Access to HBase Tables From Beeline on Secure BDA Clusters with Sentry Fails with "No valid credentials provided (Mechanism level: Failed to find any Kerberos tgt)" (Doc ID 2099257.1)

Last updated on JANUARY 25, 2016

Applies to:

Big Data Appliance Integrated Software - Version 4.2.0 and later
Linux x86-64

Symptoms

Access to HBase tables from beeline on secure BDA clusters with Sentry fails with errors in the /var/log/hive/hadoop-cmf-hive-HIVESERVER2-*.log.out like:

015-12-31 10:17:09,856 ERROR sentry.org.apache.thrift.transport.TSaslTransport: SASL negotiation failure
javax.security.sasl.SaslException: GSS initiate failed [Caused by GSSException: No valid credentials provided (Mechanism level: Failed to find any Kerberos tgt)]
at com.sun.security.sasl.gsskerb.GssKrb5Client.evaluateChallenge(GssKrb5Client.java:211)
at sentry.org.apache.thrift.transport.TSaslClientTransport.handleSaslStartMessage(TSaslClientTransport.java:94)
at sentry.org.apache.thrift.transport.TSaslTransport.open(TSaslTransport.java:271)
at sentry.org.apache.thrift.transport.TSaslClientTransport.open(TSaslClientTransport.java:37)
at org.apache.sentry.hdfs.SentryHDFSServiceClient$UgiSaslClientTransport.baseOpen(SentryHDFSServiceClient.java:128)
at org.apache.sentry.hdfs.SentryHDFSServiceClient$UgiSaslClientTransport.access$000(SentryHDFSServiceClient.java:83)
at org.apache.sentry.hdfs.SentryHDFSServiceClient$UgiSaslClientTransport$1.run(SentryHDFSServiceClient.java:114)
at org.apache.sentry.hdfs.SentryHDFSServiceClient$UgiSaslClientTransport$1.run(SentryHDFSServiceClient.java:112)
at java.security.AccessController.doPrivileged(Native Method)
at javax.security.auth.Subject.doAs(Subject.java:422)
at org.apache.hadoop.security.UserGroupInformation.doAs(UserGroupInformation.java:1671)
at org.apache.sentry.hdfs.SentryHDFSServiceClient$UgiSaslClientTransport.open(SentryHDFSServiceClient.java:112)
...
Caused by: GSSException: No valid credentials provided (Mechanism level: Failed to find any Kerberos tgt)
at sun.security.jgss.krb5.Krb5InitCredential.getInstance(Krb5InitCredential.java:147)
at sun.security.jgss.krb5.Krb5MechFactory.getCredentialElement(Krb5MechFactory.java:122)
at sun.security.jgss.krb5.Krb5MechFactory.getMechanismContext(Krb5MechFactory.java:187)
at sun.security.jgss.GSSManagerImpl.getMechanismContext(GSSManagerImpl.java:224)
at sun.security.jgss.GSSContextImpl.initSecContext(GSSContextImpl.java:212)
at sun.security.jgss.GSSContextImpl.initSecContext(GSSContextImpl.java:179)
at com.sun.security.sasl.gsskerb.GssKrb5Client.evaluateChallenge(GssKrb5Client.java:192)

 

 

 

Cause

Sign In with your My Oracle Support account

Don't have a My Oracle Support account? Click to get started

My Oracle Support provides customers with access to over a
Million Knowledge Articles and hundreds of Community platforms