You are viewing a plain text version of this content. The canonical link for it is here.
Posted to mapreduce-user@hadoop.apache.org by li...@gmail.com on 2014/01/03 14:23:54 UTC

Re: Secondary name node error in checkpoint with Kerberos enabled

13201614174
Qdfdhsgdgshagsydyffg
As sfgswzv
Fftdtf


发自我的 iPad

> 在 佛历2557年1月1日,上午6:59,Manoj Samel <ma...@gmail.com> 写道:
> 
> * Name node and secondary name nodes on different machines
> * Kerberos was just enabled
> * Cloudera CDH 4.5 on Centos
> 
> Secondary name node log (HOST2) shows following
> 
> 
> 2013-12-31 22:00:11,728 ERROR org.apache.hadoop.security.UserGroupInformation: PriviledgedActionException as:hdfs/<2NN-host>@<REALM> (auth:KERBEROS) cause:org.apache.hadoop.hdfs.server.namenode.TransferFsImage$HttpGetFailedException: Image transfer servlet at http://NN-HOST:50070/getimage?getimage=1&txid=21309&storageInfo=-40:1404288132:0:CID-07c7bfbb-055d-41d8-8a8f-23a0e11a3235 failed with status code 403
> Response message:
> Only Namenode, Secondary Namenode, and administrators may access this servlet
> 
> Name Node Log (HOST1) shows following
> 
> 2013-12-31 21:59:56,173 INFO SecurityLogger.org.apache.hadoop.ipc.Server: Auth successful for hdfs/2NN-host@REALM (auth:SIMPLE)
> 2013-12-31 21:59:56,213 INFO SecurityLogger.org.apache.hadoop.security.authorize.ServiceAuthorizationManager: Authorization successful for hdfs/2NN-host@REALM (auth:KERBEROS) for protocol=interface org.apache.hadoop.hdfs.server.protocol.NamenodeProtocol
> 
> ...
> 2013-12-31 21:59:56,612 INFO org.apache.hadoop.hdfs.server.namenode.GetImageServlet: GetImageServlet rejecting: hdfs/2NN-host@REALM
> 2013-12-31 21:59:56,615 WARN org.apache.hadoop.hdfs.server.namenode.GetImageServlet: Received non-NN/SNN/administrator request for image or edits from hdfs/2NN-host@REALM at 2NN-host-IP
> 
> 
> -- 
> Thanks,
> 
> Manoj