[
https://issues.apache.org/jira/browse/IGNITE-2525?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=15130182#comment-15130182
]
Luca Rea commented on IGNITE-2525:
----------------------------------
CentOS 6.7
HDP 2.3.2 with hadoop 2.7.1 and spark 1.4.1
Cluster with Kerberos Authentication (OpenLDAP)
Package apache-ignite-fabric-1.5.0.final-bin.zip extracted into /opt/ignite
commands:
kinit <user>@<realm>
hadoop jar /opt/ignite/libs/optional/ignite-yarn/ignite-yarn-1.5.0.final.jar
/opt/ignite/libs/optional/ignite-yarn/ignite-yarn-1.5.0.final.jar
You can read the error in the yarn log of the datanode chosen by the
resourcemanager to run the container.
> Yarn - Kerberos delegation token support for long running applications
> ----------------------------------------------------------------------
>
> Key: IGNITE-2525
> URL: https://issues.apache.org/jira/browse/IGNITE-2525
> Project: Ignite
> Issue Type: Improvement
> Affects Versions: 1.5.0.final
> Reporter: Luca Rea
> Assignee: Ivan Veselovsky
> Fix For: 1.6
>
>
> Hi,
> now Yarn returns an authentication error when kerberos is enabled:
> java.io.IOException: Failed on local exception: java.io.IOException:
> org.apache.hadoop.security.AccessControlException: Client cannot authenticate
> via:[TOKEN, KERBEROS];
> I think Apache Ignite needs somethink like "AMDelegationTokenRenewer.scala"
> and "ExecutorDelegationTokenUpdater.scala" of Apache Spark to support long
> running applications in clusters with kerberos authantication enabled.
--
This message was sent by Atlassian JIRA
(v6.3.4#6332)