Advertisement
Guest User

Untitled

a guest
Aug 5th, 2017
542
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 4.70 KB | None | 0 0
  1. Found ticket for solr@DDA.MYCO.COM to go to krbtgt/DDA.MYCO.COM@DDA.MYCO.COM expiring on Sat Apr 29 03:15:04 BST 2017
  2. Entered Krb5Context.initSecContext with state=STATE_NEW
  3. Found ticket for solr@DDA.MYCO.COM to go to krbtgt/DDA.MYCO.COM@DDA.MYCO.COM expiring on Sat Apr 29 03:15:04 BST 2017
  4. Service ticket not found in the subject
  5. >>> Credentials acquireServiceCreds: same realm
  6. Using builtin default etypes for default_tgs_enctypes
  7. default etypes for default_tgs_enctypes: 17 16 23.
  8. >>> CksumType: sun.security.krb5.internal.crypto.RsaMd5CksumType
  9. >>> EType: sun.security.krb5.internal.crypto.Aes128CtsHmacSha1EType
  10. >>> KrbKdcReq send: kdc=oc-10-252-132-139.nat-ucfc2z3b.usdv1.oraclecloud.com UDP:88, timeout=30000, number of retries =3, #bytes=682
  11. >>> KDCCommunication: kdc=oc-10-252-132-139.nat-ucfc2z3b.usdv1.oraclecloud.com UDP:88, timeout=30000,Attempt =1, #bytes=682
  12. >>> KrbKdcReq send: #bytes read=217
  13. >>> KdcAccessibility: remove oc-10-252-132-139.nat-ucfc2z3b.usdv1.oraclecloud.com
  14. >>> KDCRep: init() encoding tag is 126 req type is 13
  15. >>>KRBError:
  16. cTime is Thu Dec 24 11:18:15 GMT 2015 1450955895000
  17. sTime is Fri Apr 28 15:15:06 BST 2017 1493388906000
  18. suSec is 925863
  19. error code is 7
  20. error Message is Server not found in Kerberos database
  21. cname is solr@DDA.MYCO.COM
  22. sname is zookeeper/oc-10-252-132-160.nat-ucfc2z3b.usdv1.oraclecloud.com@DDA.MYCO.COM
  23. msgType is 30
  24. KrbException: Server not found in Kerberos database (7) - UNKNOWN_SERVER
  25. at sun.security.krb5.KrbTgsRep.<init>(KrbTgsRep.java:73)
  26. at sun.security.krb5.KrbTgsReq.getReply(KrbTgsReq.java:251)
  27. at sun.security.krb5.KrbTgsReq.sendAndGetCreds(KrbTgsReq.java:262)
  28. at sun.security.krb5.internal.CredentialsUtil.serviceCreds(CredentialsUtil.java:308)
  29. at sun.security.krb5.internal.CredentialsUtil.acquireServiceCreds(CredentialsUtil.java:126)
  30. at sun.security.krb5.Credentials.acquireServiceCreds(Credentials.java:458)
  31. at sun.security.jgss.krb5.Krb5Context.initSecContext(Krb5Context.java:693)
  32. at sun.security.jgss.GSSContextImpl.initSecContext(GSSContextImpl.java:248)
  33. at sun.security.jgss.GSSContextImpl.initSecContext(GSSContextImpl.java:179)
  34. at com.sun.security.sasl.gsskerb.GssKrb5Client.evaluateChallenge(GssKrb5Client.java:192)
  35. at org.apache.zookeeper.client.ZooKeeperSaslClient$2.run(ZooKeeperSaslClient.java:366)
  36. at org.apache.zookeeper.client.ZooKeeperSaslClient$2.run(ZooKeeperSaslClient.java:363)
  37. at java.security.AccessController.doPrivileged(Native Method)
  38. at javax.security.auth.Subject.doAs(Subject.java:422)
  39. at org.apache.zookeeper.client.ZooKeeperSaslClient.createSaslToken(ZooKeeperSaslClient.java:362)
  40. at org.apache.zookeeper.client.ZooKeeperSaslClient.createSaslToken(ZooKeeperSaslClient.java:348)
  41. at org.apache.zookeeper.client.ZooKeeperSaslClient.sendSaslPacket(ZooKeeperSaslClient.java:420)
  42. at org.apache.zookeeper.client.ZooKeeperSaslClient.initialize(ZooKeeperSaslClient.java:458)
  43. at org.apache.zookeeper.ClientCnxn$SendThread.run(ClientCnxn.java:1057)
  44. Caused by: KrbException: Identifier doesn't match expected value (906)
  45. at sun.security.krb5.internal.KDCRep.init(KDCRep.java:140)
  46. at sun.security.krb5.internal.TGSRep.init(TGSRep.java:65)
  47. at sun.security.krb5.internal.TGSRep.<init>(TGSRep.java:60)
  48. at sun.security.krb5.KrbTgsRep.<init>(KrbTgsRep.java:55)
  49. ... 18 more
  50. ERROR 2017-04-28 15:15:07,046 5539 org.apache.zookeeper.client.ZooKeeperSaslClient [main-SendThread(oc-10-252-132-160.nat-ucfc2z3b.usdv1.oraclecloud.com:2181)]
  51. An error: (java.security.PrivilegedActionException: javax.security.sasl.SaslException: GSS initiate failed
  52. [Caused by GSSException: No valid credentials provided
  53. (Mechanism level: Server not found in Kerberos database (7) - UNKNOWN_SERVER)])
  54. occurred when evaluating Zookeeper Quorum Member's received SASL token.
  55. This may be caused by Java's being unable to resolve the Zookeeper Quorum Member's hostname correctly.
  56. You may want to try to adding '-Dsun.net.spi.nameservice.provider.1=dns,sun' to your client's JVMFLAGS environment.
  57. Zookeeper Client will go to AUTH_FAILED state.
  58.  
  59. >kinit -kt /etc/security/keytabs/solr.headless.keytab solr
  60. >klist
  61. Credentials cache: API:3451691D-7D5E-49FD-A27C-135816F33E4D
  62. Principal: solr@DDA.MYCO.COM
  63.  
  64. Issued Expires Principal
  65. Apr 28 16:58:02 2017 Apr 29 04:58:02 2017 krbtgt/DDA.MYCO.COM@DDA.MYCO.COM
  66.  
  67. >klist -c FILE:/tmp/krb5cc_501
  68. Credentials cache: FILE:/tmp/krb5cc_501
  69. Principal: solr@DDA.MYCO.COM
  70.  
  71. Issued Expires Principal
  72. Apr 28 17:10:25 2017 Apr 29 05:10:25 2017 krbtgt/DDA.MYCO.COM@DDA.MYCO.COM
  73.  
  74. > krb5-config --version
  75. Kerberos 5 release 1.7-prerelease
  76.  
  77. > krb5-config --version
  78. Kerberos 5 release 1.15.1
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement