20,848
社区成员




安装完kerberos 后,使用 kinit -kt 认证时,票据不能续订,是为什么呢?
[root@hp001 ~]# kinit -kt /root/hive-hp002.keytab hive/hp002@HADOOP.COM
[root@hp001 ~]# klist
Ticket cache: KCM:0
Default principal: hive/hp002@HADOOP.COM
Valid starting Expires Service principal
2024-09-08 16:34:19 2024-09-09 16:34:19 krbtgt/HADOOP.COM@HADOOP.COM
renew until 2024-09-08 16:34:19
其中Valid starting 时间与 renew until 总是相同的!
但票据的设置已经是正确的,kdc.conf中和krb5.conf均已配置了,比如查询的信息如下:
kadmin.local: getprinc hive/hp002@HADOOP.COM
Principal: hive/hp002@HADOOP.COM
Expiration date: [never]
Last password change: Sat Sep 07 16:23:15 CST 2024
Password expiration date: [never]
Maximum ticket life: 1 day 00:00:00
Maximum renewable life: 7 days 00:00:00
Last modified: Sun Sep 08 16:28:49 CST 2024 (root/admin@HADOOP.COM)
Last successful authentication: [never]
Last failed authentication: [never]
Failed password attempts: 0
Number of keys: 4
Key: vno 3, aes128-cts-hmac-sha1-96
Key: vno 3, DEPRECATED:arcfour-hmac
Key: vno 3, camellia256-cts-cmac
Key: vno 3, camellia128-cts-cmac
MKey: vno 1
Attributes:
Policy: [none]