I am not able to find details on ODBC.ini settings in linux to connect to kerberos enabled hive cluster. I tried variout things and have seen these pages:
But I am not sure where to store GSS client library in case of linux and if anything else is needed. Currently i m either getting the error :
Error Message from ODBC: Connection failed: [ODBC 20101 driver]170Unsupported mechanism type PLAIN
OR sometimes i m getting invalid hiverserver host or port .
Any clues ?
Example, replace values with your installation settings.
From the ODBC User's Guide and Reference for Apache Hive
Service Principal Name
The service principal name to be used by driver for Kerberos authentication.
is the three-part service principal name registered with the key distribution center (KDC).
Note: Your service principal name is the value of the hive.server2.authentication.kerberos.principal property in the hive-site.xml file.
You must specify the service principal name using the following format:
is the name of the service hosting the instance. For example, yourservicename.
Depending on the Hive distribution you use, the name of the service is defined either automatically by the server or manually by the user who created the service. For instance, CDH distributions automatically generate a service name of hive, while Apache Hadoop distributions require that the service name be manually defined by the user. Refer to your distribution's documentation for additional information.
is the fully qualified domain name of the host machine. For example, yourserver.example.com.
is the domain name of the host machine. This part of the value must be specified in upper-case characters. For example, EXAMPLE.COM.
The following is an example of a valid service principal name:
*If unspecified, the value of the Network Address option is used as the service principal name.
*If Authentication Method is set to 0 or -1, the value of the Service Principal Name option is ignored.
Specifies the method the driver uses to authenticate the user to the server when a connection is established. If the specified authentication method is not supported by the database server, the connection fails and the driver generates an error.
0 | 4 | -1
If set to 0 (User ID/Password), the driver sends the user ID in clear text and an encrypted password to the server for authentication.
If set to 4 (Kerberos Authentication), the driver uses Kerberos authentication. This method supports both Windows Active Directory Kerberos and MIT Kerberos environments.
If set to -1 (No Authentication), the driver sends the user ID and password in clear text to the server for authentication.
0 (User ID/Password)
GSS Client Library
The name of the GSS client library that the driver uses to communicate with the Key Distribution Center (KDC).
The driver uses the path defined by the PATH environment variable for loading the specified client library.
native | client_library
is a GSS client library installed on the client.
If set to client_library, the driver uses the specified GSS client library.
Note: For MIT Kerberos distributions, you must provide a full path to the MIT Library. For example, the 64-bit version for Windows would use the following value: C:\Program Files\MIT\Kerberos\bin\gssapi64.dll.
If set to native, the driver uses the GSS client for Windows Kerberos. All other users must provide the full path to the library name.