Wednesday, 2 July 2014

Steps to Kerborize HDFS in Cloudera Manager and access the same from Information Server

This blog talks about Kerborize HDFS (for that matter all modules) in Cloudera Manager and access the same from Information Server for the purpose of Profiling, Data Quality analysis, Data Integration etc using the data stored in HDFS.
  1. Install Cloudera Manager on the server (let us say on “”)
  2. Install InfoSphere Information Server on a different server (let us say on “”)
  3. Install and setup Kerberos Server on “”.  (Note that this can also done on any other server and can be referred from all Kerberos clients in their configurations accordingly)
  4. Install and setup Kerberos Client on “” (where Cloudera Manager is installed and setup) and on “” ( In case if Kerberos Server is not setup on this box)
KDC Infrastructure setup:
The below are some of the steps that need to be followed while installing and setting up KDC
1. Install Kerberos V5 server/client libraries
2. Install Master KDC
  • Edit Configuration Files
  • Create Database
  • Add Administrators to the Acl File
  • Add Administrators to the Kerberos Database
  • Create a kadmind Keytab
  • Start the Kerberos Daemons on the Master KDC
3. Install Slave KDCs (optional but highly recommended)
4. Propagate Database to Slave KDCs
5. Create Stash Files and Start krb5kdc Daemons on Slave KDCs
4. Configure Kerberos Client machines

Sample kdc.conf
 kdc_ports = 88
 kdc_tcp_ports = 88

 IPS.COM = {
  master_key_type = aes128-cts
  max_life = 2d
  max_renewable_life = 2w
  acl_file = /var/kerberos/krb5kdc/kadm5.acl
  dict_file = /usr/share/dict/words
  admin_keytab = /var/kerberos/krb5kdc/kadm5.keytab
  supported_enctypes = aes128-cts:normal des3-hmac-sha1:normal arcfour-hmac:normal des-hmac-sha1:normal des-cbc-md5:normal des-cbc-crc:normal

Sample krb5.conf
  default = FILE:/var/log/krb5libs.log
  kdc = FILE:/var/log/krb5kdc.log
  admin_server = FILE:/var/log/kadmind.log

  default_realm = IPS.COM
  dns_lookup_realm = false
  dns_lookup_kdc = false
  ticket_lifetime = 2d
  renew_lifetime = 2w
  kdc_timeout = 10s
  forwardable = true
  renewable = true

  IPS.COM = {
    kdc =
    admin_server =

[domain_realm] = IPS.COM = IPS.COM


The following links give some info on overview, install and setup steps for KDC Infrastructure.

Enable Kerberos Security in ClouderaManager:
Logon to Coudera Manager admin console (for example:
to enable Hadoop Security.
These steps create the required keytab files in the server where Cloudera Manager is installed.  One of these keytab fles need to be moved to the client (, where Information Server is installed)
Drivers used:
                Cloudera ODBC Driver for Apache Hive
This driver needs to be installed on the server where Information Server is installed (
P.S. Always have latest version of Cloudera ODBC Driver for Apache Hive to avoid any performance issues
Mandatory steps to be followed in the server where Information Server (IS) Engine is installed:
  1. DSN Entry in .odbc.ini file
Schema= default
HS2KrbRealm= IPS.COM
  1. Create /opt/IBM/InformationServer/Server/DSEngine/.cloudera.hiveodbc.ini file            with the below contents

## - Note that this default DriverManagerEncoding of UTF-32 is for iODBC.
## - unixODBC uses UTF-16 by default.
## - If unixODBC was compiled with -DSQL_WCHART_CONVERT, then UTF-32 is the correct value.
##   Execute 'odbc_config --cflags' to determine if you need UTF-32 or UTF-16 on unixODBC
## - SimbaDM can be used with UTF-8 or UTF-16.
##   The DriverUnicodeEncoding setting will cause SimbaDM to run in UTF-8 when set to 2 or UTF-16 when set to 1.


## - Uncomment the ODBCInstLib corresponding to the Driver Manager being used.
## - Note that the path to your ODBC Driver Manager must be specified in LD_LIBRARY_PATH (LIBPATH for AIX).
## - Note that AIX has a different format for specifying its shared libraries.

# Generic ODBCInstLib
#   iODBC

#   SimbaDM / unixODBC

# AIX specific ODBCInstLib
#   iODBC

#   SimbaDM

#   unixODBC
  1. Add the below entry in /opt/IBM/InformationServer/Server/DSEngine/dsenv file
export SIMBAINI=/opt/IBM/InformationServer/Server/DSEngine/.cloudera.hiveodbc.ini
  1. Locate hive.keytab file in hiveserver2 (on the server where Cloudera Manager is installed, here it is and transfer it to the machine where IS Engine is installed (i.e
                ls -alt `find . -name hive.keytab`                       

Pick up the first one and transfer to /opt/cloudera/ folder on IS Engine machine
  1. Modify the file permissions
chmod 777   /opt/cloudera/hive.keytab
  1. Logon with dsadm user and run the kinit command
kinit -k -t /opt/cloudera/hive.keytab hive/
  1. Verify the ticket information by issuing klist –e command
  2. Logon to Administrator client and define the two environment variables (KRB5CCNAME and KRB5_CONFIG)

P.S. Alternatively you can also add these two environment variables to /opt/IBM/InformationServer/Server/DSEngine/dsenv file.
  1. Export the following two environment variables and Test the connection from DataDirect example program
[root@blr02 example]#export KRB5CCNAME=/tmp/krb5cc_0
[root@blr02 example]#export KRB5_CONFIG=/etc/krb5.conf

[root@blr02 example]#. /opt/IBM/InformationServer/Server/DSEngine/dsenv
[root@blr02 example]#cd /opt/IBM/InformationServer/Server/branded_odbc/samples/example

[root@blr02 example]# ./example
./example DataDirect Technologies, Inc. ODBC Example Application.
Enter the data source name : Hive_Cloudera

Enter the user name        : <leave blank>

Enter the password         : <leave blank>



Enter SQL statements (Press ENTER to QUIT)
SQL> show databases


Enter SQL statements (Press ENTER to QUIT)
SQL> use default

Enter SQL statements (Press ENTER to QUIT)
SQL> show tables


Enter SQL statements (Press ENTER to QUIT)
SQL> select * from tab2

col1    col2
1       ABCD
2       EFG
3       HIJK
4       LMNOP
5       QRST
6       UVWX
7       YZabc
8       defghi
9       klmnop
10      qrstuvwxyz

Enter SQL statements (Press ENTER to QUIT)
Using beeline to connect to Hive:
Users can also preferably use beeline to connect to hive and check the contents in the following manner:

[hive@blr01 run]$ beeline

Beeline version 0.10.0-cdh4.4.0 by Apache Hive
beeline> !connect jdbc:hive2://;principal=hive/
scan complete in 6ms
Connecting to jdbc:hive2://;principal=hive/
Enter username for jdbc:hive2://;principal=hive/
Enter password for jdbc:hive2://;principal=hive/
Connected to: Hive (version 0.10.0)
Driver: Hive (version 0.10.0-cdh4.4.0)
0: jdbc:hive2://> use default;
No rows affected (1.168 seconds)

0: jdbc:hive2://> select col1, col2 from tab2;
| col1  |    col2     |
| 1     | ABCD        |
| 2     | EFG         |
| 3     | HIJK        |
| 4     | LMNOP       |
| 5     | QRST        |
| 6     | UVWX        |
| 7     | YZabc       |
| 8     | defghi      |
| 9     | klmnop      |
| 10    | qrstuvwxyz  |
10 rows selected (26.746 seconds)

0: jdbc:hive2://>

Usage of this data in Information Server:
  • Create an ImportArea, Data connection in InfoSphere Metadata Asset Manager (IMAM) to this datasource and Import Metadata.
  • Register the metadata created in previous step in a Information Analyzer project and one can perform Data Profiling and Data Quality Analysis.
  • The same metadata can be used in Data Integration in DataStage (or) across any component in InfoSphere Information Server.

One can also register in a Google forum in!forum/scm-users and seek help for any specific questions related to Cloudera Manager.

Disclaimer: The postings on this site are those of the authors and don’t necessarily represent IBM’s positions, strategies or opinions.

1 comment:

  1. I really appreciate information shared above. It’s of great help. If someone want to learn Online (Virtual) instructor lead live training in TECHNOLOGY , kindly contact us
    MaxMunus Offer World Class Virtual Instructor-led training on TECHNOLOGY. We have industry expert trainer. We provide Training Material and Software Support. MaxMunus has successfully conducted 100000+ pieces of training in India, USA, UK, Australia, Switzerland, Qatar, Saudi Arabia, Bangladesh, Bahrain and UAE etc.
    For Demo Contact us.
    Pratik Shekhar
    Ph:(0) +91 9066268701