Python跨服务器连接Hive失败,Kerberos认证异常求助
Let's break down the error you're seeing: Server not found in Kerberos database is a clear sign your client can't locate the correct Kerberos service principal for the remote Hive server. Here's a step-by-step guide to fix this:
1. Fix the kerberos_service_name Parameter (Most Likely Culprit)
You've set kerberos_service_name='adsuedscaihen01.aipcore.local'—this is incorrect. The kerberos_service_name should be the service prefix of the Kerberos principal, not the full hostname. For Hive, this is almost always hive.
Hive's Kerberos principal follows the format: hive/<fully-qualified-hostname>@YOUR_KERBEROS_REALM. PyHive uses the host parameter to build the full principal with the service name you provide.
2. Verify Kerberos Service Principal on the Remote Server
On the Hive server, run this command to check valid principals in the Hive keytab:
klist -kt /etc/krb5.keytab
Look for a line starting with hive/adsuedscaihen01.aipcore.local—this confirms the correct service principal format.
3. Ensure Local Kerberos Configuration (krb5.conf) is Correct
Your local machine's krb5.conf (located at /etc/krb5.conf on Linux/macOS, or C:\Windows\krb5.ini on Windows) must include:
- The correct Kerberos realm for the remote server
- Mapping of the server's domain to the realm
- Valid KDC (Key Distribution Center) addresses
Example valid config snippet:
[libdefaults] default_realm = YOUR_COMPANY_REALM.COM dns_lookup_realm = false dns_lookup_kdc = true [realms] YOUR_COMPANY_REALM.COM = { kdc = kdc.your-company-realm.com admin_server = kdc.your-company-realm.com } [domain_realm] .aipcore.local = YOUR_COMPANY_REALM.COM aipcore.local = YOUR_COMPANY_REALM.COM
4. Test Kerberos Ticket Acquisition Locally
Before running your Python code, verify you can get a valid Kerberos ticket for your user:
kinit user1@YOUR_COMPANY_REALM.COM
Enter your password, then run klist to confirm the ticket is issued and valid. If kinit fails, fix that first (check username, realm, or KDC connectivity).
5. Confirm HiveServer2 Port and Transport Mode
Double-check that the port parameter matches the actual port HiveServer2 is listening on. The default port for Kerberos-enabled HiveServer2 (Thrift binary mode) is 10000—you're using 8888, which is often the HTTP port. If you're using HTTP mode, add additional parameters like transport_mode='http' and http_path='cliservice'.
Corrected Code Example
Here's the adjusted code with common fixes applied:
import pyhive from pyhive import hive conn = hive.connect( host='xx.xxx.xx.xx', port=10000, # Update to your actual HiveServer2 port auth='KERBEROS', kerberos_service_name='hive', # Fixed service name username='user1', database='database1' ) cur = conn.cursor() cur.execute('SELECT * from table1') result = cur.fetchall() print(result)
Start with correcting the kerberos_service_name—this is the most frequent cause of this exact error. If that doesn't resolve it, work through the other steps to rule out Kerberos config or ticket issues.
内容的提问来源于stack exchange,提问作者kumar saurabh

