ranger-dev mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From "Pradeep Agrawal (Jira)" <j...@apache.org>
Subject [jira] [Commented] (RANGER-2810) Kafka with Ranger plugin will fail
Date Wed, 29 Apr 2020 12:05:00 GMT

    [ https://issues.apache.org/jira/browse/RANGER-2810?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17095387#comment-17095387
] 

Pradeep Agrawal commented on RANGER-2810:
-----------------------------------------

is your kafka service runs in kerberos environment without Ranger plugin even after 10 hours
of running. 

Also if possible can you share stacktrack when you are running with Apache ranger kafka plugin. 

This could be related to expire of Kerberos ticket.

> Kafka with Ranger plugin will fail
> ----------------------------------
>
>                 Key: RANGER-2810
>                 URL: https://issues.apache.org/jira/browse/RANGER-2810
>             Project: Ranger
>          Issue Type: Bug
>          Components: audit
>    Affects Versions: 2.0.0
>         Environment: CentOS Linux release 7.6.1810 (Core)
> Ranger 2.0.0
>            Reporter: bright.zhou
>            Priority: Critical
>
> We use Ranger plugin to admin acls of Kafka cluster. At first , everything is ok, but
after 10h+ of kafka start, there is something wrong occured, we can see error log in kafka-root.log,
the error log is `Authentication failed during authentication due to xxx with SASL mechanism
GSSAPI: GSS context targ name protocol error: xxxxx `。To solve this we had to restart Kafka,
It's so strange that if i change `authorizer.class.name` to `kafka.security.auth.SimpleAclAuthorizer`
it will be ok . In theory, ranger is related with acls and not related with SASL authentication,so
i want to ask for help.



--
This message was sent by Atlassian Jira
(v8.3.4#803005)

Mime
View raw message