ERROR_IPSEC_IKE_SA_DELETED 13807 (0x35EF) IKE SA deleted by peer before establishment completed. ERROR_IPSEC_IKE_SA_REAPED 13808 (0x35F0)

Answer: ktadd in /var/lib/ambari-server/resources/common-services/KERBEROS/package/scripts/kerberos_common.py -> function create_keytab_file

Master key does not match database Cause: The loaded database dump was not created from a database that contains the master key.

WebHcat does not resolve _HOST.

Always save your own versions of webhcat-site.xml and oozie-site.xml.

A possible problem might be that postdating or forwardable options were being requested, and the KDC did not allow them.

Solution: Make sure that the KDC you are communicating with complies with RFC1510, that the request you are sending is a Kerberos V5 request, or that the KDC is available. If it says Keytype =18, then the error is due to wrong JCE policy files.

Looping detected inside krb5_get_in_tkt Cause: Kerberos made several attempts to get the initial tickets but failed.

Is it different from the krbtgt/@ expiration length Change max_renewable_life in /var/kerberos/krb5kdc/kdc.conf to 14d Change the principal krbtgt/@ maxrenewlife to renew after the same time as max_renewable_lifeIf it is MIT kerberos A well-known encryption key was returned. 1304 The password is too complex to be converted to a LAN Manager password.

Set permitted_enctypes in krb5.conf on the client to not include the aes256 encryption type. Solution: Make sure that all the relations in the krb5.conf file are followed by the "=" sign and a value.

This policy is enforced by the principal's policy.

