You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Python跨服务器连接Hive失败,Kerberos认证异常求助

Troubleshooting Kerberos Authentication Failure for PyHive Remote Hive Connection

Let's break down the error you're seeing: Server not found in Kerberos database is a clear sign your client can't locate the correct Kerberos service principal for the remote Hive server. Here's a step-by-step guide to fix this:

1. Fix the kerberos_service_name Parameter (Most Likely Culprit)

You've set kerberos_service_name='adsuedscaihen01.aipcore.local'—this is incorrect. The kerberos_service_name should be the service prefix of the Kerberos principal, not the full hostname. For Hive, this is almost always hive.

Hive's Kerberos principal follows the format: hive/<fully-qualified-hostname>@YOUR_KERBEROS_REALM. PyHive uses the host parameter to build the full principal with the service name you provide.

2. Verify Kerberos Service Principal on the Remote Server

On the Hive server, run this command to check valid principals in the Hive keytab:

klist -kt /etc/krb5.keytab

Look for a line starting with hive/adsuedscaihen01.aipcore.local—this confirms the correct service principal format.

3. Ensure Local Kerberos Configuration (krb5.conf) is Correct

Your local machine's krb5.conf (located at /etc/krb5.conf on Linux/macOS, or C:\Windows\krb5.ini on Windows) must include:

  • The correct Kerberos realm for the remote server
  • Mapping of the server's domain to the realm
  • Valid KDC (Key Distribution Center) addresses

Example valid config snippet:

[libdefaults]
  default_realm = YOUR_COMPANY_REALM.COM
  dns_lookup_realm = false
  dns_lookup_kdc = true

[realms]
  YOUR_COMPANY_REALM.COM = {
    kdc = kdc.your-company-realm.com
    admin_server = kdc.your-company-realm.com
  }

[domain_realm]
  .aipcore.local = YOUR_COMPANY_REALM.COM
  aipcore.local = YOUR_COMPANY_REALM.COM

4. Test Kerberos Ticket Acquisition Locally

Before running your Python code, verify you can get a valid Kerberos ticket for your user:

kinit user1@YOUR_COMPANY_REALM.COM

Enter your password, then run klist to confirm the ticket is issued and valid. If kinit fails, fix that first (check username, realm, or KDC connectivity).

5. Confirm HiveServer2 Port and Transport Mode

Double-check that the port parameter matches the actual port HiveServer2 is listening on. The default port for Kerberos-enabled HiveServer2 (Thrift binary mode) is 10000—you're using 8888, which is often the HTTP port. If you're using HTTP mode, add additional parameters like transport_mode='http' and http_path='cliservice'.

Corrected Code Example

Here's the adjusted code with common fixes applied:

import pyhive
from pyhive import hive

conn = hive.connect(
    host='xx.xxx.xx.xx',
    port=10000,  # Update to your actual HiveServer2 port
    auth='KERBEROS',
    kerberos_service_name='hive',  # Fixed service name
    username='user1',
    database='database1'
)

cur = conn.cursor()
cur.execute('SELECT * from table1')
result = cur.fetchall()
print(result)

Start with correcting the kerberos_service_name—this is the most frequent cause of this exact error. If that doesn't resolve it, work through the other steps to rule out Kerberos config or ticket issues.

内容的提问来源于stack exchange,提问作者kumar saurabh

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.27 07:21:57