1、错误:unsupported key type found the default TGT: 18
GSS initiate failed [Caused by GSSException: No valid credentials provided (Mechanism level: Failed to find any Kerberos tgt)]
* 原因:这个是AES256加密算法,需要安装JCE POLICY。
* 解决办法1:
1)下面地址下载JCE包:
http://www.oracle.com/technetwork/java/javase/downloads/jce8-download-2133166.html
2)解压压缩包,local_policy.jar和US_export_policy.jar这两个jar包放到$JAVA_HOME/jre/lib/security/policy/limited目录。
* 解决办法2:
1)修改kerberos client的加密方式:
[libdefaults]
dns_lookup_realm = false
ticket_lifetime = 24h
renew_lifetime = 7d
forwardable = true
rdns = false
default_realm = XXX.COM
default_tgs_enctypes = aes256-cts aes128-cts arcfour-hmac-md5 des-cbc-md5 des-cbc-crc
default_tkt_enctypes = arcfour-hmac-md5 aes256-cts aes128-cts des-cbc-md5 des-cbc-crc
permitted_enctypes = aes256-cts aes128-cts arcfour-hmac-md5 des-cbc-md5 des-cbc-crc
2)修改前:
3)修改后:
2、如何使用DBeaver访问Kerberos环境下的Hive,见如下链接:
https://cloud.tencent.com/developer/article/1377164
https://justnumbersandthings.com/post/2017-05-06-dbeaver-hive/