Quantcast
Channel: Hortonworks » All Replies
Viewing all articles
Browse latest Browse all 3435

BUG: agents authenticates to MIT KDC server even kerberos is disabled

$
0
0

Ambari version 2.0.0-150

Ambari agents tries to authenticate with MIT KDC server even though kerberos is disabled on a cluster.
How to reproduce:
1. enable security with MIT KDC server
2. disable kerberos
3. tail -f /var/log/krb5kdc.log — on KDC server , you will see something like:

May 20 20:05:54 sfdmgctmn003 krb5kdc[5013](info): AS_REQ (1 etypes {23}) 10.9.21.121: CLIENT_NOT_FOUND: HTTP/sfdmgctmn001.example.com@SFDMGCT.COM for krbtgt/SFDMGCT.COM@SFDMGCT.COM, Client not found in Kerberos database
May 20 20:05:54 sfdmgctmn003 krb5kdc[5013](info): AS_REQ (1 etypes {23}) 10.9.21.123: CLIENT_NOT_FOUND: HTTP/sfdmgctmn003.example.com@SFDMGCT.COM for krbtgt/SFDMGCT.COM@SFDMGCT.COM, Client not found in Kerberos database
May 20 20:05:54 sfdmgctmn003 krb5kdc[5013](info): AS_REQ (1 etypes {23}) 10.9.21.124: CLIENT_NOT_FOUND: HTTP/sfdmgctmn004.example.com@SFDMGCT.COM for krbtgt/SFDMGCT.COM@SFDMGCT.COM, Client not found in Kerberos database

The question is: should the agent be making any calls to the KDC server even when Kerberos is disabled.
Is this a bug?


Viewing all articles
Browse latest Browse all 3435

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>