You are viewing a plain text version of this content. The canonical link for it is here.
Posted to dev@ambari.apache.org by "Andrew Onischuk (JIRA)" <ji...@apache.org> on 2015/10/06 13:06:26 UTC
[jira] [Created] (AMBARI-13321) Oozie Alert Fails In Kerberized
Environment That Is Not SSL
Andrew Onischuk created AMBARI-13321:
----------------------------------------
Summary: Oozie Alert Fails In Kerberized Environment That Is Not SSL
Key: AMBARI-13321
URL: https://issues.apache.org/jira/browse/AMBARI-13321
Project: Ambari
Issue Type: Bug
Reporter: Andrew Onischuk
Assignee: Andrew Onischuk
Fix For: 2.1.3
The Oozie alert check for the server status (`alert_check_oozie_server.py`) is
not correctly performing a kinit before each check. There are two overall
problems:
* The smokeuser is being used instead of the oozie user
* The principal is using 0.0.0.0 instead of the FQDN of the host.
[root@c6401:~]$ kinit -k -t /etc/security/keytabs/spnego.service.keytab HTTP/c6401.ambari.apache.org
[root@c6401:~]$ oozie admin --oozie http://0.0.0.0:11000/oozie -status
Error: IO_ERROR : java.io.IOException: Error while connecting Oozie server. No of retries = 1. Exception = Could not authenticate, org.apache.hadoop.security.authentication.client.AuthenticationException: Invalid SPNEGO sequence, status code: 400
[root@c6401:~]$ oozie admin --oozie http://c6401.ambari.apache.org:11000/oozie -status
System mode: NORMAL
--
This message was sent by Atlassian JIRA
(v6.3.4#6332)