You are viewing a plain text version of this content. The canonical link for it is here.
Posted to dev@ambari.apache.org by "Andrew Onischuk (JIRA)" <ji...@apache.org> on 2015/10/06 13:13:26 UTC
[jira] [Resolved] (AMBARI-13321) Oozie Alert Fails In Kerberized
Environment That Is Not SSL
[ https://issues.apache.org/jira/browse/AMBARI-13321?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ]
Andrew Onischuk resolved AMBARI-13321.
--------------------------------------
Resolution: Fixed
Committed to trunk and branch-2.1
> Oozie Alert Fails In Kerberized Environment That Is Not SSL
> -----------------------------------------------------------
>
> Key: AMBARI-13321
> URL: https://issues.apache.org/jira/browse/AMBARI-13321
> Project: Ambari
> Issue Type: Bug
> Reporter: Andrew Onischuk
> Assignee: Andrew Onischuk
> Fix For: 2.1.3
>
>
> The Oozie alert check for the server status (`alert_check_oozie_server.py`) is
> not correctly performing a kinit before each check. There are two overall
> problems:
> * The smokeuser is being used instead of the oozie user
> * The principal is using 0.0.0.0 instead of the FQDN of the host.
>
>
>
> [root@c6401:~]$ kinit -k -t /etc/security/keytabs/spnego.service.keytab HTTP/c6401.ambari.apache.org
> [root@c6401:~]$ oozie admin --oozie http://0.0.0.0:11000/oozie -status
> Error: IO_ERROR : java.io.IOException: Error while connecting Oozie server. No of retries = 1. Exception = Could not authenticate, org.apache.hadoop.security.authentication.client.AuthenticationException: Invalid SPNEGO sequence, status code: 400
> [root@c6401:~]$ oozie admin --oozie http://c6401.ambari.apache.org:11000/oozie -status
> System mode: NORMAL
>
--
This message was sent by Atlassian JIRA
(v6.3.4#6332)