSD, Light DM, Realm D, SSSD For this tutorial I will be walking through how to use a tool called Realmd to connect an Ubuntu Server or Ubuntu Desktop system to a Windows Active Directory Domain.
In the past I wrote an article talking about how to use Powerbroker Identity Services to do the same thing, but the scope of the article was limited to the server version of Ubuntu only.
Colin Patrick Mc Cabe created HDFS-3691:------------------------------------------Summary: User Group Information#spawn Auto Renewal Thread For User Creds dumps shell output to stdout / stderr Key: HDFS-3691URL: https://issues.apache.org/jira/browse/HDFS-3691Project: Hadoop HDFSIssue Type: Bug Components: name-node Affects Versions: 2.0.1-alpha Reporter: Colin Patrick Mc Cabe Priority: Minor Fix For: 2.2.0-alpha User Group Information#spawn Auto Renewal Thread For User Creds tries to renew user credentials.